Telemetry Aggregation
CONNECTORSBuilt in Connectors
Every scanner and every system of record, pulled into one schema.
AlloyGRC does not ask you to change what you run. Connectors pull vulnerabilities, compliance results, assets and identity from the tools you already own, land them in one described dataset, and hand work back to your ticketing.
Why it is a dataset, not an integration
Described once, spoken everywhere
A connector does not feed one screen. Its output is profiled in the Dataset Builder, its fields are given roles, and from then on the Dynamic Datatable, AREA, the sprint board, GenAI Dashboards and Ask Alloy all read the same described data. Add a source and every feature already knows what to do with it.
How the Dataset Builder describes dataBuilt in today
What each connector pulls
Tenable Security Center
Vulnerability findings per asset, and compliance results from STIG benchmark audits: every check with its CAT severity, the expected and actual value, and the NIST SP 800-53 control, CCI and CSF function it maps to.
Qualys
Detections per asset with CVSS, Qualys detection score and TruRisk, first and last detected dates and the ATT&CK tactics and techniques Qualys attaches. Asset inventory with agent status, last scan dates, operating system, hardware identity and criticality. Software inventory per asset. Every pull is kept as a dated snapshot.
Jira
Send a sprint or a grouped fix to Jira as tickets, opt in on every send, with the ticket key written back to the finding so the board and the ticket agree.
Active Directory
Sign in and role resolution from your directory. Remediation lanes resolve real owners and their email through it, so nothing about who fixes what is hand typed.
MidPoint
Live account, role and entitlement state for the Access Control assessment agent, so the AC family is assessed from what exists rather than what was attested.
ATIP threat corpus
The enriched CVE corpus arrives daily from the Avint pipeline and is joined to every finding by CVE, so each connector's output carries actors, malware, exploits and ATT&CK context.
Every source, one table
Today, in development, planned
The honest list. A source moves up a row only when its connector is in the product.
| Source | Kind | What it pulls | Status |
|---|---|---|---|
| Tenable Security Center | Vulnerabilities and compliance | Vulnerability findings and STIG benchmark compliance per asset | Today |
| Qualys | Vulnerabilities and asset management | Detections, asset inventory and software inventory, kept as dated snapshots | Today |
| Jira | Work out | Tickets out, opt in on every send, key written back to the finding | Today |
| Active Directory | Identity | Sign in, role resolution and owner lookup | Today |
| MidPoint | Identity state | Account, role and entitlement state for the AC agent | Today |
| ATIP threat corpus | Avint feed | Enriched CVE records, daily, joined to findings by CVE | Today |
| CrowdStrike Falcon | Endpoint telemetry | Endpoint detections and host telemetry beside the findings on the same asset | In development |
| Qualys policy compliance | Compliance | Compliance scan results alongside the vulnerability and asset pulls | Planned |
| Microsoft Intune | Work out | Hand remediation to endpoint management | Planned |
| ATIP API | Avint feed | Query the threat corpus from outside AlloyGRC | Planned |
| Existing ATO import | Authorization | Bring an authorized system straight into continuous monitoring | Planned |
How a connector works
Pull, normalize, join, serve
Four stages, the same for every source. The first two happen when the connector runs; the last two are why the data is useful everywhere.
STAGE 01
Pull
A scheduled pull from the tool's API or export. Each run lands as a dated snapshot, so history is never overwritten.
Raw snapshot
STAGE 02
Normalize
Fields are mapped to roles in the Dataset Builder: finding id, asset id, severity, dates, status. Scanner wording becomes one vocabulary.
Described dataset
STAGE 03
Join
Assets are tied to the systems you own through hardware identity, and every CVE picks up its ATIP record.
Findings scoped to systems
STAGE 04
Serve
Tables, AREA ranking, dashboards, the sprint board and Ask Alloy all read the same dataset. Work goes back out through Jira.
Every feature, one schema
Straight answers
Do we have to replace our scanner?
No. Tenable Security Center and Qualys are both read as they are. AlloyGRC ranks and scopes what they find; it does not discover anything itself.
We run something that is not listed.
Anything that lands in the AlloyGRC database can be profiled and described in the Dataset Builder and used by every feature. A dedicated connector adds the scheduled pull and the normalization, and we build them in the order customers need them.
Does scan data leave our environment?
No. Connectors run inside your deployment, pull into your database, and nothing is sent to Avint.
How are findings tied to our systems?
Through the asset's hardware identity, matched against the system inventory. A finding on an asset nobody owns stays visible as unassigned rather than disappearing.
Bring a scanner export. Leave with it ranked and scoped.
Ask for a demo and we will show a Tenable or Qualys pull landing, being described, and turning up ranked on the vulnerabilities page.