Feature · Administration

Connect Zovos to your stack with 54 connectors and an open API.

Zovos sits on top of the systems you already pay for. It reads and writes where it should, and every action is audited.

SectionAdministration
UpdatedOctober 2026
Connectors
54
in the registry
Categories
18
identity → BSA/AML
API
REST
signed webhooks
Connector directory · two honest states
JiraAvailable
ServiceNowAvailable
Splunk HECAvailable
Verafin (Nasdaq)Available
SharePointAvailable
Microsoft 365 postureAvailable
Unit21Available
Adobe Acrobat SignComing soon
Illustrative product preview. It does not show tenant data.
01 · Integrations & connectors

54 connectors across 18 categories

One connector registry spans the systems your evidence already lives in (services/connectors/registry).

  • 01Categories include identity and access, document management, ticketing and workflow, and notifications.
  • 02They include BSA/AML oversight, security evidence, security operations, and third-party risk.
  • 03They include board portals, regulator portals, e-signature, and regulatory intelligence.
  • 04They also include reporting and exports, control content, business continuity, and more.
02 · Integrations & connectors

Two honest states

Every connector is labelled for what it actually does today. No tile pretends to be live when it is not.

  • 01Available means the connector runs against the real service with a credential you already hold.
  • 02Coming soon means the tile is listed but cannot be connected in your deployment yet.
03 · Integrations & connectors

Automation API and signed webhooks

Drive Zovos from the outside with a REST API and HMAC-signed outbound webhooks (automation, outbound_webhooks, api_keys).

  • 01The REST automation API uses scoped API keys.
  • 02Outbound webhooks are HMAC-signed so you can verify them.
04 · Integrations & connectors

SIEM and audit-log export

Forward the append-only audit log to the SIEM your examiners ask about. Your security team sets up the forwarder in Settings → Integrations (siem_config, audit_log_export).

  • 01Export goes to Splunk HEC, Microsoft Sentinel, or a generic HTTPS/JSON collector.
  • 02The export comes from an audit log that is append-only at the database.
05 · Integrations & connectors

SSRF-guarded endpoints

Tenant-supplied destinations are called through an SSRF-guarded client, so a misconfigured or hostile endpoint cannot reach into the network (security/ssrf).

  • 01Tenant-configured URLs are validated and guarded before any request is made.
Proof points

Grounded in shipped behaviour.

  • The registry holds 54 connectors across 18 categories: identity & access, document management, ticketing & workflow, BSA/AML oversight, security evidence, security operations, third-party risk, board & regulator portals, e-signature, regulatory intelligence, reporting & exports, control content, and business continuity.
  • Zovos has a REST automation API with HMAC-signed outbound webhooks.
  • The audit log exports to Splunk HEC, Microsoft Sentinel, or a generic HTTPS/JSON collector.
  • Tenant-supplied endpoints are SSRF-guarded.

Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.

FAQ

Questions, answered first.

How many connectors are there?
There are 54 connectors across 18 categories, resolved from a single registry that is also the source of the in-app Settings → Integrations directory.
Do I need Zovos to build a connector to my system?
Often you do not. Many connectors run against your own credential today, and a REST API plus signed webhooks cover anything a tile does not.
What does “coming soon” mean?
The connector is carried in the product as a tile, but it cannot be connected or used as a send target in your deployment yet. Adobe Acrobat Sign shows that state until its OAuth application is configured.
Can I forward audit events to my SIEM?
Yes. Set up the SIEM forwarder in Settings → Integrations. Events go to Splunk’s HTTP Event Collector, Microsoft Sentinel, or a generic HTTPS/JSON collector, from an audit log that is append-only at the database.

See integrations & connectors on your library.

Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.