Connect Zovos to your stack with 54 connectors and an open API.
Zovos sits on top of the systems you already pay for. It reads and writes where it should, and every action is audited.
54 connectors across 18 categories
One connector registry spans the systems your evidence already lives in (services/connectors/registry).
- 01Categories include identity and access, document management, ticketing and workflow, and notifications.
- 02They include BSA/AML oversight, security evidence, security operations, and third-party risk.
- 03They include board portals, regulator portals, e-signature, and regulatory intelligence.
- 04They also include reporting and exports, control content, business continuity, and more.
Two honest states
Every connector is labelled for what it actually does today. No tile pretends to be live when it is not.
- 01Available means the connector runs against the real service with a credential you already hold.
- 02Coming soon means the tile is listed but cannot be connected in your deployment yet.
Automation API and signed webhooks
Drive Zovos from the outside with a REST API and HMAC-signed outbound webhooks (automation, outbound_webhooks, api_keys).
- 01The REST automation API uses scoped API keys.
- 02Outbound webhooks are HMAC-signed so you can verify them.
SIEM and audit-log export
Forward the append-only audit log to the SIEM your examiners ask about. Your security team sets up the forwarder in Settings → Integrations (siem_config, audit_log_export).
- 01Export goes to Splunk HEC, Microsoft Sentinel, or a generic HTTPS/JSON collector.
- 02The export comes from an audit log that is append-only at the database.
SSRF-guarded endpoints
Tenant-supplied destinations are called through an SSRF-guarded client, so a misconfigured or hostile endpoint cannot reach into the network (security/ssrf).
- 01Tenant-configured URLs are validated and guarded before any request is made.
Grounded in shipped behaviour.
- The registry holds 54 connectors across 18 categories: identity & access, document management, ticketing & workflow, BSA/AML oversight, security evidence, security operations, third-party risk, board & regulator portals, e-signature, regulatory intelligence, reporting & exports, control content, and business continuity.
- Zovos has a REST automation API with HMAC-signed outbound webhooks.
- The audit log exports to Splunk HEC, Microsoft Sentinel, or a generic HTTPS/JSON collector.
- Tenant-supplied endpoints are SSRF-guarded.
Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.
Questions, answered first.
- How many connectors are there?
- There are 54 connectors across 18 categories, resolved from a single registry that is also the source of the in-app Settings → Integrations directory.
- Do I need Zovos to build a connector to my system?
- Often you do not. Many connectors run against your own credential today, and a REST API plus signed webhooks cover anything a tile does not.
- What does “coming soon” mean?
- The connector is carried in the product as a tile, but it cannot be connected or used as a send target in your deployment yet. Adobe Acrobat Sign shows that state until its OAuth application is configured.
- Can I forward audit events to my SIEM?
- Yes. Set up the SIEM forwarder in Settings → Integrations. Events go to Splunk’s HTTP Event Collector, Microsoft Sentinel, or a generic HTTPS/JSON collector, from an audit log that is append-only at the database.
See integrations & connectors on your library.
Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.