Details
Integrations and supported checks
For every integration we state what is checked and where the limits are. The detail behind the overview on the home page.
Integrations
Nine integrations available for pilots.
We list only integrations we can discuss with their boundaries, and we state each boundary up front.
| Integration | Area | Scope note | Status |
|---|---|---|---|
| GitLab | Source control | Tested on self-managed GitLab. Some checks return UNKNOWN on the Free tier. | Pilot supported |
| Microsoft Azure | Cloud | Tested on one subscription with a Reader service principal. | Pilot supported |
| Veeam Backup & Replication | Backup | Evidences backup jobs, not the servers they protect. | Pilot supported |
| Proxmox Backup Server | Backup | Tested in a lab environment. | Pilot supported |
| Microsoft Entra ID | Identity | Some checks depend on Entra ID P1/P2 licensing. | Pilot supported, bounded |
| Graylog | Logging | Part of the check set validated against a live system; the rest is scoped per pilot. | Pilot supported, bounded |
| Wazuh | Monitoring | Most checks validated against a live system; the rest is scoped per pilot. | Pilot supported, bounded |
| GitHub | Source control | Repository and ruleset checks validated on a private repository. | Pilot supported, bounded |
| HashiCorp Vault | Secrets | Metadata checks only. No secret values are read. | Pilot supported, bounded |
“Pilot supported” means available for design-partner pilots within the stated boundaries. It does not mean production-proven. A system you run is not listed? Ask us. We will tell you plainly whether it is supported.
Coverage
Technical assurance across six areas.
Each area is checked through systems you already run. Depth differs by system and edition, and every pilot starts with a written list of what is checked and what is not.
| Area | What is checked | Through |
|---|---|---|
| Identity | Privileged accounts and MFA, legacy authentication, role assignments. | Microsoft Entra ID |
| Source control | Branch protection, review and approval requirements, secret scanning, pipeline gates. | GitHub, GitLab |
| Cloud | Azure Policy evaluation and coverage of expected resources. | Microsoft Azure |
| Logging and monitoring | Log inputs and sources active, monitoring agents enrolled and reporting, retention. | Graylog, Wazuh |
| Backup | Expected backup jobs and groups exist, with current successful or verified runs. | Veeam, Proxmox Backup Server |
| Secrets management | Vault initialized, audit device enabled, no raw secrets in audit logs. No secret values are read. | HashiCorp Vault |
Honest results
No evidence is not evidence of security.
Every check ends in one of three results. When Akvera cannot prove a control either way, it says so, rather than showing green.
- PASSPassed
Sufficient, current evidence supports the control.
- FAILFailed
A current, valid observation violates the control.
- UNKNOWNUnknown
Akvera does not have sufficient evidence to make a defensible assertion.
Typical causes of UNKNOWN
- Missing permissions
- Unsupported API capability
- Incomplete coverage
- Licensing or edition limits
- Stale evidence
An UNKNOWN names its cause and the next step, such as granting a permission or declaring expected inventory. It is a defined result, not an error.
Product principles
- Missing evidence does not become PASS.
- Partial coverage does not become complete coverage.
- Akvera prefers UNKNOWN over false certainty.
Expected vs. observed
Visible in a tool is not the same as complete.
Akvera does not assume that everything a security platform shows represents your whole environment. You declare what should exist, source systems report what they observe, and the difference is a coverage gap.
- ExpectedDeclared by you: the endpoints, log sources, repositories or backup groups that must be covered.
- ObservedReported by the source systems when Akvera queries them.
- Coverage gapsWherever expectation and observation differ.
| State | What it means |
|---|---|
EXPECTED + OBSERVEDExpected and observed | Coverage exists. The check can evaluate the object. |
EXPECTED + MISSINGExpected, not observed | Required coverage is absent. This is a gap, not a pass. |
OBSERVED + UNEXPECTEDObserved, not expected | Found in a source system but not declared. It needs a decision. |
Conceptual illustration. Expected inventory is deliberately narrow and is not a CMDB.
Pilot scope
Current pilots are customer-hosted and read-only, and start with one or two of your systems. Akvera is pre-release software. Scope, duration and terms are agreed in a written pilot agreement.