Compliance integrations that collect the evidence, so nobody on your team has to.
Greypike connects to the platforms already running your identity, devices, cloud infrastructure, productivity, endpoint security, awareness training and ticketing. Seventeen compliance integrations pull the records an assessor will ask for, on their own, instead of somebody chasing screenshots the week before an audit.
The goal is not to push you onto a particular stack. It is to make compliance faster when an integration exists, and fully workable when it does not.
Thirty minutes, no prep. Tell us what you run and you will leave knowing which of your evidence collects itself and which of it you will still attach by hand.
Seven categories of evidenceSeven categories, 17 compliance integrations
Jump straight to the category you care about, or read the full catalog further down.
Most platforms are designed around connectors. Greypike is designed around the work.
Every compliance requirement can be completed whether a compliance integration exists or not. The integration does not make the task possible. It makes one step of it faster. Here are both paths side by side, so you can see exactly which step changes.
- TaskAssigned, with a named owner and a due date
- Upload evidenceAttach an exported report or a screenshot
- ReviewA compliance manager checks it before an assessor does
- CompleteMapped to every framework the work satisfies
- TaskAssigned, with a named owner and a due date
- Evidence collected automaticallyPulled from the connected system, dated and attached
- ReviewA compliance manager checks it before an assessor does
- CompleteMapped to every framework the work satisfies
Only one step ever changes. Three of the four are identical either way, because the assignment, the review and the framework mapping are the product. A missing connector costs you a few minutes of uploading. It does not cost you a program.
This is the part worth being clear about before you compare vendors. A platform sold on connector count is selling you step two. If the other three steps are not there, a fully connected tenant still produces a pile of automatically collected files that nobody has assigned, reviewed or mapped to anything. That is not a compliance program. It is a faster way to accumulate evidence you have not checked.
It also explains why the roadmap items further down this page are not a problem. A requirement covered by a roadmap connector completes today. Somebody attaches the export. When the compliance integration ships, that same requirement stops needing a person. Nothing about the program changes, and nothing waits.
Most compliance platforms stop at commercial Microsoft 365. Government contractors do not.
Microsoft GCC High runs in separate sovereign cloud environments with different endpoints and a different authentication surface. You cannot point a commercial connector at a GCC High tenant and expect it to return anything. Supporting it means building compliance integrations against those environments deliberately, and most platforms have not.
The connector list looks right
Microsoft Entra ID, Microsoft 365, Microsoft Intune — all listed on the pricing page. Then you connect your tenant and nothing comes back, because the platform was only ever built against commercial endpoints. You find this out after you have bought it, usually in the same week you told your prime you had a plan.
The sovereign environments themselves
- Microsoft Entra ID GCC High
- Microsoft 365 GCC High
- Microsoft Intune GCC High
For a defense contractor this is not a feature comparison
It is the difference between a platform that works and one that does not. Evidence gets collected from the environments where your Controlled Unclassified Information is actually managed, not from a commercial tenant that happens to share a logo. If your CUI lives in GCC High and your compliance integrations do not, every access review, every device compliance report and every configuration export goes back to being manual.
All 17 compliance integrations, and the evidence each one supplies
Grouped by the kind of evidence you are trying to stop collecting by hand. Roadmap items are marked as such: those requirements still complete today, you just attach the evidence yourself until the connector ships.
Identity & access 2 integrations
The category assessors open first. Multi-factor enforcement, who holds administrative roles, and whether anyone reviewed the list this quarter.
Microsoft Entra ID
- Multi-factor authentication settings
- User inventories
- Administrative role assignments
- Access reviews
- Conditional Access configurations
Google Workspace
- User inventories
- Authentication settings
- Administrative controls
Endpoint security 2 integrations
Coverage and deployment status, which is the question behind most endpoint controls: not whether you own the tool, but whether it is on everything.
Huntress
- Endpoint coverage
- Agent deployment status
- Security monitoring evidence
- Detection and response information
ConnectSecure
- Vulnerability findings
- Asset information
- Risk reporting
- Remediation tracking
Cloud infrastructure 2 integrations
Resource inventories and security configuration, dated. The two things nobody can reconstruct accurately from memory a year later.
Microsoft Azure
- Identity
- Infrastructure
- Security configuration evidence
- Cloud resource inventories
Google Cloud
- Cloud resource visibility
- Configuration evidence
- Asset information
Productivity & storage 2 integrations
Where the documents live, which matters for both the evidence itself and for the controls covering how it is stored and shared.
Microsoft 365
- SharePoint
- OneDrive
- Microsoft 365 services
- Supporting documentation workflows
Google Drive
- Evidence management
- Supporting documentation workflows
Device management 2 integrations
Device compliance state and configuration baselines, pulled per device rather than asserted in a policy document nobody has opened since it was written.
Microsoft Intune
- Device compliance
- Device inventories
- Configuration policies
- Security baselines
Jamf
- Apple device inventories
- Device management configurations
- Compliance evidence
Security awareness training 3 integrations, on the roadmap
Completion by named user is the single most requested piece of evidence in this category, and the most tedious to assemble by hand. Until these ship, you export the report and attach it.
KnowBe4
- Training completion by named user
- Assignment and due dates
- Phishing simulation results
- Campaign history
Huntress Security Awareness Training
- Completion records by name and date
- Enrollment coverage
- Episode and campaign history
Proofpoint Security Awareness
- Training completion evidence
- User assignment records
- Simulation outcomes
Ticketing & ITSM 4 integrations, on the roadmap
Change approvals, access requests and incident timelines already exist in your ticketing system. These compliance integrations are about not retyping them into a compliance platform.
Jira Service Management
- Change approvals and records
- Access request and removal tickets
- Incident tickets and timelines
- Closure evidence
ServiceNow
- Change management records
- Approval chains
- Incident and problem records
- Asset references
ConnectWise PSA
- Ticket history and resolution records
- Onboarding and offboarding tickets
- Change records from your MSP
Autotask PSA
- Ticket and resolution evidence
- Access change records
- Scheduled maintenance records
If you run an MSP, the last two matter more than they look. Most of the change and access evidence a Defense Industrial Base contractor needs was created by their provider, in their provider’s system, and has to be requested by email today.
Running a stack we have not listed?
Tell us what you use. In thirty minutes we can tell you which of your evidence these compliance integrations would collect on their own, which of it you will keep attaching by hand, and whether that changes your timeline at all. Usually it does not, which is the point.
Do not see your tool? That is fine.
Plenty of platforms will not let you start until you have connected something. Greypike is built around completing the work and managing the evidence, so a missing connector is an inconvenience rather than a blocker.
If a connector for your stack does not exist, the task still gets assigned, completed, reviewed and mapped to every framework it satisfies. You attach the evidence yourself, and the compliance manager reviews it exactly as they would review something a connector pulled in.
That matters most for the organizations nobody builds connectors for: the manufacturer running a line-of-business application older than the cloud, the contractor whose MSP holds half the evidence, the firm with three tools that have no public API at all. Those programs pass assessments every year. They just do step two by hand.
- Upload evidence manually
- Attach exported reports
- Import screenshots
- Track completion activities
- Maintain the full compliance workflow
Every framework, every requirement, with or without a connector. If a vendor tells you a requirement cannot be evidenced because they have not built the integration, what they are describing is a limit of their product rather than a limit of the framework.
- Veteran-Owned Small Business
- 20+ years across government and the Defense Industrial Base
- 20+ DIB contractors on active contracts supporting defense missions
- 14 years as a cybersecurity and fraud investigator
- Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on the team
- MIT Sloan certificate in artificial intelligence for business strategy and governance
Why the connector list is short and honest
It would be easy to publish a longer one. Most compliance platforms do, because the list is what gets compared on a procurement spreadsheet. The cost of that is paid later, by the customer who connects a tenant and gets nothing back.
Two decades of work inside the Defense Industrial Base teaches you which claims survive contact with an assessor. A connector that only reaches commercial endpoints is worth nothing to a contractor whose CUI sits in GCC High. A training integration that reports a completion percentage but not the names is worth nothing when the assessor asks who specifically completed it and when. So this page marks three sovereign environments explicitly, labels seven of the seventeen compliance integrations as roadmap or in validation, and says plainly that the work completes either way.
The reason that is safe to say out loud is that the assignment, the review and the framework mapping are what we actually sell. The connectors save your team time. They are not what makes the evidence hold up.
Compliance integration questions we get asked
Do I need an integration to use Greypike?
No. Compliance integrations are a convenience, never a prerequisite. Every requirement can be assigned, completed, reviewed and mapped without connecting a single system. The integration changes one step of four: instead of attaching an exported report or a screenshot, the evidence is pulled from the connected platform and dated for you. The other three steps are identical either way.
What happens to requirements covered by a roadmap integration?
They complete today, manually. Seven of the seventeen compliance integrations are marked as roadmap or in validation, and every requirement they will eventually cover is already assignable, evidenceable and reviewable. Somebody exports the training completion report and attaches it. When the connector ships, that same requirement stops needing a person, and nothing about the program has to be rebuilt.
Does Greypike support Microsoft GCC High?
Yes, for three environments directly: Microsoft Entra ID GCC High, Microsoft 365 GCC High and Microsoft Intune GCC High. This matters because GCC High runs in separate sovereign cloud environments with different endpoints. A commercial connector pointed at a GCC High tenant returns nothing, which is a problem most contractors discover after purchase. If your Controlled Unclassified Information is managed in GCC High, ask any vendor to demonstrate a live pull from a GCC High tenant rather than showing you a logo on a connector page.
What evidence do the compliance integrations actually collect?
It depends on the system. Identity platforms supply multi-factor settings, user inventories, administrative role assignments, access reviews and Conditional Access configuration. Device management supplies device compliance state, inventories, configuration policies and security baselines. Endpoint security supplies coverage and agent deployment status. Cloud platforms supply resource inventories and security configuration. Each card in the catalog above lists exactly what that connector returns, so you can check it against the controls you owe rather than against a category name.
How is this different from a compliance platform with more connectors?
Connector count measures one step. A platform sold on the length of its integration list is selling you automated evidence collection, which produces files nobody has assigned, reviewed or mapped to a framework. The work of compliance is deciding who owns a requirement, confirming the evidence satisfies it, and knowing which other frameworks the same work covers. Automated collection makes that faster. It does not do it.
My MSP holds most of our evidence. Does that work?
Yes, and it is a common shape in the Defense Industrial Base. Today the change records, access request tickets and onboarding evidence held by your provider are requested by email and attached manually, which works but adds a step. The ticketing and ITSM connectors on the roadmap — Jira Service Management, ServiceNow, ConnectWise PSA and Autotask PSA — are aimed squarely at that problem. Until they ship, your provider exports and you attach.
Are integrations charged separately?
No. Every compliance integration is included, and no connector is required to run the program. Pricing is not tied to how many systems you connect, which means there is no commercial reason to connect something you would rather not, and no penalty for a stack nobody has built a connector for.
Which frameworks does the collected evidence map to?
All of the ones you run. Evidence collected once is mapped onto every requirement it satisfies, which is why a second framework costs a fraction of the first. An access review pulled from Microsoft Entra ID is the same access review whether a C3PAO assessing CMMC, a SOC 2 auditor, an ISO 27001 certification body or an insurer’s questionnaire is the one asking. See the frameworks we cover or the same program by industry.
Last reviewed: September 2026
Built around the work, not the connectors.
Tell us what you run and we will show you what collects itself and what does not. Either way the program works. The compliance integrations only decide how much of it you do by hand.
Every integration included · No connector required · Manual evidence always works