Back to the overview

Details

Integrations and supported checks

For every integration we state what is checked and where the limits are. The detail behind the overview on the home page.

Integrations

Nine integrations available for pilots.

We list only integrations we can discuss with their boundaries, and we state each boundary up front.

Integrations available for pilots, with their scope notes
IntegrationAreaScope noteStatus
GitLabSource controlTested on self-managed GitLab. Some checks return UNKNOWN on the Free tier.Pilot supported
Microsoft AzureCloudTested on one subscription with a Reader service principal.Pilot supported
Veeam Backup & ReplicationBackupEvidences backup jobs, not the servers they protect.Pilot supported
Proxmox Backup ServerBackupTested in a lab environment.Pilot supported
Microsoft Entra IDIdentitySome checks depend on Entra ID P1/P2 licensing.Pilot supported, bounded
GraylogLoggingPart of the check set validated against a live system; the rest is scoped per pilot.Pilot supported, bounded
WazuhMonitoringMost checks validated against a live system; the rest is scoped per pilot.Pilot supported, bounded
GitHubSource controlRepository and ruleset checks validated on a private repository.Pilot supported, bounded
HashiCorp VaultSecretsMetadata checks only. No secret values are read.Pilot supported, bounded

“Pilot supported” means available for design-partner pilots within the stated boundaries. It does not mean production-proven. A system you run is not listed? Ask us. We will tell you plainly whether it is supported.

Coverage

Technical assurance across six areas.

Each area is checked through systems you already run. Depth differs by system and edition, and every pilot starts with a written list of what is checked and what is not.

Assurance areas, what is checked and through which systems
AreaWhat is checkedThrough
IdentityPrivileged accounts and MFA, legacy authentication, role assignments.Microsoft Entra ID
Source controlBranch protection, review and approval requirements, secret scanning, pipeline gates.GitHub, GitLab
CloudAzure Policy evaluation and coverage of expected resources.Microsoft Azure
Logging and monitoringLog inputs and sources active, monitoring agents enrolled and reporting, retention.Graylog, Wazuh
BackupExpected backup jobs and groups exist, with current successful or verified runs.Veeam, Proxmox Backup Server
Secrets managementVault initialized, audit device enabled, no raw secrets in audit logs. No secret values are read.HashiCorp Vault

Honest results

No evidence is not evidence of security.

Every check ends in one of three results. When Akvera cannot prove a control either way, it says so, rather than showing green.

  • PASSPassed

    Sufficient, current evidence supports the control.

  • FAILFailed

    A current, valid observation violates the control.

  • UNKNOWNUnknown

    Akvera does not have sufficient evidence to make a defensible assertion.

Typical causes of UNKNOWN

  • Missing permissions
  • Unsupported API capability
  • Incomplete coverage
  • Licensing or edition limits
  • Stale evidence

An UNKNOWN names its cause and the next step, such as granting a permission or declaring expected inventory. It is a defined result, not an error.

Product principles

  • Missing evidence does not become PASS.
  • Partial coverage does not become complete coverage.
  • Akvera prefers UNKNOWN over false certainty.

Expected vs. observed

Visible in a tool is not the same as complete.

Akvera does not assume that everything a security platform shows represents your whole environment. You declare what should exist, source systems report what they observe, and the difference is a coverage gap.

  1. ExpectedDeclared by you: the endpoints, log sources, repositories or backup groups that must be covered.
  2. ObservedReported by the source systems when Akvera queries them.
  3. Coverage gapsWherever expectation and observation differ.
Possible states per asset
StateWhat it means
EXPECTED + OBSERVEDExpected and observed
Coverage exists. The check can evaluate the object.
EXPECTED + MISSINGExpected, not observed
Required coverage is absent. This is a gap, not a pass.
OBSERVED + UNEXPECTEDObserved, not expected
Found in a source system but not declared. It needs a decision.

Conceptual illustration. Expected inventory is deliberately narrow and is not a CMDB.

Pilot scope

Current pilots are customer-hosted and read-only, and start with one or two of your systems. Akvera is pre-release software. Scope, duration and terms are agreed in a written pilot agreement.