Connect your Cloud Platforms
Cloud platforms hold configuration state that drifts hourly. TruSecure's cloud connector pulls configuration, access policy and resource inventory from AWS, Azure and GCP, so cloud controls are tested against live state rather than the architecture diagram.
What the connector pulls
| Source system | What TruSecure pulls | Feeds governance |
|---|---|---|
| Resource inventory | Accounts, subscriptions, projects, resource counts | Obligation Intelligence · scope and applicability |
| Configuration state | CIS benchmark posture, encryption settings, network exposure | Control Library · cloud security controls |
| Access policies | IAM bindings, key rotation ages, privilege boundaries | Evidence Automation · access-control tests |
| Audit logs | Management-plane events, policy changes | Audit Trail · change evidence |
Evidence produced from Cloud Platforms data
One control test pulled from live Cloud Platforms state — not a manual export, not a screenshot, but a verified query result with provenance:
- Control tested
- Cloud access keys rotated within 90 days
- Cloud source
- AWS · 3 organizations, 17 accounts
- Test
- re-perform · IAM credential report
- Sample
- 44 long-lived keys · 41 within 90 days, 3 aged 91-140
- Result
- fail · 3 keys past rotation, owners notified
- Evidence
- AWS API query · timestamped 2026-08-22T09:12:26Z
- Export
- sealed · sha256:4f8a...d3e7
Setup and scope model
- Read-only, scoped permission
Connector requires read-only access to configuration and IAM state — typically a dedicated audit role. No write permissions, no ability to change policies or rotate keys itself.
- Data filtered by entity
Accounts and subscriptions mapped to entity contexts. Multi-cloud groups see one governance record per entity, not a merged blur across tenants.
- Continuous sync
Configuration tests re-query the cloud on demand. Drift found on Tuesday is evidence dated Tuesday.
Commercial packaging
Cloud Platforms connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.
How integration works
A demo with your actual Cloud Platforms environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.