Skip to main content
INTEGRATION

Connect your EDR / XDR

Endpoint detection and response platforms hold the ground truth of your endpoint posture — agent coverage, detections, response actions. TruSecure's EDR/XDR connector pulls that posture into the governance record, so 'do we monitor our endpoints?' becomes a query, not a claim.

What the connector pulls

EDR / XDR data pulled into TruSecure
Source systemWhat TruSecure pullsFeeds governance
Agent fleetDeployment status, agent versions, stale agentsEvidence Automation · coverage controls
Detection eventsDetections, severity, MITRE tacticsIncident and Resilience Workflows · NIS2 Art. 23 triggers
Response actionsIsolations, kills, restores, by whom and whenAudit Trail · response-effectiveness evidence
Policy statePrevention policies, exclusions, tamper protectionControl Library · hardening measures

Evidence produced from EDR / XDR data

One control test pulled from live EDR / XDR state — not a manual export, not a screenshot, but a verified query result with provenance:

Control test · EDR-2026-114 agent coverageSample data
Control tested
NIS2 Art. 21(2)(d) — detection on all managed endpoints
EDR source
CrowdStrike · sensor: windows/7.16.0-1709
Test
re-perform · fleet coverage and sensor health
Sample
1,082/1,102 endpoints · 98.2% covered
Result
pass with exceptions · 3 stale sensors, 17 cloud-shadow hosts
Evidence
EDR API query · timestamped 2026-08-22T08:04:41Z
Export
sealed · sha256:e1c9...4b7f

Setup and scope model

  1. Read-only, scoped permission

    Connector requires read-only access to detection events, response logs, and agent status. No write permissions, no ability to isolate hosts or change policies.

  2. Data filtered by entity

    Pull is scoped to the TruSecure entity context — your endpoints only, no cross-tenant data. Coverage percentages match your fleet, not the tenant-wide number.

  3. Continuous sync

    Coverage re-computed on every control test. A stale sensor shows as a stale sensor the day it goes stale, not at quarter-end.

Commercial packaging

EDR / XDR connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.

How integration works

A demo with your actual EDR / XDR environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.