Integrations
Retrievy is only as useful as the data sources connected to it. This section is the catalog: every cloud platform, identity provider, and on-prem system Retrievy can audit, plus the tools that bridge them.
Cloud data sources
Connected directly via API. No agent required. Pick the page that matches your provider.
| Data source | What gets scanned | Setup time |
|---|---|---|
| AWS | IAM, S3, EC2, RDS, VPC, CloudTrail, GuardDuty, KMS, Lambda, ELB | ~15 min |
| Azure | Storage, Key Vault, NSGs, VMs, SQL DB, Defender for Cloud, Entra ID | ~15 min (Quick Connect) or ~25 min (manual) |
| GCP | IAM, Cloud Storage, Compute Engine, VPC firewalls, Cloud SQL, KMS | ~20 min |
| Microsoft 365 | Exchange, SharePoint, Teams, Defender for Office 365, secure score | ~10 min |
| Oracle Cloud (OCI) | IAM, Object Storage, Compute, VCN, Vault, audit logs | ~20 min |
| Cloudflare | Zones, DNS, WAF, access policies, R2 | ~10 min |
On-prem data sources
Connected via the Retrievy Agent. Install the agent once on a machine inside your network, then point it at the systems you want scanned.
| Data source | What gets scanned | Agent platform |
|---|---|---|
| Active Directory | Domain controllers, GPOs, privileged groups, stale accounts, MFA gaps | Windows MSI |
| FortiGate firewalls | Policies, NAT rules, VPN config, admin accounts, CIS benchmark | Docker container |
The Retrievy Agent (the tool)
The Agent is the local bridge between your on-prem systems and the Retrievy cloud. It runs on a machine inside your network, performs scans on a schedule, and ships results to your workspace over an encrypted channel. You install it once per network segment, then connect data sources to it.
| Install method | When to use it |
|---|---|
| Windows MSI | Required for Active Directory scans. Install on a domain-joined Windows server. |
| Docker container | Recommended for FortiGate scans. Works on any host with Docker. |
The Agent itself isn't a data source — it's the tool that talks to data sources. Think of it the same way you'd think of an SSH client: useful only when paired with a system to connect to.
Single sign-on
Lets your team sign in with their corporate identity instead of email + password. Plan-gated to Advanced and Build Your Own.
| Provider | Setup guide |
|---|---|
| Microsoft Entra ID (Azure AD) | Microsoft Entra ID single sign-on |
Google Workspace and Cloudflare Zero Trust SSO guides land here as the provider-specific instructions are finalised. In the meantime, contact support for manual configuration.
What's not yet covered
Retrievy's roadmap includes additional integrations (Kubernetes posture, GitHub Advanced Security, Okta, Workday). When those land, this page will gain new rows. If you want something specific, ask support; the integration backlog is prioritised by customer demand.
Related
- Plan feature matrix (which integrations are gated)
- Plans and pricing (data-source slot counts per plan)
- Run your first scan (recommended for new workspaces)