Skip to main content
Back to the trust center

Trust

Per-connector data inventory

The table a data protection officer asks for, and the input to an article 30 record. It is generated from the connector registry on every release: a hand-maintained inventory is a promise that decays, and this is the table you show a regulator.

Generated on 1 October 2026

What does not vary

Three of the four answers are uniform per direction — by construction rather than convenience: a connector module has no database handle at all. The one exception is declared below, connector by connector, rather than buried here.

  • Kept from a read: one headline, at most six numeric tiles, and a proposed ReCyF level.
  • No raw response from a third-party tool is ever kept.
  • Credentials are encrypted at rest and deleted on disconnection.
  • What goes out to a PSA tool is a summary, a plain-text body, and the source that produced it.
  • What comes back from a PSA tool is the state of an already-created ticket: its status, its closure date and its last activity. A closure becomes a proposal a consultant validates — never an action closed on its own.
  • Summaries carry no person's name — verified by a test, not guaranteed by the type system.
  • When an agency switches it on for a connection, that connector also keeps one opaque marker per asset: a keyed digest of the source tool's own internal identifier — never a machine name, a serial number or an IP address. It can say that three machines disappeared; it can never say which.
  • That option exists for 2 connectors of 76, it is off by default, and switching it off deletes the markers already held.

What is not documented yet

The required access right is still to be documented for 45 of 76 connectors. The cell is empty rather than filled with a guess: an inventory that guessed "read-only role" for a tool whose permission model was never checked would be an unverifiable claim in front of the one audience that tests it.

OAuth connectors (2)

Your client's own administrator consents, sees the list of permissions on their own consent screen, and can revoke them without asking us.

ToolHostingReCyF objectives readCredential heldRequired access right
Google WorkspaceVerified against a live instanceSaaSObjective 10oauth-consent (refresh token, encrypted)openid, email, https://www.googleapis.com/auth/admin.directory.user.readonly
Microsoft 365Verified against a live instanceSaaSObjectives 1, 10, 18oauth-consent (refresh token, encrypted)openid, profile, offline_access, https://graph.microsoft.com/User.Read.All, https://graph.microsoft.com/AuditLog.Read.All, https://graph.microsoft.com/DeviceManagementManagedDevices.Read.All

Credential connectors, one client (53)

One credential per client, supplied by the agency, encrypted at rest.

ToolHostingReCyF objectives readCredential heldRequired access right
Acronis Cyber ProtectNot verified against a live instanceSaaSObjectives 9, 13clientId, clientSecretNot documented to date
AdGuard HomeVerified against a live instanceSelf-hostedObjective 9username, passwordNot documented to date
AuthentikVerified against a live instanceSelf-hostedObjective 10apiTokenNot documented to date
BareosVerified against a live instanceSelf-hostedObjective 13consoleName, consolePasswordCréez un Console dédié (bareos-dir.d/console/) rattaché à un Profile dont la Command ACL se limite aux commandes de lecture — « status, show, list, llist, .jobs » suffisent à ce connecteur — plutôt que de réutiliser le profil « operator » ou la console par défaut.
Bitdefender GravityZoneNot verified against a live instanceSaaSObjectives 1, 9apiKeyNot documented to date
BitwardenNot verified against a live instanceSelf-hostedObjective 10clientId, clientSecretNot documented to date
CrowdSecVerified against a live instanceSelf-hostedObjective 12apiKeyNot documented to date
Datto BCDRNot verified against a live instanceSaaSObjective 13publicKey, secretKeyNot documented to date
Datto RMMNot verified against a live instanceSaaSObjectives 1, 5, 9apiKey, apiSecretKey, siteUidNot documented to date
DefectDojoVerified against a live instanceSelf-hostedObjective 5apiTokenNot documented to date
DuplicatiVerified against a live instanceSelf-hostedObjective 13passwordDuplicati n'a qu'un seul secret pour son interface web (DUPLICATI__WEBSERVICE_PASSWORD) et aucun rôle « lecture seule » : le mot de passe donné ici autorise aussi la modification des tâches côté Duplicati. Exposez donc l'interface uniquement sur un réseau de confiance et réservez ce mot de passe à Vigicap.
ESET PROTECTNot verified against a live instanceSaaSObjectives 1, 9username, passwordUtilisateur dédié avec le droit « Integrations » et un jeu d'autorisations en LECTURE SEULE (ESET Business Account).
Fleet (osquery)Verified against a live instanceSelf-hostedObjectives 1, 5, 18apiTokenUtilisateur API-only, rôle Observer — lecture seule, sans accès à l'interface.
Fortinet FortiGateNot verified against a live instanceSelf-hostedObjectives 7, 9apiTokenAdministrateur d'API REST avec le profil super_admin_readonly (ou un profil entièrement en lecture), restreint par hôtes de confiance.
FreeIPANot verified against a live instanceSelf-hostedObjective 10username, passwordNot documented to date
GLPIVerified against a live instanceSelf-hostedObjective 1appToken, userTokenNot documented to date
GoPhishVerified against a live instanceSelf-hostedObjective 4apiKeyNot documented to date
Grafana LokiVerified against a live instanceSelf-hostedObjective 20username, password, orgIdNot documented to date
GraylogVerified against a live instanceSelf-hostedObjective 20apiTokenNot documented to date
GreenboneVerified against a live instanceSelf-hostedObjective 5username, passwordGMP n'a pas de rôle applicatif « lecture seule » séparé pour un compte web standard — créez un utilisateur dédié avec le rôle intégré « Guest » ou « Info » (Administration > Users) plutôt que de réutiliser le compte admin.
HashiCorp VaultVerified against a live instanceSelf-hostedObjective 10token, namespaceNot documented to date
IT GlueNot verified against a live instanceSaaSObjectives 1, 3apiKey, organizationIdClé d'API IT Glue (sa création requiert un compte Administrateur ; la clé elle-même est en lecture pour cette intégration).
Kaseya VSANot verified against a live instanceSaaSObjectives 1, 5username, personalAccessTokenUtilisateur dédié dont le scope est limité aux organisations de ce client, avec jeton personnel.
Keeper SecurityNot verified against a live instanceSaaSObjective 10apiTokenNot documented to date
KeycloakVerified against a live instanceSelf-hostedObjective 10realm, clientId, clientSecretService account avec exactement view-users, query-users et view-realm sur realm-management — aucune écriture.
KnowBe4Not verified against a live instanceSaaSObjective 4apiTokenNot documented to date
KopiaVerified against a live instanceSelf-hostedObjective 13username, passwordLe serveur Kopia n'expose qu'un seul couple identifiant/mot de passe HTTP (--server-username / --server-password) : il n'existe pas de rôle « lecture seule » distinct. Utilisez ce couple, et non le compte de contrôle (--server-control-username), qui autorise en plus le pilotage du serveur.
MeshCentralVerified against a live instanceSelf-hostedObjectives 1, 11username, passwordMeshCentral n'a pas de rôle « lecture seule » séparé : tout compte capable de lister les appareils et les comptes est un compte à droits d'administration partiels ou complets. Créez un compte dédié plutôt que de réutiliser un compte technicien existant.
NessusVerified against a live instanceSelf-hostedObjective 5accessKey, secretKeyNot documented to date
NetBoxVerified against a live instanceCan keep one marker per asset (opt-in)Self-hostedObjective 1apiTokenNot documented to date
NinjaOneNot verified against a live instanceSaaSObjectives 1, 5, 9, 18clientId, clientSecret, organizationIdApplication « Client Credentials » avec le seul scope monitoring (lecture seule), limitée à l'organisation du client.
OCS InventoryVerified against a live instanceSelf-hostedObjective 1username, passwordNot documented to date
OpenSearchVerified against a live instanceSelf-hostedObjective 20username, passwordCompte du plugin de sécurité disposant au minimum de la lecture sur _cluster/health et _cat/indices.
OPNsense / pfSenseNot verified against a live instanceSelf-hostedObjective 7apiKey, apiSecretNot documented to date
Pi-holeVerified against a live instanceSelf-hostedObjective 9appPasswordNot documented to date
privacyIDEAVerified against a live instanceSelf-hostedObjective 10username, passwordNot documented to date
Proxmox Backup ServerVerified against a live instanceSelf-hostedObjective 13tokenId, secretNot documented to date
Proxmox VENot verified against a live instanceCan keep one marker per asset (opt-in)Self-hostedObjectives 1, 13tokenId, secretToken d'API avec Privilege Separation activée et le rôle PVEAuditor sur / avec propagation.
SentinelOneNot verified against a live instanceSaaSObjectives 9, 12apiTokenNot documented to date
Snipe-ITVerified against a live instanceSelf-hostedObjective 1apiTokenNot documented to date
Sophos CentralNot verified against a live instanceSaaSObjectives 9, 18clientId, clientSecretIdentifiants d'API avec le rôle « Service Principal Read-Only », créés au niveau du tenant et non du partenaire.
Synology DSMNot verified against a live instanceSelf-hostedObjective 13account, passwordCréez un utilisateur DSM dédié (Panneau de configuration > Utilisateur et groupe) sans droit d'administration et sans accès aux dossiers partagés : ce connecteur n'appelle que SYNO.API.Info et SYNO.API.Auth. La double authentification doit être désactivée sur ce seul compte de service — DSM refuse une connexion par API lorsqu'elle est exigée (codes 403 et 406).
Tactical RMMNot verified against a live instanceSelf-hostedObjectives 1, 5apiKeyUne clé API est émise POUR un utilisateur et hérite de son rôle — créez un utilisateur dédié avec un rôle en lecture seule (Settings > User Management > Roles) avant de générer sa clé (Settings > Global Settings > API Keys).
TeleportVerified against a live instanceSelf-hostedObjectives 8, 11username, password, otpSecretCréez un rôle dédié accordant uniquement `read`/`list` sur user, role, node, event, session et cluster_auth_preference, plus `node_labels: {'*': '*'}` avec `logins: []`. Les labels sont indispensables : sans eux la liste des ressources revient VIDE au lieu de refuser, et `logins` vide garantit que le compte voit le parc sans pouvoir y ouvrir de session. N'utilisez pas les rôles intégrés `editor` ou `access`.
TheHiveVerified against a live instanceSelf-hostedObjective 12apiKeyCréez un utilisateur dédié dans l'organisation concernée avec le profil intégré « read-only », puis générez sa clé d'API (Organisation > Users > Preview > API key). Ce profil n'accorde aucune permission d'écriture et suffit à compter les dossiers — vérifié.
ThreatDown (Malwarebytes)Not verified against a live instanceSaaSObjective 9clientId, clientSecret, accountIdCouple client_id / client_secret de portée « read ».
UrBackupNot verified against a live instanceSelf-hostedObjective 13username, passwordNot documented to date
VadeNot verified against a live instanceSaaSObjective 9login, passwordNot documented to date
VeeamNot verified against a live instanceSelf-hostedObjective 13username, password, apiVersionNot documented to date
VMware vSphereNot verified against a live instanceSelf-hostedObjective 1username, passwordUtilisateur vCenter SSO avec le rôle « Read Only » sur l'objet racine, propagé aux enfants.
WazuhVerified against a live instanceSelf-hostedObjectives 12, 20username, passwordNot documented to date
ZabbixVerified against a live instanceSelf-hostedObjective 13apiTokenNot documented to date
ZitadelVerified against a live instanceSelf-hostedObjective 10patNot documented to date

Agency connectors, the whole portfolio (16)

A single credential reads the entire portfolio — a materially different exposure, which is why it has its own section.

ToolHostingReCyF objectives readCredential heldRequired access right
Action1Verified against a live instanceSaaSObjectives 1, 5clientId, clientSecretNot documented to date
Cisco MerakiVerified against a live instanceSaaSObjectives 1, 5apiKeyClé d'API Meraki en lecture seule (rôle « read-only » sur l'organisation).
Comet BackupNot verified against a live instanceSaaSObjective 13username, passwordNot documented to date
Datto Autotask PSANot verified against a live instanceSaaS—apiIntegrationCode, username, secretNot documented to date
DomotzVerified against a live instanceSaaSObjective 1apiKeyNot documented to date
HaloPSAVerified against a live instanceSaaS—clientId, clientSecret, authUrlApplication API « Client Credentials » portant exactement deux permissions, toutes deux en lecture : « read:customers » (GET /Client, la liste des clients) et « read:assets » (GET /Asset, l'inventaire). Aucune permission d'écriture, et pas le scope « all ».
HornetsecurityNot verified against a live instanceSaaSObjective 9apiToken, appIdNot documented to date
HuduVerified against a live instanceSaaSObjective 1apiKeyNot documented to date
HuntressVerified against a live instanceSaaSObjectives 1, 10, 12, 18apiKey, apiSecretClé d'API Huntress en lecture (compte partenaire).
Kaseya BMSNot verified against a live instanceSaaS—username, password, tenantNot documented to date
LansweeperNot verified against a live instanceSaaS—apiTokenNot documented to date
LiongardNot verified against a live instanceSaaS—accessKey, accessSecretNot documented to date
SendmarcNot verified against a live instanceSaaSObjective 9apiKeyNot documented to date
SuperOpsVerified against a live instanceSaaSObjective 1apiToken, subdomainNot documented to date
SyncroNot verified against a live instanceSaaSObjective 9subdomain, apiKeyNot documented to date
UniFi Site ManagerNot verified against a live instanceSaaSObjectives 1, 5apiKeyNot documented to date

Outbound to a PSA tool (5)

The only family that WRITES. An outbound flow needs documenting more than an inbound one, because it is the case where data leaves for a system we do not operate.

ToolHostingReCyF objectives readCredential heldRequired access right
AteraNot verified against a live instanceSaaS—apiKeyClé d'API Atera. ÉCRITURE : la clé Atera n'est pas cloisonnable en lecture seule — elle porte les droits du compte qui l'a créée. LECTURE : la même clé relit le ticket ; aucune portée distincte n'existe, ce qui est précisément pourquoi la phrase précédente est écrite telle quelle.
ConnectWise ManageNot verified against a live instanceSaaS—companyId, publicKey, privateKey, clientIdMembre d'API ConnectWise (clés publique + privée). ÉCRITURE : droit de création sur le board de tickets visé. LECTURE : droit de lecture sur ce même board (Service Desk → Service Tickets), pour relire le statut d'un ticket déjà créé.
Datto AutotaskNot verified against a live instanceSaaS—apiIntegrationCode, username, secretUtilisateur d'API Autotask dédié. ÉCRITURE : droit de création de tickets sur la file visée. LECTURE : le niveau de sécurité de l'utilisateur d'API doit accorder la vue des tickets — l'entité Ticket respecte les droits View/Add/Edit du compte connecté.
HaloPSAVerified against a live instanceSaaS—clientId, clientSecret, authUrlApplication API « Client Credentials » portant exactement trois permissions : « edit:tickets » (ÉCRITURE — création du ticket, POST /Tickets), « read:tickets » (relecture du statut, GET /Tickets/{id}) et « read:customers » (vérification de l'ID client au moment où il est saisi, GET /Client/{id}). Aucune autre, et pas le scope « all ».
NinjaOneNot verified against a live instanceSaaS—clientId, clientSecretApplication « Client Credentials », scope monitoring/management. ÉCRITURE : management est requis pour créer un ticket. LECTURE : le même jeton relit le ticket et la liste des statuts ; NinjaOne ne documente pas de portée plus étroite pour /v2/ticketing.

The same data, as JSON: /api/connectors/data-inventory