Trust
Per-connector data inventory
The table a data protection officer asks for, and the input to an article 30 record. It is generated from the connector registry on every release: a hand-maintained inventory is a promise that decays, and this is the table you show a regulator.
Generated on 1 October 2026
What does not vary
Three of the four answers are uniform per direction — by construction rather than convenience: a connector module has no database handle at all. The one exception is declared below, connector by connector, rather than buried here.
- Kept from a read: one headline, at most six numeric tiles, and a proposed ReCyF level.
- No raw response from a third-party tool is ever kept.
- Credentials are encrypted at rest and deleted on disconnection.
- What goes out to a PSA tool is a summary, a plain-text body, and the source that produced it.
- What comes back from a PSA tool is the state of an already-created ticket: its status, its closure date and its last activity. A closure becomes a proposal a consultant validates — never an action closed on its own.
- Summaries carry no person's name — verified by a test, not guaranteed by the type system.
- When an agency switches it on for a connection, that connector also keeps one opaque marker per asset: a keyed digest of the source tool's own internal identifier — never a machine name, a serial number or an IP address. It can say that three machines disappeared; it can never say which.
- That option exists for 2 connectors of 76, it is off by default, and switching it off deletes the markers already held.
What is not documented yet
The required access right is still to be documented for 45 of 76 connectors. The cell is empty rather than filled with a guess: an inventory that guessed "read-only role" for a tool whose permission model was never checked would be an unverifiable claim in front of the one audience that tests it.
OAuth connectors (2)
Your client's own administrator consents, sees the list of permissions on their own consent screen, and can revoke them without asking us.
| Tool | Hosting | ReCyF objectives read | Credential held | Required access right |
|---|---|---|---|---|
| Google WorkspaceVerified against a live instance | SaaS | Objective 10 | oauth-consent (refresh token, encrypted) | openid, email, https://www.googleapis.com/auth/admin.directory.user.readonly |
| Microsoft 365Verified against a live instance | SaaS | Objectives 1, 10, 18 | oauth-consent (refresh token, encrypted) | openid, profile, offline_access, https://graph.microsoft.com/User.Read.All, https://graph.microsoft.com/AuditLog.Read.All, https://graph.microsoft.com/DeviceManagementManagedDevices.Read.All |
Credential connectors, one client (53)
One credential per client, supplied by the agency, encrypted at rest.
| Tool | Hosting | ReCyF objectives read | Credential held | Required access right |
|---|---|---|---|---|
| Acronis Cyber ProtectNot verified against a live instance | SaaS | Objectives 9, 13 | clientId, clientSecret | Not documented to date |
| AdGuard HomeVerified against a live instance | Self-hosted | Objective 9 | username, password | Not documented to date |
| AuthentikVerified against a live instance | Self-hosted | Objective 10 | apiToken | Not documented to date |
| BareosVerified against a live instance | Self-hosted | Objective 13 | consoleName, consolePassword | Créez un Console dédié (bareos-dir.d/console/) rattaché à un Profile dont la Command ACL se limite aux commandes de lecture — « status, show, list, llist, .jobs » suffisent à ce connecteur — plutôt que de réutiliser le profil « operator » ou la console par défaut. |
| Bitdefender GravityZoneNot verified against a live instance | SaaS | Objectives 1, 9 | apiKey | Not documented to date |
| BitwardenNot verified against a live instance | Self-hosted | Objective 10 | clientId, clientSecret | Not documented to date |
| CrowdSecVerified against a live instance | Self-hosted | Objective 12 | apiKey | Not documented to date |
| Datto BCDRNot verified against a live instance | SaaS | Objective 13 | publicKey, secretKey | Not documented to date |
| Datto RMMNot verified against a live instance | SaaS | Objectives 1, 5, 9 | apiKey, apiSecretKey, siteUid | Not documented to date |
| DefectDojoVerified against a live instance | Self-hosted | Objective 5 | apiToken | Not documented to date |
| DuplicatiVerified against a live instance | Self-hosted | Objective 13 | password | Duplicati n'a qu'un seul secret pour son interface web (DUPLICATI__WEBSERVICE_PASSWORD) et aucun rôle « lecture seule » : le mot de passe donné ici autorise aussi la modification des tâches côté Duplicati. Exposez donc l'interface uniquement sur un réseau de confiance et réservez ce mot de passe à Vigicap. |
| ESET PROTECTNot verified against a live instance | SaaS | Objectives 1, 9 | username, password | Utilisateur dédié avec le droit « Integrations » et un jeu d'autorisations en LECTURE SEULE (ESET Business Account). |
| Fleet (osquery)Verified against a live instance | Self-hosted | Objectives 1, 5, 18 | apiToken | Utilisateur API-only, rôle Observer — lecture seule, sans accès à l'interface. |
| Fortinet FortiGateNot verified against a live instance | Self-hosted | Objectives 7, 9 | apiToken | Administrateur d'API REST avec le profil super_admin_readonly (ou un profil entièrement en lecture), restreint par hôtes de confiance. |
| FreeIPANot verified against a live instance | Self-hosted | Objective 10 | username, password | Not documented to date |
| GLPIVerified against a live instance | Self-hosted | Objective 1 | appToken, userToken | Not documented to date |
| GoPhishVerified against a live instance | Self-hosted | Objective 4 | apiKey | Not documented to date |
| Grafana LokiVerified against a live instance | Self-hosted | Objective 20 | username, password, orgId | Not documented to date |
| GraylogVerified against a live instance | Self-hosted | Objective 20 | apiToken | Not documented to date |
| GreenboneVerified against a live instance | Self-hosted | Objective 5 | username, password | GMP n'a pas de rôle applicatif « lecture seule » séparé pour un compte web standard — créez un utilisateur dédié avec le rôle intégré « Guest » ou « Info » (Administration > Users) plutôt que de réutiliser le compte admin. |
| HashiCorp VaultVerified against a live instance | Self-hosted | Objective 10 | token, namespace | Not documented to date |
| IT GlueNot verified against a live instance | SaaS | Objectives 1, 3 | apiKey, organizationId | Clé d'API IT Glue (sa création requiert un compte Administrateur ; la clé elle-même est en lecture pour cette intégration). |
| Kaseya VSANot verified against a live instance | SaaS | Objectives 1, 5 | username, personalAccessToken | Utilisateur dédié dont le scope est limité aux organisations de ce client, avec jeton personnel. |
| Keeper SecurityNot verified against a live instance | SaaS | Objective 10 | apiToken | Not documented to date |
| KeycloakVerified against a live instance | Self-hosted | Objective 10 | realm, clientId, clientSecret | Service account avec exactement view-users, query-users et view-realm sur realm-management — aucune écriture. |
| KnowBe4Not verified against a live instance | SaaS | Objective 4 | apiToken | Not documented to date |
| KopiaVerified against a live instance | Self-hosted | Objective 13 | username, password | Le serveur Kopia n'expose qu'un seul couple identifiant/mot de passe HTTP (--server-username / --server-password) : il n'existe pas de rôle « lecture seule » distinct. Utilisez ce couple, et non le compte de contrôle (--server-control-username), qui autorise en plus le pilotage du serveur. |
| MeshCentralVerified against a live instance | Self-hosted | Objectives 1, 11 | username, password | MeshCentral n'a pas de rôle « lecture seule » séparé : tout compte capable de lister les appareils et les comptes est un compte à droits d'administration partiels ou complets. Créez un compte dédié plutôt que de réutiliser un compte technicien existant. |
| NessusVerified against a live instance | Self-hosted | Objective 5 | accessKey, secretKey | Not documented to date |
| NetBoxVerified against a live instanceCan keep one marker per asset (opt-in) | Self-hosted | Objective 1 | apiToken | Not documented to date |
| NinjaOneNot verified against a live instance | SaaS | Objectives 1, 5, 9, 18 | clientId, clientSecret, organizationId | Application « Client Credentials » avec le seul scope monitoring (lecture seule), limitée à l'organisation du client. |
| OCS InventoryVerified against a live instance | Self-hosted | Objective 1 | username, password | Not documented to date |
| OpenSearchVerified against a live instance | Self-hosted | Objective 20 | username, password | Compte du plugin de sécurité disposant au minimum de la lecture sur _cluster/health et _cat/indices. |
| OPNsense / pfSenseNot verified against a live instance | Self-hosted | Objective 7 | apiKey, apiSecret | Not documented to date |
| Pi-holeVerified against a live instance | Self-hosted | Objective 9 | appPassword | Not documented to date |
| privacyIDEAVerified against a live instance | Self-hosted | Objective 10 | username, password | Not documented to date |
| Proxmox Backup ServerVerified against a live instance | Self-hosted | Objective 13 | tokenId, secret | Not documented to date |
| Proxmox VENot verified against a live instanceCan keep one marker per asset (opt-in) | Self-hosted | Objectives 1, 13 | tokenId, secret | Token d'API avec Privilege Separation activée et le rôle PVEAuditor sur / avec propagation. |
| SentinelOneNot verified against a live instance | SaaS | Objectives 9, 12 | apiToken | Not documented to date |
| Snipe-ITVerified against a live instance | Self-hosted | Objective 1 | apiToken | Not documented to date |
| Sophos CentralNot verified against a live instance | SaaS | Objectives 9, 18 | clientId, clientSecret | Identifiants d'API avec le rôle « Service Principal Read-Only », créés au niveau du tenant et non du partenaire. |
| Synology DSMNot verified against a live instance | Self-hosted | Objective 13 | account, password | Créez un utilisateur DSM dédié (Panneau de configuration > Utilisateur et groupe) sans droit d'administration et sans accès aux dossiers partagés : ce connecteur n'appelle que SYNO.API.Info et SYNO.API.Auth. La double authentification doit être désactivée sur ce seul compte de service — DSM refuse une connexion par API lorsqu'elle est exigée (codes 403 et 406). |
| Tactical RMMNot verified against a live instance | Self-hosted | Objectives 1, 5 | apiKey | Une clé API est émise POUR un utilisateur et hérite de son rôle — créez un utilisateur dédié avec un rôle en lecture seule (Settings > User Management > Roles) avant de générer sa clé (Settings > Global Settings > API Keys). |
| TeleportVerified against a live instance | Self-hosted | Objectives 8, 11 | username, password, otpSecret | Créez un rôle dédié accordant uniquement `read`/`list` sur user, role, node, event, session et cluster_auth_preference, plus `node_labels: {'*': '*'}` avec `logins: []`. Les labels sont indispensables : sans eux la liste des ressources revient VIDE au lieu de refuser, et `logins` vide garantit que le compte voit le parc sans pouvoir y ouvrir de session. N'utilisez pas les rôles intégrés `editor` ou `access`. |
| TheHiveVerified against a live instance | Self-hosted | Objective 12 | apiKey | Créez un utilisateur dédié dans l'organisation concernée avec le profil intégré « read-only », puis générez sa clé d'API (Organisation > Users > Preview > API key). Ce profil n'accorde aucune permission d'écriture et suffit à compter les dossiers — vérifié. |
| ThreatDown (Malwarebytes)Not verified against a live instance | SaaS | Objective 9 | clientId, clientSecret, accountId | Couple client_id / client_secret de portée « read ». |
| UrBackupNot verified against a live instance | Self-hosted | Objective 13 | username, password | Not documented to date |
| VadeNot verified against a live instance | SaaS | Objective 9 | login, password | Not documented to date |
| VeeamNot verified against a live instance | Self-hosted | Objective 13 | username, password, apiVersion | Not documented to date |
| VMware vSphereNot verified against a live instance | Self-hosted | Objective 1 | username, password | Utilisateur vCenter SSO avec le rôle « Read Only » sur l'objet racine, propagé aux enfants. |
| WazuhVerified against a live instance | Self-hosted | Objectives 12, 20 | username, password | Not documented to date |
| ZabbixVerified against a live instance | Self-hosted | Objective 13 | apiToken | Not documented to date |
| ZitadelVerified against a live instance | Self-hosted | Objective 10 | pat | Not documented to date |
Agency connectors, the whole portfolio (16)
A single credential reads the entire portfolio — a materially different exposure, which is why it has its own section.
| Tool | Hosting | ReCyF objectives read | Credential held | Required access right |
|---|---|---|---|---|
| Action1Verified against a live instance | SaaS | Objectives 1, 5 | clientId, clientSecret | Not documented to date |
| Cisco MerakiVerified against a live instance | SaaS | Objectives 1, 5 | apiKey | Clé d'API Meraki en lecture seule (rôle « read-only » sur l'organisation). |
| Comet BackupNot verified against a live instance | SaaS | Objective 13 | username, password | Not documented to date |
| Datto Autotask PSANot verified against a live instance | SaaS | — | apiIntegrationCode, username, secret | Not documented to date |
| DomotzVerified against a live instance | SaaS | Objective 1 | apiKey | Not documented to date |
| HaloPSAVerified against a live instance | SaaS | — | clientId, clientSecret, authUrl | Application API « Client Credentials » portant exactement deux permissions, toutes deux en lecture : « read:customers » (GET /Client, la liste des clients) et « read:assets » (GET /Asset, l'inventaire). Aucune permission d'écriture, et pas le scope « all ». |
| HornetsecurityNot verified against a live instance | SaaS | Objective 9 | apiToken, appId | Not documented to date |
| HuduVerified against a live instance | SaaS | Objective 1 | apiKey | Not documented to date |
| HuntressVerified against a live instance | SaaS | Objectives 1, 10, 12, 18 | apiKey, apiSecret | Clé d'API Huntress en lecture (compte partenaire). |
| Kaseya BMSNot verified against a live instance | SaaS | — | username, password, tenant | Not documented to date |
| LansweeperNot verified against a live instance | SaaS | — | apiToken | Not documented to date |
| LiongardNot verified against a live instance | SaaS | — | accessKey, accessSecret | Not documented to date |
| SendmarcNot verified against a live instance | SaaS | Objective 9 | apiKey | Not documented to date |
| SuperOpsVerified against a live instance | SaaS | Objective 1 | apiToken, subdomain | Not documented to date |
| SyncroNot verified against a live instance | SaaS | Objective 9 | subdomain, apiKey | Not documented to date |
| UniFi Site ManagerNot verified against a live instance | SaaS | Objectives 1, 5 | apiKey | Not documented to date |
Outbound to a PSA tool (5)
The only family that WRITES. An outbound flow needs documenting more than an inbound one, because it is the case where data leaves for a system we do not operate.
| Tool | Hosting | ReCyF objectives read | Credential held | Required access right |
|---|---|---|---|---|
| AteraNot verified against a live instance | SaaS | — | apiKey | Clé d'API Atera. ÉCRITURE : la clé Atera n'est pas cloisonnable en lecture seule — elle porte les droits du compte qui l'a créée. LECTURE : la même clé relit le ticket ; aucune portée distincte n'existe, ce qui est précisément pourquoi la phrase précédente est écrite telle quelle. |
| ConnectWise ManageNot verified against a live instance | SaaS | — | companyId, publicKey, privateKey, clientId | Membre d'API ConnectWise (clés publique + privée). ÉCRITURE : droit de création sur le board de tickets visé. LECTURE : droit de lecture sur ce même board (Service Desk → Service Tickets), pour relire le statut d'un ticket déjà créé. |
| Datto AutotaskNot verified against a live instance | SaaS | — | apiIntegrationCode, username, secret | Utilisateur d'API Autotask dédié. ÉCRITURE : droit de création de tickets sur la file visée. LECTURE : le niveau de sécurité de l'utilisateur d'API doit accorder la vue des tickets — l'entité Ticket respecte les droits View/Add/Edit du compte connecté. |
| HaloPSAVerified against a live instance | SaaS | — | clientId, clientSecret, authUrl | Application API « Client Credentials » portant exactement trois permissions : « edit:tickets » (ÉCRITURE — création du ticket, POST /Tickets), « read:tickets » (relecture du statut, GET /Tickets/{id}) et « read:customers » (vérification de l'ID client au moment où il est saisi, GET /Client/{id}). Aucune autre, et pas le scope « all ». |
| NinjaOneNot verified against a live instance | SaaS | — | clientId, clientSecret | Application « Client Credentials », scope monitoring/management. ÉCRITURE : management est requis pour créer un ticket. LECTURE : le même jeton relit le ticket et la liste des statuts ; NinjaOne ne documente pas de portée plus étroite pour /v2/ticketing. |
The same data, as JSON: /api/connectors/data-inventory