Integrations

Zero Trust that fits the stack you already run.

InstaSafe sits between your people and your applications — so it has to speak to both ends of what you already own. Your directory stays the source of truth, your SIEM keeps receiving the events, and your cloud keeps its inbound ports closed.

  • 800+SAML, OAuth and OIDC applications
  • 55named integrations, documented
  • 7SIEM export formats

Identity & authentication

Authenticate against the directory you already run. Users and groups sync in, and the joiners-movers-leavers process you already have stays the one that governs access.

  • Active DirectorySync users and groups from the directory of record. Entitlement follows the group, not a second list.
  • Microsoft Entra IDFederate to Entra ID as your identity provider, or act as one for the applications it does not reach.
  • Google WorkspaceSingle sign-on plus user and group provisioning, so a Workspace account is the whole identity.
  • OktaKeep Okta as the identity provider; InstaSafe enforces it on the network path Okta cannot see.
  • OneLoginAuthentication and group synchronisation, with the access policy evaluated on every request.
  • OpenLDAPRead groups straight from an LDAP server for applications that never learned SAML.
  • ADFSFederate to the Windows trust you already run, without changing what the application understands.
  • Microsoft 365Use the 365 login as the front door, with MFA and device posture attached to it.

Applications

Anything that speaks SAML 2.0, OAuth 2.0 or OpenID Connect sits behind one login — in practice over 800 business applications. These are the ones we are asked about most.

  • SalesforceSAML sign-on with the factor decided by the user's group, not the app.
  • JiraOne login into the tracker, and one action that removes a leaver from it.
  • GitLabOpenID Connect sign-on for the platform and its CI, on the same policy.
  • GitHubSAML sign-on for the organisation, with repository access behind the tunnel.
  • SlackOAuth sign-on, so leaving the directory closes the workspace too.
  • ZoomSAML sign-on for the meeting account, with the same second factor.
  • SAPReach the SAP portal over a per-app tunnel — no inbound port, no VPN.
  • ServiceNowSAML sign-on for the service desk and the records behind it.
  • WorkdaySAML sign-on for HR data, with hardware keys where the group requires them.
  • Microsoft TeamsOne session across Teams and the rest of the 365 estate.
  • DropboxSAML sign-on with download controls applied per group.
  • ZendeskAgent sign-on tied to the directory rather than a local password.
  • NotionSAML sign-on, provisioned from the same groups as everything else.
  • HubSpotSAML sign-on for the CRM, with session recording where it is required.
  • AdobeFederated sign-on for Creative Cloud and Document Cloud seats.
  • DocuSignSAML sign-on for a system that signs things — a good place for a hardware key.
  • MiroSAML sign-on with provisioning, so boards follow the group.
  • MondaySAML sign-on for the work platform and its integrations.
  • FigmaSAML sign-on with SCIM, so design seats are not managed by hand.
  • CanvaSAML sign-on for the brand team's shared workspace.
  • QuickBooksSign-on to the books, behind whatever the finance profile demands.
  • BambooHRSAML sign-on for HR records, with access scoped to the HR group.
  • PipedriveSAML sign-on for the sales pipeline and its exports.
  • GmailWorkspace mail behind the same single login as everything else.

Cloud & infrastructure

Reach private resources in any cloud without opening an inbound port. The gateway runs as software next to the workload, and nothing behind it is published to the internet.

  • AWSPrivate access to VPC resources — instances, databases, internal load balancers.
  • Microsoft AzureReach VNet resources and Azure-managed services without a site-to-site tunnel.
  • Google CloudPrivate access to GCP projects, with the policy evaluated per request.
  • Oracle CloudZTNA in front of OCI compute and database resources.
  • VMwarePublish on-premise virtual desktops and servers without exposing the hypervisor.
  • KubernetesDeploy the gateway into a cluster and reach services without a public ingress.
  • DockerRun the gateway as a container alongside whatever it is protecting.

Device management & security

Posture signals from the tools already on the endpoint. The device has to pass before the connection exists, not after.

  • CrowdStrikeTake the agent's verdict as a posture signal and refuse anything it flags.
  • Microsoft IntuneTrust the Intune compliance state as a device check, so managed and unmanaged separate themselves.

DevOps & automation

Zero Trust at pipeline speed. Access is configuration, so it lands in review with everything else rather than in a ticket queue.

  • TerraformDeclare resources, policies and groups as code and apply them with the rest of your estate.
  • JenkinsGive a build agent a scoped identity instead of a shared credential.
  • GitHubSecure workflows and Codespaces without handing a runner network-wide reach.
  • GitLabBring per-app access into the CI pipeline, scoped to the job that needs it.
  • BitbucketRepository access on the same policy as everything else the developer touches.
  • KubernetesManage gateways and resources declaratively from inside the cluster.

Logging & SIEM

Every access event, in the format your SIEM already ingests. 202 event types, 11 built-in reports and 7 export formats — so the trail lands where your analysts already look.

  • SplunkStream access events in CEF or NDJSON straight into an index.
  • ElasticShip structured events to Elasticsearch for search and dashboards.
  • ArcSightCEF export for estates standardised on ArcSight correlation.
  • SyslogPlain syslog for anything that does not need a named connector.
  • SigNozOpen-source observability for teams who would rather host it themselves.
  • Amazon S3Export raw log data to a bucket for retention and offline analysis.

Internet security

DNS-level filtering alongside the access layer, so a request that should never resolve does not.

  • CloudflareDNS filtering and DNS-over-HTTPS in front of the same managed devices.
  • DNSFilterCategory and threat filtering applied to traffic leaving the endpoint.

//Ready when you are//

Ditch the VPN. Keep your apps invisible.

Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.

Regulated, air-gapped, or on-premise? See deployment options