🔌 Evidence Integrations

Compliance Evidence
Integrations
Tools Become Proof

The tools your clients already run are sitting on the evidence auditors want. Connect them and their data becomes automated compliance evidence — and where there's no API, declare the tool in attest mode.

Connected Evidenceyourclient.com
5
evidence families connected
Awareness training (LMS)AUTOMATED
Backup & recoveryAUTOMATED
Managed EDRAUTOMATED
Incident response (PSA)AUTOMATED
Backup vendor (no API)ATTESTED

The Evidence Already Exists — It’s Just Not in the Report

Your clients run security-awareness training like KnowBe4, a backup platform like Datto, a managed-EDR service like Huntress, an HRIS like BambooHR, and a PSA — HaloPSA, Autotask, Syncro, Atera, or NinjaOne. Every one of them is generating the exact evidence a framework asks for — training completion, tested restores, incident history, personnel screening — and none of it is in the compliance report.

Connect the tool and SBCMSP turns its live data into automated evidence, citing the real numbers under the control. When a framework asks “do users complete awareness training regularly,” the answer stops being a promise and becomes a citation.

No API for a tool? Declare it in attest mode. That records the control as attested — honestly “declared,” not “automated” — and fills only undocumented gaps. It never overwrites live-API evidence or a human answer.

01Connect for Live Evidence
A connected tool marks its controls automated and cites the live data in the report.
02Attest Mode for the Rest
No API? Declare the tool — recorded as attested, filling only undocumented gaps.
03Precedence You Can Trust
Live-API evidence and human answers are never overwritten by an attest-mode declaration.

Five Evidence Families, Real Integrations

Connect a tool a client already runs and its live data is written into the compliance record as automated evidence — the real number, cited under the exact control.

🎓
Awareness Training — KnowBe4
Training-completion rates and phishing-simulation history become live awareness evidence, refreshed as new campaigns close. Maps to NIST PR.AT, SOC 2 CC1.4, ISO A.6.3, HIPAA 164.308(a)(5), CIS 14, PCI 12.6, CMMC AT.1 and FTC §314.4(e).
🎫
Incident Response — Your PSA
HaloPSA, Autotask, Syncro, Atera and NinjaOne need no new connection. The security tickets the platform already opens read back as incident-response evidence — findings tracked to resolution, with a median time-to-close. Maps to NIST RS.MA / RS.CO, SOC 2 CC7.4, ISO A.5.24, CIS 17, HIPAA 164.308(a)(6) and CMMC IR.1.
💾
Backup & Recovery — Datto BCDR
Backup success and screenshot (boot) verification per protected asset become recovery evidence — proof the backups exist and actually restore. Maps to NIST RC.RP, SOC 2 A1.3 / CC7.5, ISO A.8.13, CIS 11, HIPAA 164.308(a)(7) and CMMC RE.1.
👥
Personnel Lifecycle — BambooHR
Hires and terminations from the HRIS become access-control evidence: workforce screening on the way in, access removed on the way out. Maps to ISO A.6.1 / A.6.5 and HIPAA 164.308(a)(3).
🛡️
Managed Detection — Huntress
Managed-EDR deployment coverage and incident handling become continuous-monitoring evidence — endpoints watched, threats worked. Maps to NIST DE.CM, SOC 2 CC6.6 and CIS 10.
🏷️
Vendor Inventory — Built In
No credentials required: a third-party and supply-chain inventory is compiled automatically from tech-stack, software and shadow-IT scanning. Maps to NIST GV.SC, CIS 15, PCI 12.8 and FTC §314.4(f).

Declare the Tool in Attest Mode

Common tools without a live adapter still finish the family. Connecting one records that the client uses it and writes that family’s controls as attested — honestly declared, not API-verified — filling undocumented gaps only. Upgrade to a live feed later with no data migration.

LMS
Awareness Training
Hoxhunt · NINJIO · Curricula
BACKUP
Backup & BCDR
Veeam · Acronis Cyber Protect · Axcient x360
HRIS
Personnel Lifecycle
Rippling · Gusto
EDR
Managed Detection
SentinelOne · CrowdStrike Falcon
LIVE
Live Adapters
KnowBe4 · Datto · Huntress · BambooHR · your PSA
RULE
Attested, Not Automated
Fills undocumented gaps · never overwrites live or human evidence

Connect Once — the Report Stays Current

Sync becomes attestation becomes a cited control, and it keeps itself fresh with zero touch.

🔗
1. Connect Once
Add the client’s tool under Settings → Integrations with a scoped read token — or reuse the PSA you already run. Nothing to install on the endpoint.
🌙
2. Nightly Sync
Every night the platform re-reads each connected tool and refreshes its evidence. A content hash skips the write entirely when nothing has changed since the last run.
🏢
3. Per-Domain Fan-Out
One KnowBe4 tenant behind twenty client domains writes twenty cited reports. Domains are the compliance unit, so every client sees their own evidence.
📌
4. Written as a Citation
Live data lands as an automated attestation with an auditor-facing note printed under the control — the real number, the source tool and the date.
🔒
5. Precedence You Can Trust
Live-API evidence and a human’s own answer are never overwritten. An attest-mode declaration fills only undocumented gaps and yields the moment a live feed arrives.
🗺️
6. Maps Across Frameworks
Evidence propagates through concept families — connect one tool and it satisfies the equivalent control in every standard you assess, from NIST CSF and SOC 2 to ISO 27001, CIS, HIPAA, PCI DSS, CMMC and FTC Safeguards.

Common Questions About Evidence Integrations

Which kinds of tools can I connect?
Five evidence families: security-awareness training (LMS), incident response (PSA ticket history), backup and recovery, personnel lifecycle (HRIS), and managed endpoint detection (EDR). A connected tool marks its controls automated and cites its live data.
What if a client’s tool has no API?
Declare it in attest mode. That records the control as attested — honestly “declared,” not “automated” — and fills only undocumented gaps. It never overwrites live-API evidence or a human answer.
Does connecting a tool keep the report current?
Yes. A nightly sync refreshes connected evidence, so training completion, backup testing, and incident history in the report reflect the latest data.
Does one integration only help one framework?
No. Evidence propagates across frameworks via concept families, so connecting a single tool can satisfy the equivalent control in every standard you assess.

Turn Client Tooling Into Audit Evidence

Connect what has an API, declare what doesn’t — and let the report cite real data.

→ Start Free Trial

Part of the SBCMSP Platform

Connected evidence feeds the same compliance record SBCMSP uses everywhere — mapped to frameworks, sharable with auditors, and summarized for clients.