140+ connectors · open-source
PRODUCT140+ first-party connectors across cloud, identity, code, devices, data, and vendors each reading the real API surface its engineers use, with read-only scoped credentials. Missing one? Our connectors are open-source; open a PR.
A surface-level integration tells you what a vendor's UI is willing to show. A deep one reads the same API the product's own engineers build against typed, complete, and verifiable. That's the only kind Uproot ships.
Assume a read-only role or grant a least-scope token. No long-lived keys, no write access, no production blast radius. First sync completes before the kickoff call ends.
Each connector maps the source's full surface to a typed model IAM policies, device records, merge events. Controls assert against that model, so checks are precise, not approximate.
Connectors poll on a tuned cadence and subscribe to webhooks where the source supports them so a new IAM policy or merged PR shows up in seconds, not on the next nightly run.
Access is short-lived and rotated on a schedule you control. There's no static key sitting in a config file waiting to leak. Revoke a connector and its access is gone immediately.
Connectors are the foundation everything else stands on monitoring, evidence, vendor risk. So they're engineered to the same bar as the rest of your stack, and they're open for you to read and extend.
The AWS connector alone reads dozens of services IAM, S3, RDS, KMS, CloudTrail, EC2, EKS as typed objects your controls assert against. You’re not limited to whatever a generic "cloud security" checkbox exposes.
Typed models for every resource a control might reference
Multi-account, multi-region, multi-org from one connection
New API surfaces tracked as the provider ships them
Every integration assumes a read-only role with short-lived, rotated credentials. No standing keys to leak, no write path to abuse, and a one-click revoke that takes effect immediately. Self-host the agent in your VPC if your boundary requires it.
Read-only scopes, reviewed and documented per connector
Short-lived credentials, auto-rotated no static keys
Optional self-hosted agent runs entirely inside your network
Every connector is open-source. Audit exactly what it reads before you connect it. And if you run something niche, the connector SDK lets you build and contribute your own the same framework we use for first-party sources.
Public source for all 140+ connectors auditable scopes
Connector SDK with a local harness and fixtures
Contribute upstream, or keep a private connector internal
140+ connectors organized across the surfaces a security program has to cover. Here’s a sample of each the full catalog is in the docs.
The control plane behind your product read as typed resources across every account and region.
Who can reach what, with which factor the backbone of nearly every access control.
Branch protections, approvals, signed commits, and pipeline gates your SDLC controls, observed.
Disk encryption, OS posture, and endpoint detection read from MDM and EDR, not a survey.
Where sensitive data lives and how it's watched warehouses, databases, and monitoring.
People, tickets, and vendors the human-process evidence frameworks keep asking for.
When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort.

Connecting your whole environment is a trust decision. Here's what the connector layer does and doesn't do.
A shallow integration OAuths in and reads whatever summary the vendor's UI exposes. A deep connector maps the source's full API surface to typed objects your controls assert against precise and complete, not a vendor's idea of a security view.
No connector needs write scope to read your posture. Remediation features (like opening a rollback PR) use a separate, opt-in GitHub app permission the monitoring and evidence layer is strictly read-only.
Through short-lived, auto-rotated credentials STS role assumption for AWS, scoped tokens elsewhere. No long-lived keys stored anywhere, and revoking a connector cuts its access immediately.
The connector SDK lets you build one with a local test harness and fixtures, then contribute it upstream or keep it private. Because the connectors are open-source, you're never blocked on our roadmap.
Yes. The agent can be self-hosted in your VPC, so data and credentials never leave your boundary same connectors, running on your side of the line. Useful when regulatory or contractual requirements demand it.
Assume a read-only role, watch the first sync land, and see your real posture before the trial email arrives. Read the connector source first if you like it's all public.
140+ connectors
Cloud, identity, code, devices, data, vendors.
Read-only & rotating
No static keys, no write path.
Open-source
Audit any connector before you trust it.
Extensible
Build the connector we're missing with the SDK.