Box
Scans Box enterprise file and folder sharing and collaborations to find public links and over-broad external access.
DisponibleToutes les sources qu'8200.dev peut analyser dès aujourd'hui — des connecteurs en lecture seule qui cartographient qui et quoi peut accéder à vos données. Aucune installation requise, révocables à tout moment.
23 connecteurs, un modèle de permissions unifié.
Scans Box enterprise file and folder sharing and collaborations to find public links and over-broad external access.
DisponibleScans Dropbox Business team folders, shared links, and membership to surface external sharing and public-link exposure.
DisponibleScans Google Drive files and folders, their sharing settings, and the user directory to map who can access what across your Workspace.
DisponibleScans SharePoint / OneDrive sharing, inventories Entra (Azure AD) app registrations, service principals and their consented scopes, and audits the tenant security posture (Security Defaults, Conditional Access, MFA coverage, app consent, admin roles).
DisponibleScans workspace page and database sharing, member access, and connected integrations to surface over-broad or public exposure.
DisponibleScans channel and file sharing exposure, inventories installed apps, bots, and integrations and their OAuth token scopes (the AI-agent / shadow-AI surface), and audits the workspace security configuration (2FA enforcement, app-install policy, public file sharing, external Slack Connect channels).
DisponibleScans AWS IAM users, roles, groups, and policies to map effective permissions and find over-privileged or stale principals.
DisponibleAudits your Azure AD (Microsoft Entra ID) directory — MFA coverage and Conditional Access, legacy-auth blocking, privileged-role sprawl (Global Admins, admins without MFA, PIM), over-privileged app identities, guests and external collaboration, Identity Protection risk (at-risk / compromised users), group hygiene, and audit-log retention. Identity-infrastructure posture, read-only — distinct from the Microsoft 365 file/content scan.
DisponibleAudits your Google Cloud (GCP) project security posture — project IAM (service-account keys, primitive-role sprawl, inactive and external principals, public bindings), enabled APIs and API-key restrictions, Cloud Audit Log coverage and retention, VPC firewall exposure (SSH/RDP open to the internet), and public Cloud Storage buckets. Read-only.
DisponibleScans Okta users, application assignments, and group memberships to map who can sign in to which application.
DisponibleScans your Intercom support workspace — the Fin AI Agent and custom bots (their knowledge sources, sensitive-topic answering, external data sources, and human-handover policy), teammates (admins) and 2FA, installed integrations, and Messenger security (identity verification).
DisponibleScans your Telegram bots — the identity and capabilities of each bot (including whether it can read all group messages) and its webhook posture: HTTP vs HTTPS, self-signed certificates, data flowing to external AI providers, and unmonitored update backlogs.
DisponibleAudits your WhatsApp Business Accounts — 2-Step Verification, phone-number verification and quality, system-user permissions (MANAGE), and connected-app scopes. Read-only; never message contents.
DisponibleScans your Zendesk support account — Zendesk AI bots and agent Copilot (sensitive-field and PII access, escalation policy), agents and admins, custom roles with elevated access, installed marketplace apps, and account security (SSO, 2FA enforcement, public ticket sharing, API-token age).
DisponibleScans your Anthropic organization: API keys, member roles, workspaces, and the daily usage report — flags inactive-but-unrevoked keys, default-workspace (org-wide) keys, orphaned keys, never-expiring keys, admin sprawl, and usage spikes vs your own 30-day baseline.
DisponibleConnects your ChatGPT Enterprise workspace’s Compliance Logs Platform (a separate product from the OpenAI API): exported log windows for conversations metadata, file uploads, admin actions, and auth events become governance evidence — and an empty stream is flagged before the 30-day retention erases it.
DisponibleScans your Cursor team via the server-side Admin API: members/roles, per-seat daily activity, and spend — flags owner sprawl, paid seats with zero activity, and uncapped usage-based spend. Client-side telemetry is never used.
DisponibleWorks for a personal account or an organization — detected automatically. Scans repository visibility, collaborator access, deploy keys, and installed GitHub Apps and their scopes.
DisponibleAudits your Jira Cloud site — public projects and "Anyone on the web" filters/dashboards, admin sprawl and dormant users, permission schemes that grant sensitive actions to everyone, missing issue-security on security-labeled projects, insecure webhooks, unrecognized write-scoped apps, and automation rules that post data externally. Read-only.
DisponibleAudits your Linear workspace — admin sprawl, stale and guest access, SAML SSO, authorized OAuth apps and their scopes, webhooks, and public teams that expose security-labeled issues. Read-only.
DisponibleScans your Mistral AI organization: API keys (with Mistral’s native last-used signal), member roles, and audit events — flags stale, org-wide, orphaned, and never-expiring keys plus admin-role sprawl.
DisponibleScans your OpenAI organization: admin + project API keys (with OpenAI’s native last-used signal), member roles, projects, and audit events — flags stale, org-wide, and orphaned keys, owner sprawl, and audit logging left disabled.
DisponibleConnectez votre première source en quelques minutes — gratuit, lecture seule, sans appel commercial.