Platform

Integrations

Connect the tools you already run — EDR, SIEM, cloud, identity, and email — through a governed connector layer with safe egress and normalised telemetry.

Nirvet meets your stack where it lives. A connector wizard onboards each source with a guided create-configure-test flow; ingestion mappers normalise incoming telemetry to a common schema; and response actioners reach back into your tools to contain, disable, and block. All outbound calls run through an SSRF-safe egress layer, and credentials are encrypted at rest.

Guided connector wizard

Add a source, configure it, and test the connection before it goes live — no guesswork, clear failure reasons.

Normalised ingestion

Mappers translate each vendor's telemetry into one schema, so detection content and investigations work across sources.

Response actioners

Microsoft Defender, Entra, and M365; Okta identity; CrowdStrike EDR host containment and fleet-wide IOC blocks — with more added continuously.

Safe by construction

Outbound requests are SSRF-guarded, credentials are encrypted, and every connector action is authority-gated and audited.

What you get

  • EDR, SIEM, cloud, identity, and email source connectors
  • Per-tenant connector configuration and isolation
  • Health and degraded-state visibility per integration
  • Response coverage expanding across identity, endpoint, and network vendors
  • Region-aware endpoints, including sovereign/GovCloud where required

Connect your stack in an afternoon

Tell us what you run — we'll show the connector flow, the normalised telemetry, and the response actions available today.