Integrations
What Driftlock connects to in your stack.
A matrix of every connector Driftlock ships — source control, CI, on-call alerting, dependency advisory feeds, and secret managers. Each row names the tool and the signal the watcher ingests through it, with a deep link to the matching /docs reference where one exists. The watcher fans in from these surfaces as read-only taps you already own; the sandbox writes only to the SCM and signing surfaces you authorise.
Matrix
The full matrix — pick a category, filter by tool.
Each row names the tool and the brief capability Driftlock ships through it. Status reflects what is live today, what is in beta with current customers, and what is on the public roadmap — not what the surface vendor advertises about themselves.
22 of 22 connectors match
Source control
3 connectors
GitHub Enterprise
Repos · PRs · webhooks · GitHub Apps. Issues, PR diffs, branch updates, and Dependabot alerts ingested through a GitHub App installed on the tenant.
Self-hosted Driftlock
Single Helm + terraform install that lands in your VPC — Docker + Postgres + S3-compatible object storage. Comes with the sign-off matrix a security reviewer reads on day one.
GitLab self-hosted
Issues, merge requests, and pipeline events through the self-hosted GitLab webhook gateway.
Directionality
Read-only taps, no implicit third-party calls.
Every connector below is a one-way tap you already own. The watcher ingests events from each source; the sandbox writes only to the SCM and signing surface it has been issued keys for — nothing leaves your VPC, and no third-party LLM is ever called.
Inbound
Read-only ingest
Source control webhooks, CI run events, dependency advisories, on-call alerts, and ticket updates are all received one-way into the watcher. Driftlock never calls back out to consult a third-party model.
source control · CI · deps · on-call · tickets
Outbound
Authorised writes
The sandbox writes a branch, a signed commit, a CycloneDX SBOM, and a chat/notification — only against identities you provisioned. Keys live in Vault, AWS Secrets Manager, Key Vault, or your HSM, and rotate on your schedule.
SCM · artifact registry · signing · chat
Posture
No third-party LLM
Network egress is restricted by policy and reviewed at deploy time. The sandbox cannot pull a third-party model call, because the destination is not on the allow-list. Same posture across the offline runner for air-gapped deployments.
hermetic sandbox · bounded egress · your deny-list
Can't find your stack?
Request an integration, or read the runbook.
Most of the integrations above are added by request — we ship against a single customer's stack and then generalise. Send the integration name and the signal you want the watcher to read (or write), and we'll come back with a plan and an ETA.