Data sources

Every connector Noru supports, what each one asks for, what it collects, and how syncs behave.

A data source is a connection to a system you already run. Noru reads it on a schedule and turns what it finds into evidence, assets, personnel identities, security findings, certificate domains, and privacy signals. Nothing is written back: every connector is read-only, and the pages in this tab say exactly which reads each one performs.

Categories

CategoryWhat it feeds
IdentityPersonnel directory, MFA and access evidence, third-party app grants
CloudAsset inventory, configuration and posture evidence, security findings, certificate domains
Code and workRepository and project inventory, branch protection and CI evidence, vulnerability findings, imported policies
SecurityScanner findings, SIEM signals, monitor and audit evidence
DataWorkspace and database inventory, access-control evidence
PeopleHR records that drive personnel status and onboarding or offboarding evidence

All providers

Each provider page follows the same shape: what is collected, what is not, what to prepare, the connect dialog step by step, and a permissions table that separates what a credential could reach from what Noru actually reads.

Where to find it

Data Sources
Data Sources list with status badges and the Connect Data Source buttonData Sources list with status badges and the Connect Data Source button
Every connection, its status, and when it last synced.

Click Connect Data Source to open the Connect data source dialog, pick a provider, and follow the provider-specific form. Clicking a row opens the detail drawer with evidence, sync history, and connection settings.

Connect data source dialog showing the provider pickerConnect data source dialog showing the provider picker
The provider picker. Most providers open their own dialog after this step.

Admins and editors can connect, sync, reauthenticate, change the sync frequency, and delete a data source. Viewers can open the list, the drawer, the evidence, and the sync history but cannot change anything. See Roles and permissions.

  1. Identity first. Google Workspace or Microsoft Entra ID populates the people directory, so identities found later in GitHub, Cloudflare, or Databricks match a person instead of creating orphans.
  2. Cloud and code next. AWS, Google Cloud, Azure, GitHub, and GitLab produce the bulk of configuration evidence and the asset inventory.
  3. Security tooling. Datadog and Detectify add findings that would otherwise need to be entered by hand.
  4. Review what did not map. Every sync leaves some evidence without a control mapping. Open the evidence vault and link it, or accept that it is informational.

What Noru does not do

Connecting a system does not make it compliant; it makes the current configuration visible. A granted scope is not the same as collection: the permissions table on each provider page lists the reads Noru performs, and anything outside that list is not read even if the credential would allow it. A sync can prove that a setting had a value at a point in time. It cannot prove that a process is followed, that a review happened, or why a setting was chosen. Those remain your evidence to add. See the sync model for what a run does and does not produce.

Last updated on