Never be surprised by an integration again

Every Logic App and Function you run including the ones nobody registered, and the ones that exist only as code, found, flagged, and mapped to the data they move. On every deploy. In your tenant.

Governed, incomplete, or ungoverned, no grey areas

Governed

A manifest exists with an owner and a data classification. Documented, owned, classified.

Incomplete

A manifest exists but is missing an owner or a classification. The exact missing field is flagged wherever it appears.

Ungoverned

A Logic App or Function is running with no manifest at all. Detected live, flagged red, with a page telling the developer exactly what to add.

Most tools only see what’s deployed

One screen tells you where you stand

Posture at a glance, total integrations, and how many are governed, incomplete, or ungoverned.

Data-classification exposure, Restricted and Confidential integrations named individually. Internal and Public summarised.

Criticality breakdown, critical / high / medium / low, colour-coded for instant prioritisation.

Open governance issues, every gap, with the exact missing field.

How it works

Live in three steps, then automatic

Step 1

Add it to your pipeline. Add it to your Azure DevOps pipeline and point it at your resource groups. No platform to host, no agents.

Step 2

Fill in the stubs. It discovers your Logic Apps, Functions and repos, and opens a pull request with stub manifests. About five minutes each.

Step 3

It runs on every deploy. Every push regenerates your catalog, dashboard, diagrams and pages and flags anything ungoverned.

Runs where your data already lives

In your tenant

Everything runs inside your Azure environment. Nothing is sent to us. No phone-home.

Reads no secrets

Secrets, connection strings, hostnames and tokens are stripped from every output. Optionally, fail the build on any secret detected.

Least privilege

Read-only discovery through your existing pipeline identity.

Verifiable

Every page carries the build ID, commit SHA and timestamp that produced it.

FAQs

No. It never reads secret values. Redaction strips anything sensitive from output, and it can even be configured to fail the build if a secret is detected.

Nowhere. It runs in your tenant. Nothing is sent to us.

Read-only discovery through your existing pipeline identity.

No. Functions are scored by trigger and output. Housekeeping and timer jobs are skipped, so only genuine integrations are flagged.

Logic Apps and Azure Functions in the resource groups you configure, plus Functions code in your Azure DevOps repos. Anything without a manifest is flagged, with the missing fields named.

Be one of our founding customers