Integrations

Deploy into your existing architecture.

Tether acts as a specialized data source for the security tools you already operate. It pushes events to your SIEM, pulls identity from your IdP, and integrates directly into your current SOC workflows.

A short version of this also appears on How it works and Pilot. Nothing to rip out — Tether extends the stack you already trust.

Write the audit trail where it belongs.

AI traffic shouldn't live in a siloed vendor dashboard. Tether forwards every cryptographically signed event to your SIEM natively.

Splunk

Shipped
  • Tether events land in your Splunk Cloud or on-prem instance natively — no connector to build.
  • Each event carries the policy version, identity, agent, host, and verdict, so your existing searches and dashboards just work.
  • The access token lives in your Splunk; Tether holds it write-only.

Microsoft Sentinel

Shipped
  • Streams into Log Analytics with no app registration to stand up.
  • A distinct log type per event family means your Sentinel analytics rules can target Tether's stream directly.
  • Configured per workspace; your security team keeps full control of detection logic.

Syslog (air-gap clean)

Shipped
  • Targets on-prem Splunk, rsyslog, or any standards-compliant collector — with no internet dependency.
  • Part of an architecturally coherent air-gap path: pair it with an on-prem control plane and a local judge, and every component supports running with no internet dependency.
  • Same reliable delivery as the other adapters.

Signed webhooks

Shipped
  • For anything else downstream — SOAR, a ticketing system, your own pipeline — Tether posts signed, verifiable events.
  • Filter each receiver to only the event types and verdicts it cares about.
  • Secrets are write-only and redacted everywhere after registration.

Exact routes, signing algorithms, retry timing, and the event envelope are in the technical brief →

Identity, authentication, and lifecycle.

We defer to your IdP. Sign-on, role assignment, and offboarding are controlled entirely by your existing enterprise directory via SSO and SCIM.

Single sign-on

Shipped
  • SAML 2.0 and OIDC — your team signs in with the identity provider you already run.
  • Upload your IdP metadata and SSO is live; no per-user setup.
  • Every session is scoped to a role: admin, operator, or viewer.

Directory sync

Shipped
  • Create, update, and remove operators directly from your directory — no parallel user list to keep in step.
  • Group membership maps to role, so access stays correct as people change teams.
  • A deprovision in Okta or Entra cuts access here, and every change lands in the audit trail.

The SSO/SCIM endpoints, signature scheme, and group-to-role mapping are in the technical brief →

A machine that's drifted out of compliance
drops out of device trust on its own.

Your conditional-access policy reads whether a developer's machine is actually running Tether and current on policy — in the format your IdP already understands. No converter to write, no translation for your Okta or Entra team.

Okta Device Trust

Shipped
  • Tether posture drops straight into Okta's conditional-access rules with no custom integration.
  • Carries the signals that matter: whether the agent is live and on the current policy.
  • A non-compliant machine falls out of the trusted set automatically.

Microsoft Entra

Shipped
  • Mirrors the managed-device shape Entra Conditional Access already reads.
  • Tether's signal sits out of the way of your existing Intune data — no schema change.
  • Your Microsoft team works with a format they already know.

Tether-native

Shipped
  • Full per-host detail for your own conditional-access broker or scheduled pulls.
  • Filter to compliant-only or to changes since a given time.
  • Read-only — posture reporting, never a write path.

CSV

Shipped
  • Clean, spreadsheet-safe export for ad-hoc audits and evidence packets.
  • Drops into incident-response timelines without surprises.
  • The format your compliance team will ask for anyway.

Export routes, the exact field shapes, and filter parameters are in the technical brief →

A change log of every policy decision —
ready for your auditor.

Append-only policy audit

  • Every policy publish, revert, and fleet acknowledgement is recorded — who did it, why, and what changed.
  • Reads directly against a SOC 2 CC8 change-management evidence requirement; pull it on a schedule into your own systems.
  • The record lives in your cloud storage, inside your tenant — not on a Tether server.

Export route, file format, and storage location are in the technical brief →

Stand up an adapter in an afternoon.

A platform engineer who knows Splunk or Sentinel registers the adapter in one call. We can pair on it during the pilot.

Book a 30-min walkthrough ↗