Connect Valdra
to your entire stack.
AI discovery, SSO, cloud, CRM, HR, and Canadian tools — synced to your AI-governance and privacy posture. Built for Canadian teams.
Connection methods
Three ways to connect — pick what fits your team.
SSO & SCIM
EnterpriseSAML 2.0 and OIDC single sign-on with SCIM user provisioning and deprovisioning. Works with Okta, Microsoft Entra, Google, or any standards-based identity provider.
- SAML 2.0 + OIDC
- SCIM provisioning
- Okta / Entra / Google
- Per-org configuration
REST API
API-keyAPI-key access to your compliance data: readiness score, breach status, DSAR status, and CASL unsubscribe checks. Hashed keys with per-plan rate limits.
- API-key auth
- Readiness & breach endpoints
- CASL unsubscribe check
- DSAR status lookup
Embed Widgets
No-codeDrop-in scripts for your own site — a CASL consent widget and a Law 25 cookie-consent banner that record timestamped consent straight into Valdra.
- CASL consent widget
- Cookie-consent banner
- Timestamped records
- One-line embed
AI Governance
3 live · 2 betaThe AI engine inside Valdra — powers assessments, AI document drafting, the Copilot, and every agent check. PII is anonymized via Shielk before it ever reaches the model.
Discover shadow AI — scans Workspace OAuth grants to surface the third-party and AI apps your employees connected, ready to promote into your AI registry.
Discover shadow AI across Microsoft 365 — scans Entra app grants and service principals for connected AI tools.
Valdra's sister product — anonymizes PII before any document reaches an AI model. 244 Canadian entity types, fully reversible.
Query your compliance posture, vendor risk and AI registry, log breaches and open DSARs from Claude Desktop or Claude Code — 11 tools via @canuckt/valdra-mcp on npm.
Identity & SSO
4 liveSAML 2.0 & OIDC single sign-on plus SCIM user provisioning and automatic deprovisioning.
OIDC single sign-on and SCIM provisioning for Azure AD / Entra identities.
OIDC single sign-on with your Google Workspace identities.
Bring any SAML 2.0 or OIDC provider — SP metadata, signature validation, and SCIM included.
Cloud & Data
5 live · 1 beta · 2 comingDiscover S3 data and map it to your ROPA, flag non-Canadian regions and CLOUD Act exposure — and collect SOC 2 evidence (encryption, IAM, CloudTrail).
Read-only scan — sample columns, classify Canadian PII via Shielk, and populate your data map automatically.
Read-only PII discovery scan straight into your ROPA.
Document-store PII discovery across collections and top-level fields.
SOC 2 evidence connector — branch protection, signed commits, Dependabot alerts, and CODEOWNERS.
Map Dropbox shared folders containing personal data to your ROPA, with shared-folder risk scoring.
Discover personal data in Azure Blob, SQL, and Cosmos DB with Canadian vs. US residency flags.
Data discovery across BigQuery, Cloud SQL, and GCS buckets with PII classification.
CRM & Marketing
1 live · 2 beta · 2 comingAPI-key sync — mirror Mailchimp unsubscribes straight into the CASL Consent Center.
OAuth sync — CASL consent mirroring and DPA / ROPA flags from your HubSpot contacts.
OAuth sync — contact and lead consent records with DPA and ROPA flags.
CASL express-consent tracking and suppression-list sync with the Valdra Consent Center.
Consent record sync and DPA auto-generation for Zoho CRM data processors.
HR & People
1 live · 2 comingCanadian HRIS — sync active employees into your workspace and auto-assign privacy training. PIPEDA pre-assessed.
Map employee data categories to your ROPA and trigger PIAs when new HR data is added.
Employee data mapping, PHIPA readiness for health plans, and retention-schedule automation.
Communication
1 live · 1 beta · 2 comingOAuth — pull workspace users for shadow-AI and employee discovery, plus compliance and breach-countdown alerts.
All transactional email — magic-link login, e-sign requests, and conversion nudges — over secure SMTP.
SMS consent records, CASL compliance for text campaigns, and opt-out queue management.
Transactional email consent mapping and a CASL audit trail for outbound campaigns.
Canadian Tools
0 live · 5 comingMap client billing data in your ROPA. Canadian-first: PIPEDA compliance pre-assessed.
Law-firm client data mapped to PIPEDA and Law 25, with matter-level consent and PIA triggers.
Health-practice client data — PHIPA readiness and PIPEDA consent for Canadian clinics.
Fintech data-processor mapping with FINTRAC flags and PIPEDA pre-assessment.
Financial data mapping and a PIPEDA ROPA for small Canadian businesses.
Full connector catalogue
85+ integrationsEvery tool connects in one click via secure OAuth or a read-only key — no engineering required. Hosted in Canada.
Source control — branch protection & change-management evidence
Source control — branch protection & change-management evidence
Source control — branch protection & change-management evidence
Cloud infrastructure — encryption, IAM & audit-log evidence
Cloud infrastructure — encryption, IAM & audit-log evidence
SSO, MFA & user-access evidence
SSO, MFA & user-access evidence
SSO, MFA & user-access evidence
SSO, MFA & user-access evidence
SSO, MFA & user-access evidence
Device & endpoint — encryption, MDM & patch evidence
Device & endpoint — encryption, MDM & patch evidence
Device & endpoint — encryption, MDM & patch evidence
Device & endpoint — encryption, MDM & patch evidence
Device & endpoint — encryption, MDM & patch evidence
Monitoring, alerting & incident evidence
Monitoring, alerting & incident evidence
Monitoring, alerting & incident evidence
Monitoring, alerting & incident evidence
Monitoring, alerting & incident evidence
Network & security-posture evidence
AI governance — access, usage & model evidence
AI governance — access, usage & model evidence
AI governance — access, usage & model evidence
AI governance — access, usage & model evidence
AI governance — access, usage & model evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
HR — onboarding/offboarding & access evidence
Finance — vendor & data-processing inventory
Finance — vendor & data-processing inventory
Finance — vendor & data-processing inventory
Finance — vendor & data-processing inventory
Finance — vendor & data-processing inventory
Finance — vendor & data-processing inventory
Commerce — customer-data inventory (ROPA)
Commerce — customer-data inventory (ROPA)
Commerce — customer-data inventory (ROPA)
CRM — consent & customer-data mapping
CRM — consent & customer-data mapping
CRM — consent & customer-data mapping
CRM — consent & customer-data mapping
CRM — consent & customer-data mapping
CRM — consent & customer-data mapping
CRM — consent & customer-data mapping
CRM — consent & customer-data mapping
Support — customer-data inventory & access
Support — customer-data inventory & access
Support — customer-data inventory & access
Support — customer-data inventory & access
Support — customer-data inventory & access
Support — customer-data inventory & access
Support — customer-data inventory & access
Marketing — consent & suppression-list sync
Marketing — consent & suppression-list sync
Marketing — consent & suppression-list sync
Communication — access & data inventory
Communication — access & data inventory
File storage — sensitive-data discovery
File storage — sensitive-data discovery
Analytics — data-processing inventory
Analytics — data-processing inventory
Design — access & data inventory
Work management — change & approval evidence
Work management — change & approval evidence
Work management — change & approval evidence
Work management — change & approval evidence
Work management — change & approval evidence
Docs & e-sign — policy & agreement evidence
Docs & e-sign — policy & agreement evidence
Docs & e-sign — policy & agreement evidence
Docs & e-sign — policy & agreement evidence
Docs & e-sign — policy & agreement evidence
Docs & e-sign — policy & agreement evidence
Finance — vendor & data-processing inventory
Finance — vendor & data-processing inventory
Commerce — customer-data inventory (ROPA)
More integrations ship every sprint. Azure, Google Cloud, Klaviyo, and BambooHR are on the roadmap — request yours below.
Find the AI your team uses but never told you about.
Connect Google Workspace or Microsoft 365 and Valdra scans the AI apps your employees have authorized — surfacing shadow AI, scoring it by risk, and letting you promote sanctioned tools into your AI registry in a click.
“Hey Claude, what are our PIPEDA gaps?” — MCP Server
A Model Context Protocol server for Claude Desktop, Claude Code, or any MCP-compatible client: query your compliance scores, vendor risk, and AI system registry, log breach incidents, and open access requests — in natural language. Install “@canuckt/valdra-mcp” from npm with your Valdra API key.
Don’t see your tool?
We’re adding integrations every sprint. Tell us which tool matters most and we’ll prioritize it.
Request an integration