Skip to content

INTEGRATION-LAYER POSTURE

Vectasec

Vectasec reads the brokers, gateways, meshes and MCP servers that connect your systems without changing them, checks them with deterministic detectors, and backs every finding with a stored observation.

Detectors
448
Read-only connectors
39
Compliance frameworks
5
Alert destinations
6

Why Vectasec#

  • Read-only by contract

    Collection uses read calls only, and nothing writes to a system you scan. The MCP connector reads discovery and tools/list, and never issues tools/call.

  • Evidence on every finding

    Each finding is committed in the same transaction as the observation it cites. The observation ledger rejects edits to evidence and is hash-chained per finding.

  • Gaps reported, never passed

    When a check cannot read its evidence, for example after an AWS AccessDenied or a Kubernetes 403, it files a not-assessable finding. A denied read is never reported as a pass.

  • Non-human identity inventory

    Service accounts, broker users, API consumers, OAuth clients and their grants are derived from what the connectors collect. Credentials are recorded as metadata only, never as values.

  • Attack paths

    Vectasec correlates exposed surfaces, over-privileged identities and data whose name or labels mark it as sensitive into hop-by-hop chains. Every hop cites a resource from the scan.

  • Agentless on AWS

    One cross-account read-only role, with an ExternalId condition if you set one, reads SQS, SNS, EventBridge, MSK and API Gateway across the regions you list.

  • Collector for private systems

    The Collector runs inside your network and connects outbound only. Credentials stay local, redaction is the last step, and it sends findings and resource metadata, never the raw configuration it collected.

  • Grounded AI triage (optional)

    Postgres rejects any AI explanation that does not cite a stored observation. A model can rank a finding as more urgent than its severity implies, never less, and with no AI key a deterministic summary runs instead.

What it covers#

Vectasec reads the integration layer: the systems that carry traffic and events between your services. Its 39 connectors span message brokers and streaming platforms (Kafka, Confluent Cloud, Redpanda, RabbitMQ, ActiveMQ Classic and Artemis, Pulsar, NATS, Solace, IBM MQ, MQTT), API gateways and endpoints (Kong, OpenAPI and Swagger documents, GraphQL, gRPC), Kubernetes with its mesh and ingress layer (Istio, Linkerd, Gateway API, Ingress, RBAC), and cloud services on AWS (SQS, SNS, EventBridge, MSK, API Gateway), Azure (Service Bus, Event Hubs, API Management, Logic Apps) and GCP (Pub/Sub, Apigee). They also cover iPaaS (MuleSoft, Boomi, Workato, n8n), coordination stores (etcd, ZooKeeper, Consul, Nacos), data plumbing (Kafka Connect, Schema Registry, Flink, Airflow, PgBouncer, Redis, Memcached, Elasticsearch and OpenSearch, Solr, vector databases), Vault, Keycloak, managed file transfer appliances, MCP servers, and integration-as-code manifests (docker-compose files, Kubernetes workloads, Kafka Connect connector JSON). A discovery connector probes only the hosts and ranges you declare to find middleware that no connection monitors. The Azure and GCP connectors are preview: their automated tests run against fixture API responses, not a live subscription or project. The connector reference lists each connector's fields and rules.

How it fits#

Vectasec has four parts: a Supabase Postgres control plane, a Python engine with a queue worker, a Next.js console and an optional Collector. It routes no traffic. A scan reads each system, builds an inventory and a graph, derives non-human identities and runs the detectors. Postgres enforces the integrity guarantees itself: tenant isolation with forced row-level security, an evidence ledger that is hash-chained per finding and rejects edits to evidence, and the citation gate on AI output. The ledger is tamper-evident, and vectasec doctor --verify-ledger finds breaks. The engine reaches a system directly using connection secrets held in Supabase Vault, or, for a private network, a Collector runs the same connectors and detectors inside it so credentials never leave. Findings map to 30 controls across PCI DSS 4.0.1, NIS2, DORA, HIPAA and the MCP specification (2025-11-25). Automated evaluation reports a control only as failing, unknown or not applicable. A control passes only when a person attests to it, and a live failing finding overrides that attestation. Findings route to Slack, Microsoft Teams, Jira, email, a webhook or a SIEM, and results export as OSCAL, CSV, and CycloneDX SBOM and VEX documents. For a product-level view, see the Vectasec product page.

Next steps#

  • Quick start: apply the schema, start the misconfigured Kafka, RabbitMQ and Redis dev targets, and run a first scan from the CLI.
  • How Vectasec works: follow a scan from the queue through collection, detection and the single write transaction.
  • Security model: how the engine authenticates callers, how tenants are isolated and how connection secrets are stored.
  • Connector reference: every connector, the fields it needs and the rules it feeds.
  • Run a collector in your network: scan private systems with credentials that stay on your side.