certifly_ Sign in

Your policy says one thing.
Your systems say another.

Certifly holds the policies you have committed to, and connects to the systems that actually decide who can do what. Every control points at the checks that test it, so the gap between what you wrote down and what is running is visible continuously rather than during an audit.

Sign in to get started Sign in with Rocketbox ID. No password to create.

One control, end to end

Everything below is one chain. This is the whole product in six lines.

You write

AC-4 — Administrators must enrol a phishing-resistant authenticator.

A control in your access-control policy. Versioned; published revisions cannot be edited.
You attach

okta.user.admin-phishing-resistant-mfa

One of 113 shipped checks. It is source you can read, change, and test against your own estate before enabling it.
Certifly reports

Admin amy.ade@example.com (Super Administrator) has SMS and Okta Verify enrolled; neither is phishing-resistant.

Re-evaluated on every import. The control shows failing until the finding clears or somebody records an accepted risk against it, with a reason and an expiry.

If the check cannot see the field — the credential lacks the scope, the provider does not expose it — the control reads unverified, not passing. A control nothing tests has not been checked, and showing it green would be the most useful lie this product could tell.

Connects to

What it reads

113 checks ship with the product, across 42 kinds of configuration object. All of them are readable source.

ProviderChecksObject typesExamples
Google Workspace3012users, groups, OUs, Chrome devices & browsers, domains, mailbox settings
Okta2814users, groups, apps, sign-on & authentication policies, admin roles, API tokens
GitHub247org members, repositories, secrets, apps, OAuth grants
Slack226members, workspaces, apps, invites, retention settings
Google Cloud83service accounts, keys, IAM bindings

What it does

Write the policy here

Policies live in the platform, versioned. Every revision is kept and publishing puts one into force, so “what did the access-control policy say in March” is answered by a record rather than by a shared drive nobody can date.

Controls point at evidence

A control names the audit checks that test it. The policy stops being a document and becomes something continuously verified: a control whose checks are raising findings is a policy you are not actually following.

Configuration becomes text

Every import is rendered as a readable, diffable configuration language. A change to an Okta policy reads as three changed lines, not as a screenshot somebody took in March.

History, not snapshots

Every import is versioned. When a setting changed, what it changed from, and which import first saw it are answerable questions rather than a matter of recollection.

One person, several accounts

Accounts are correlated across providers into people, so “who is an administrator” stops being a question you answer once per console.

Findings have owners

Assign a finding, or a whole check, to a person or a team. Ownership keys on what the finding is rather than on its row, so it survives the next import instead of quietly detaching.

What it looks like

Policies / Access Control / Controls The controls of an access-control policy, each beside the live state of the audit check that tests it: four failing with open counts, one unverified because nothing tests it.
A policy, and whether it is true Controls sit beside the live state of the checks that test them. Unverified is its own state, never a soft pass: a control nothing tests has not passed, it has not been checked. Example data. Every name and identifier shown is generated.
Findings / Open / By rule The findings list grouped by audit check, each row showing a rule with its severity, who owns it, and how many findings and entities it is raising.
Findings, grouped by check One rule firing on eighty entities is one row with a count, not eighty rows saying the same sentence. Example data. Every name and identifier shown is generated.
Dashboard Dashboard showing overall posture and open findings by severity, the findings that need attention, and connector health.
What needs attention Open findings by severity, what is assigned to you, and which connectors are healthy. Example data. Every name and identifier shown is generated.
Identities / Amy Ade / Accounts One person's correlated accounts: six accounts across GitHub, Okta and Slack, each showing the value that attached it and a control to reject it.
One person, every account they hold Accounts are correlated from what the providers themselves report, so “who is an administrator” stops being a question you answer once per console. Each row shows the value that attached it, and a wrong one can be separated. Example data. Every name and identifier shown is generated.
Findings / Okta admin / Access path A graph of how access was obtained: an account, the groups it belongs to, the rule that assigned it, and the role that grants the permission, with the eight routes listed underneath.
How the access was actually obtained Not just that somebody is an administrator, but the path: the account, the group, the rule that put them in it, and the role at the end. This is the question that takes an afternoon in a provider console. Example data. Every name and identifier shown is generated.

What we ask your providers for

Eleven of the thirteen Google Workspace scopes are read-only. Two are not, and it is worth saying why rather than rounding the number up.

Reading a mailbox’s forwarding configuration — the thing an auditor asks about, because it is how data leaves quietly — requires gmail.settings.basic, and Google publishes no read-only equivalent. We chose it over gmail.readonly, which would let us read the mail itself. We deliberately do not request gmail.settings.sharing, which is the scope that actually authorises changing forwarding.

Every scope is listed with its purpose and a link to the API it calls before you grant anything, and the connection screen shows exactly which ones a provider still needs.

What it does not do

Certifly is a tool for finding things, not a certification and not a substitute for one. A check can only see what a provider’s API exposes, so a field your credential cannot read is reported as unknown, never as compliant. Absence of evidence is not evidence of absence, and a control that quietly passed because nothing tested it would be worse than no control at all.

A finding is a prompt to look. A clean result is not a promise.

How your data is handled

Credentials are sealed at rest and never displayed back to you. The server refuses to connect to private or link-local addresses, so a mistyped destination cannot reach the infrastructure it runs on. There is no analytics, no telemetry and no third-party JavaScript; this page loads nothing from anywhere else, fonts included.

Importing configuration means importing data about your people. For that data you are the controller and we are your processor. The privacy policy says exactly what is collected, written from an audit of the running system rather than from a template.