Integrations / Reusable adapters

One platform.
Configurable connections.

CyberPass is designed as a universal layer. Infrastructure differences are expressed through configuration and adapter types, not a separate codebase for every customer.

OpenAI-compatibleMCP toolsOIDC / LDAPSyslog/CEF TLS
01 / AVAILABLE

Current engineering
integration baseline.

These interfaces already exist in the product. Compatibility with a specific IdP, LDAP schema, PKI and SIEM endpoint is validated in customer infrastructure.

Available

OpenAI-compatible inference

Public and Private LLMs through a configurable base URL, encrypted provider key, connection test and model discovery.

  • Local inference servers
  • Public OpenAI-compatible providers
  • Stable model aliases over upstream IDs
Baseline

Enterprise identity

OIDC with PKCE and signed ID-token validation; LDAP/AD bind, group-to-role mapping and managed auto-provisioning.

Available

SIEM & customer PKI

CEF over UDP, TCP or verified TCP/TLS, optional mTLS, delivery counters, an async queue and DLQ.

Beta

Windows Endpoint

Device enrollment, loopback proxy and managed browser-extension channel.

02 / ADAPTER PRINCIPLE

A new protocol
is added once.

Customer-specific values—URLs, credentials, CAs, aliases, groups and mappings—remain configuration. Code changes only for a new reusable protocol adapter.

Adapter typeShared protocol and request normalization.
Provider recordTenant URL, encrypted key and public/private class.
Model aliasA stable name for applications and policies.
PolicyApproved route and security rules.
03 / STATUS

Shared protocol now.
Vendor profile in the pilot.

We do not promise compatibility with a specific product until its version, claims/schema, network path and acceptance criteria are validated.

IntegrationStatusApproach
OIDC / SSOBaselineAuthorization Code + PKCE, signed ID token and group-to-role mapping; the IdP defines MFA and lifecycle.
LDAP / Active DirectoryBaselineLDAPS/StartTLS, service bind, user bind and configurable attributes/filter.
SIEM over TLSAvailableVerified TCP/TLS, customer CA and optional client certificate.
KMS / HSM / external secret storeOptionalThe current baseline is local AES-256-GCM; an external backend is selected during the pilot.
MCP toolsBaselineStreamable HTTP tools/list and tools/call, allow/block/approval, argument DLP and metadata-only audit. Resources, prompts and sampling are not yet proxied.

Bring the protocol, not a brand list.

An integration assessment needs the endpoint contract, authentication, network path and acceptance criteria.

Discuss integrations →