Quickstart: connect your first integration in 5 minutes.

This guide walks you through creating an account, connecting your first integration, and verifying that evidence collection is running. By the end, you'll have your first control check results in the Tenurex dashboard.

Before you start

You'll need:

  • A Tenurex account — start a free trial if you don't have one
  • Admin access to at least one integration (AWS, identity provider, or GitHub are the most common starting points)
  • About 10 minutes

Step 1: Create your account

Sign up at tenureq.com/login/register.html. During onboarding, you'll select your primary compliance framework — SOC 2, ISO 27001, or HIPAA. You can add additional frameworks later.

After completing signup, you'll land on the Tenurex dashboard. At this point, no integrations are connected and no evidence has been collected.

Step 2: Connect your first integration

From the dashboard, navigate to Integrations in the left sidebar. Click Add Integration.

For most teams, the best starting integrations are:

  1. AWS — provides cloud infrastructure evidence for the largest number of SOC 2 criteria
  2. Identity Provider — covers logical access controls (CC6 criteria)
  3. GitHub or GitLab — provides change management evidence

Select your integration type. Tenurex will walk you through the authorization flow — OAuth for most integrations, API token for others. The permission scope requested is read-only. See the Integration Reference for the exact scope requested per integration.

Step 3: Verify the connection

After authorizing, Tenurex runs a test collection to confirm the connection is working. You'll see a confirmation screen showing which controls the integration covers and a sample of the evidence that will be collected.

If the test fails, the most common causes are:

  • Insufficient permissions on the OAuth scope — review the required scopes for your integration
  • Network restriction blocking outbound connections to Tenurex collection endpoints
  • Expired or revoked token — re-authorize the integration

Step 4: Review your framework coverage

Once your first integration is connected, navigate to Frameworks to see your current coverage. This shows which control criteria are now mapped to evidence sources and which criteria still have no evidence source connected.

The coverage map is a useful guide for which integrations to add next. If you have several SOC 2 CC6 criteria uncovered, adding your identity provider will fill those gaps. If CC7 monitoring criteria are uncovered, AWS CloudTrail or a SIEM integration will cover them.

SOC 2 framework mapping

Tenurex maps to all 64 Trust Services Criteria across the five categories: CC (Common Criteria), A (Availability), C (Confidentiality), PI (Processing Integrity), and P (Privacy). Most SOC 2 engagements only include CC — which covers security — plus whichever additional categories are in scope for your business.

CC1 — Control Environment
  CC1.1  COSO Principle 1 — Integrity and ethical values
  CC1.2  COSO Principle 2 — Board independence
  ...

CC6 — Logical and Physical Access Controls
  CC6.1  Logical access security software and authentication
  CC6.2  Prior to issuing system credentials
  CC6.3  Access revoked after termination
  CC6.6  Logical access restrictions on external systems
  CC6.7  Transmission of information restricted
  CC6.8  Controls to prevent or detect and act upon malicious software

ISO 27001 framework mapping

Tenurex maps to all 93 controls in Annex A of ISO/IEC 27001:2022. The controls are organized into four themes: Organizational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls).

Evidence collected for SOC 2 criteria is automatically cross-mapped to overlapping ISO 27001 controls. For most teams, running both frameworks adds only 15-20% additional evidence collection effort.

HIPAA framework mapping

Tenurex maps to the HIPAA Security Rule Technical Safeguards (45 CFR §164.312). Coverage focuses on access controls, audit controls, integrity controls, transmission security, and authentication requirements. HIPAA is available on Growth and Scale plans.

What happens next

After your first integration is connected, evidence collection runs automatically every 4 hours. Your first full collection run will complete within 4 hours of connection. After that, the evidence feed is continuously updated.

If any control drifts — a gap is detected — you'll receive an email alert within one collection cycle. On Growth and Scale plans, alerts can also route to Slack and create Jira tasks.

Questions? Email us at [email protected].