How to Harden
Open-source SaaS security hardening guides for supply chain defense. Protect your organization from third-party breaches.
Hardening Guides
Okta
Tier 1Identity Provider hardening for SSO, MFA policies, and API token security.
Snowflake
Tier 1Data warehouse security including network policies, MFA enforcement, and access controls.
ServiceNow
Tier 1Enterprise IT platform security for workflows, integrations, and access control lists.
CyberArk
Tier 1Privileged access management hardening for vaults, PSM, and credential rotation.
HashiCorp Vault
Tier 1Secrets management security including auth methods, policies, and audit logging.
BeyondTrust
Tier 1Remote access security for PRA, session monitoring, and credential injection.
CrowdStrike Falcon
Tier 1EDR platform hardening for API security, update policies, and RTR access.
Ping Identity
Tier 1Identity federation security for PingFederate, PingOne, and OAuth configurations.
GitLab
Tier 2DevOps platform security for CI/CD pipelines, repository access, and runners.
CircleCI
Tier 2CI/CD pipeline security including contexts, secrets, and runner hardening.
Azure DevOps
Tier 2Microsoft DevOps security for pipelines, service connections, and artifact feeds.
Atlassian Cloud
Tier 2Jira/Confluence security for organization policies, app controls, and data residency.
Workday
Tier 2HCM platform hardening for security groups, integration security, and domain policies.
HubSpot
Tier 2CRM security for private apps, OAuth scopes, and data export controls.
Salesforce
Tier 2CRM platform security for MFA enforcement, Connected Apps, and Shield Event Monitoring.
Zoom
Tier 2Video conferencing security for meeting policies, recording controls, and app marketplace.
NetSuite
Tier 2ERP security for role-based access, SuiteScript controls, and integration hardening.
Wiz
Tier 2Cloud security platform hardening for connector security and RBAC controls.
Datadog
Tier 2Observability platform security for API keys, log pipelines, and sensitive data.
Databricks
Tier 2Data platform security for workspace access, Unity Catalog, and secrets management.
JFrog
Tier 2Artifact management security for repository permissions, Xray policies, and access tokens.
ADP
Tier 3Payroll platform security for API connections, SSO, and data access controls.
Docker Hub
Tier 3Container registry security for access tokens, image signing, and repository controls.
Dropbox
Tier 3Cloud storage security for sharing policies, linked apps, and admin controls.
SailPoint
Tier 3Identity governance security for certification campaigns, source configs, and API access.
Splunk
Tier 3SIEM platform hardening for role-based access, HEC tokens, and search controls.
Box
Tier 3Enterprise content security for sharing policies, app controls, and classification.
Terraform Cloud
Tier 3IaC platform security for workspace variables, team access, and run triggers.
SAP SuccessFactors
Tier 3HCM security for permission groups, integration center, and data protection.
Oracle HCM Cloud
Tier 3Enterprise HR security for security profiles, HDL controls, and IDCS integration.
Adobe Marketo
Tier 3Marketing automation security for API users, LaunchPoint services, and lead database.
Zendesk
Tier 4Support platform security for API tokens, app marketplace, and ticket redaction.
PagerDuty
Tier 4Incident management security for API keys, event rules, and integration hardening.
Tableau
Tier 4BI platform security for site roles, data source credentials, and embed controls.
Mailchimp
Tier 4Email marketing security for API keys, audience protection, and domain authentication.
Notion
Tier 4Workspace security for sharing defaults, connection controls, and audit logging.
Miro
Tier 4Visual collaboration security for board sharing, app controls, and export restrictions.
LaunchDarkly
Tier 4Feature flag security for SDK keys, environment access, and approval workflows.
Asana
Tier 4Project management security for guest access, app controls, and division settings.
Monday.com
Tier 4Work OS security for board sharing, app restrictions, and API token controls.
Klaviyo
Tier 4E-commerce marketing security for API keys, profile protection, and export controls.
New Relic
Tier 5Observability security for API keys, license keys, and log obfuscation.
Power BI
Tier 5Microsoft BI security for tenant settings, gateway credentials, and embed controls.
Looker
Tier 5Google BI security for model access, embed secrets, and database connections.
BambooHR
Tier 5HR platform security for API keys, access levels, and sensitive field protection.
Freshservice
Tier 5ITSM security for API tokens, CMDB access, and change management controls.
Snyk
Tier 5AppSec platform security for service accounts, SCM integrations, and Broker configs.
Vercel
Tier 5Deployment platform security for access tokens, environment variables, and Git integration.
Rippling
Tier 5Workforce platform security for app provisioning, device management, and SCIM controls.
Gusto
Tier 5Payroll security for admin controls, partner integrations, and bank account protection.
Smartsheet
Tier 5Work management security for sharing defaults, connector controls, and activity logging.