How to Harden
Open-source SaaS security hardening guides for supply chain defense. Protect your organization from third-party breaches.
See it in action
The hth CLI scans your SaaS platforms against hardening guides and fixes what it finds.
1Password
AI DraftedEnterprise password manager hardening for 1Password Business SSO, policies, and vault security
Abnormal Security
AI DraftedEmail security platform hardening for Abnormal Security including SSO configuration, admin access, and integration security
ADP
AI DraftedPayroll platform security for API connections, SSO, and data access controls
Airtable
AI DraftedLow-code platform hardening for Airtable Enterprise including SSO, access controls, and collaboration security
Amplitude
AI DraftedProduct analytics platform hardening for Amplitude including SAML SSO, project access, and data governance
Anthropic
AI DraftedAI platform security hardening for Claude API, Console, SSO, workspace isolation, and admin controls
Asana
AI DraftedProject management platform hardening for Asana including SAML SSO, admin console controls, and mobile security
Atlassian Cloud
AI DraftedJira/Confluence security for organization policies, app controls, and data residency
Auth0
AI DraftedIdentity platform hardening for Auth0 tenant security, MFA, and attack protection
Amazon Web Services
AI DraftedAWS identity management hardening for IAM Identity Center including MFA, permission sets, and account access
Azure DevOps
AI DraftedMicrosoft DevOps security for pipelines, service connections, and artifact feeds
BambooHR
AI DraftedHR platform security for API keys, access levels, and sensitive field protection
BeyondTrust
AI DraftedRemote access security for PRA, session monitoring, and credential injection
Bitbucket
AI DraftedCode repository security hardening for Bitbucket Cloud including workspace security, branch permissions, and access controls
Box
AI DraftedEnterprise content security for sharing policies, app controls, and classification
Braze
AI DraftedCustomer engagement platform hardening for Braze including SAML SSO, permission sets, and API security
Buildkite
AI DraftedCI/CD platform hardening for Buildkite including SAML SSO, team permissions, agent security, and pipeline controls
OpenAI
AI DraftedEnterprise AI security hardening for ChatGPT, SSO configuration, data privacy, and admin controls
CircleCI
AI DraftedCI/CD pipeline security including contexts, secrets, and runner hardening
Clari
AI DraftedRevenue platform hardening for Clari including SAML SSO, user permissions, and forecast data security
Cloudflare
AI DraftedSecurity hardening for Cloudflare Zero Trust, Access, Gateway, and WARP deployment
SAP
AI DraftedTravel and expense management platform hardening for SAP Concur including SAML SSO, expense policies, and audit controls
Coupa
AI DraftedProcurement and spend management platform hardening for Coupa including SAML SSO, role-based access control, and data security
CrowdStrike Falcon
AI DraftedEDR platform hardening for API security, update policies, and RTR access
Anysphere
AI DraftedAI code editor security hardening for code privacy, API key management, and workspace trust
CyberArk
AI DraftedPrivileged access management hardening for vaults, PSM, and credential rotation
Databricks
AI DraftedData platform security for workspace access, Unity Catalog, and secrets management
Datadog
AI DraftedObservability platform hardening for Datadog including SAML SSO, role-based access control, and organization security settings
Docker Hub
AI DraftedContainer registry security for access tokens, image signing, and repository controls
DocuSign
AI DraftedeSignature platform hardening for DocuSign including SSO configuration, session security, and admin controls
Drata
AI DraftedCompliance automation platform hardening for Drata including access controls, integration security, and monitoring configuration
Dropbox
AI DraftedCloud storage security for sharing policies, linked apps, and admin controls
Duo Security
AI DraftedMulti-factor authentication hardening for Cisco Duo, admin policies, and bypass protection
Figma
AI DraftedDesign platform hardening for Figma Enterprise including SSO, access controls, and governance features
Fivetran
AI DraftedData integration platform hardening for Fivetran including SSO configuration, role-based access, and connector security
Freshservice
AI DraftedITSM security for API tokens, CMDB access, and change management controls
Fullstory
AI DraftedDigital experience intelligence platform hardening for Fullstory including SAML SSO, data privacy controls, and access management
GitHub
AI DraftedComprehensive source control and CI/CD security hardening for GitHub organizations, Actions, supply chain protection, and Enterprise Cloud/Server
GitLab
AI DraftedDevOps platform security for CI/CD pipelines, repository access, and runners
Gong
AI DraftedRevenue intelligence platform hardening for Gong including SAML SSO, data access controls, and recording security
Comprehensive security hardening for Google Workspace, Gmail, Drive, and Google Admin Console
Gusto
AI DraftedPayroll security for admin controls, partner integrations, and bank account protection
Harness
AI DraftedSoftware delivery platform hardening for Harness including SAML SSO, RBAC, secret management, and pipeline security
HashiCorp Vault
AI DraftedSecrets management security including auth methods, policies, and audit logging
Heap (Contentsquare)
AI DraftedDigital insights platform hardening for Heap including SAML SSO, environment access, and data governance
HubSpot
AI DraftedCRM security for private apps, OAuth scopes, and data export controls
Intercom
AI DraftedCustomer messaging platform hardening for Intercom including SAML SSO, workspace security, and data protection
Jamf
AI DraftedMDM hardening for Jamf Pro macOS and iOS device management
Jenkins
AI DraftedCI/CD security hardening for Jenkins including authorization, agent security, and pipeline protection
JFrog
AI DraftedArtifact management security for repository permissions, Xray policies, and access tokens
Jira Cloud
AI DraftedIssue tracking platform hardening for Atlassian Jira Cloud including SAML SSO, organization security, and access controls
JumpCloud
AI DraftedCloud directory and identity management hardening for JumpCloud SSO, MFA, and device management
Keeper Security
AI DraftedEnterprise password manager hardening for Keeper Security including role enforcement, MFA, and admin console security
Klaviyo
AI DraftedE-commerce marketing security for API keys, profile protection, and export controls
KnowBe4
AI DraftedSecurity awareness training platform hardening for KnowBe4 including SAML SSO, admin access, and campaign security
LastPass
AI DraftedEnterprise password manager hardening for LastPass Business including MFA policies, admin controls, and security dashboard
LaunchDarkly
AI DraftedFeature flag security for SDK keys, environment access, and approval workflows
Linear
AI DraftedIssue tracking platform hardening for Linear including SAML SSO, workspace access, and team permissions
Looker
AI DraftedGoogle BI security for model access, embed secrets, and database connections
Mailchimp
AI DraftedEmail marketing security for API keys, audience protection, and domain authentication
Adobe Marketo
AI DraftedMarketing automation security for API users, LaunchPoint services, and lead database
Microsoft 365
AI DraftedComprehensive security hardening for Microsoft 365, Exchange Online, SharePoint, Teams, and OneDrive
Microsoft Entra ID
AI DraftedIdentity Provider hardening for Azure Active Directory, Conditional Access, PIM, and Zero Trust
Microsoft Intune
AI DraftedEndpoint management hardening for Microsoft Intune — defending against admin-plane abuse, credential theft, and destructive wipe attacks
Mimecast
AI DraftedEmail security hardening for Mimecast including targeted threat protection, impersonation policies, and gateway configuration
Miro
AI DraftedVisual collaboration security for board sharing, app controls, and export restrictions
Mixpanel
AI DraftedProduct analytics platform hardening for Mixpanel including SAML SSO, project access controls, and data governance
Monday.com
AI DraftedWork management platform hardening for Monday.com including SAML SSO, authentication policies, and admin controls
MongoDB
AI DraftedDatabase-as-a-Service security hardening for MongoDB Atlas network access, authentication, and encryption
Netskope
AI DraftedSecurity hardening for Netskope CASB, SWG, and ZTNA deployment
NetSuite
AI DraftedERP security for role-based access, SuiteScript controls, and integration hardening
New Relic
AI DraftedObservability security for API keys, license keys, and log obfuscation
Notion
AI DraftedCollaboration platform hardening for Notion including SAML SSO, workspace security, and data protection controls
Okta
AI DraftedIdentity Provider hardening for SSO, MFA policies, and API token security
OneLogin
AI DraftedIdentity provider hardening for OneLogin including MFA policies, user security, and SmartFactor Authentication
Oracle HCM Cloud
AI DraftedEnterprise HR security for security profiles, HDL controls, and IDCS integration
Orca Security
AI DraftedCloud security platform hardening for Orca Security including SAML SSO, role-based access, and cloud account integration
Outreach
AI DraftedSales engagement platform hardening for Outreach including SAML SSO, user permissions, and data security
PagerDuty
AI DraftedIncident management platform hardening for PagerDuty including SSO configuration, user provisioning, and access controls
Paylocity
AI DraftedHCM platform hardening for Paylocity including SAML SSO configuration, MFA enforcement, and role-based access controls
Pendo
AI DraftedProduct experience platform hardening for Pendo including SAML SSO, subscription access, and data privacy controls
Ping Identity
AI DraftedIdentity federation security for PingFederate, PingOne, and OAuth configurations
Postman
AI DraftedAPI platform security hardening for Postman Enterprise including SSO, team policies, and API key management
Power BI
AI DraftedMicrosoft BI security for tenant settings, gateway credentials, and embed controls
Proofpoint
AI DraftedEmail security platform hardening for Proofpoint including SAML SSO, admin access controls, and threat protection policies
Qualys
AI DraftedVulnerability management platform hardening for Qualys VMDR including user access, scanning configuration, and policy compliance
Rapid7
AI DraftedVulnerability management platform hardening for Rapid7 InsightVM and Command Platform including SSO, console security, and user management
Rippling
AI DraftedWorkforce platform security for app provisioning, device management, and SCIM controls
SailPoint
AI DraftedIdentity governance security for certification campaigns, source configs, and API access
Salesforce
AI DraftedCRM platform security for MFA enforcement, Connected Apps, and Shield Event Monitoring
SAP SuccessFactors
AI DraftedHCM security for permission groups, integration center, and data protection
Twilio Segment
AI DraftedCustomer data platform hardening for Segment including SAML SSO, workspace access, and data governance
SendGrid
AI DraftedEmail delivery platform hardening for Twilio SendGrid including API key management, two-factor authentication, and SSO configuration
SentinelOne
AI DraftedEndpoint Detection and Response (EDR) hardening for SentinelOne Singularity platform
Sentry
AI DraftedApplication monitoring platform hardening for Sentry including SAML SSO, team access, data scrubbing, and integration security
ServiceNow
AI DraftedIT service management platform hardening for ServiceNow including SSO configuration, Security Center, and high-security plugins
Shopify
AI DraftedE-commerce platform hardening for Shopify Plus including SAML SSO, staff permissions, and store security
Slack
AI DraftedEnterprise security hardening for Slack workspaces, SSO, DLP, and data governance
Smartsheet
AI DraftedWork management security for sharing defaults, connector controls, and activity logging
Snowflake
AI DraftedData warehouse security including network policies, MFA enforcement, and access controls
Snyk
AI DraftedAppSec platform security for service accounts, SCM integrations, and Broker configs
Splunk
AI DraftedSIEM platform hardening for Splunk Cloud including SAML SSO, role-based access control, and data security
Square (Block)
AI DraftedCommerce platform hardening for Square including SSO configuration, team permissions, and API security
Stripe
AI DraftedPayment platform hardening for Stripe including SSO configuration, team permissions, and API key security
Tableau
AI DraftedBI platform security for site roles, data source credentials, and embed controls
Tenable
AI DraftedVulnerability management platform hardening for Tenable.io and Security Center including user access, scanning security, and agent configuration
Terraform Cloud
AI DraftedIaC platform security for workspace variables, team access, and run triggers
Twilio
AI DraftedCloud communications platform hardening for Twilio including SSO configuration, account security, and API key management
UKG
AI DraftedHCM platform hardening for UKG Pro including SAML SSO configuration, authentication upgrade features, and access controls
Vanta
AI DraftedCompliance automation platform hardening for Vanta including access controls, integration security, and continuous monitoring
Vercel
AI DraftedComprehensive platform security for authentication, WAF, deployment protection, secrets, network isolation, security headers, and monitoring
Webex
AI DraftedEnterprise collaboration hardening for Cisco Webex including meeting security, SSO configuration, and admin controls
Wiz
AI DraftedCloud security platform hardening for connector security and RBAC controls
Workato
AI DraftedComprehensive security hardening for Workato including SSO, RBAC, encryption key management, API security, secrets management, environment separation, and audit logging
Workday
AI DraftedHCM platform hardening for security groups, integration security, and domain policies
Zendesk
AI DraftedSupport platform security for API tokens, app marketplace, and ticket redaction
Zoom
AI DraftedVideo conferencing security for meeting policies, recording controls, and app marketplace
Zscaler
AI DraftedSecurity hardening for Zscaler ZIA, ZPA, and Client Connector deployment