Runs on the systems you already operate.
ResearchSecurity.ai is a verification layer, not a replacement for your disclosure system of record. The integrations below are labeled with their real implementation state — Available (shipped connector), Configurable import (file / API / Generic REST), In development, or Planned. Integration states are listed as they are. During the Founding Partner phase, connector priorities follow partner institutions' systems.
A buyer reads "we integrate with X" as "a working connector exists." That is the standard we hold this page to. Where a system is not a shipped connector, the table below says so — and describes exactly how institutions running that system get their data into the platform today.
Disclosure systems of record
| System | Status | Notes |
|---|---|---|
| Huron Research Suite | Available | Webhook-driven sync for awards, proposals, COI disclosures, agreements, IRB protocols, and personnel. |
| Cayuse | Available | OAuth2 connector with webhook-driven sync for awards, proposals, sponsors, units, and people. |
| Kuali Research | Available | Bearer-token connector with polled delta sync (no webhooks yet) across awards, proposals, protocols, persons, units, sponsors. |
| InfoEd, Streamlyne, other | Configurable import | Not shipped as a dedicated vendor connector today; institutions integrate via the Generic REST connector below or via file/API import against the platform's contract data model. |
HR / effort sources
| System | Status | Notes |
|---|---|---|
| Workday | Available | OAuth2 connector with webhook processing for workers, organizations, positions, and job profiles. |
| Ellucian Banner | Planned | No dedicated connector today. Integrations reach Banner via institutional middleware exposed through the Generic REST connector. |
| Oracle PeopleSoft | Planned | No dedicated connector today. Data currently arrives via institutional ETL populating the platform's contract data model, or via a customer-owned REST wrapper through the Generic connector. |
Researcher identifiers & federal sponsor records
| System | Status | Notes |
|---|---|---|
| ORCID (public API) | Available | Read-only against ORCID's public API — person, employments, educations, fundings, works. This is public data enrichment for identity and undisclosed-affiliation detection; it is not ORCID OAuth login or institutional-account sync. |
| NIH RePORTER / eRA Commons IDs | Configurable import | The platform queries the public NIH RePORTER API using eRA Commons identifiers to corroborate federal award history. It does NOT authenticate against institutional eRA Commons accounts and does not read non-public eRA data. |
Compliance training
| System | Status | Notes |
|---|---|---|
| CITI Program | Available | SOAP connector with WS-Security auth; pulls member completions and course rosters. Polling-based (no webhooks). |
Universal fallback
| System | Status | Notes |
|---|---|---|
| Generic REST connector | Available | Configurable client for any REST endpoint — multiple auth methods (OAuth2, API key, custom headers), pagination styles, retries. Used for institutional middleware, PeopleSoft/Banner via a wrapper, or any custom source. |
| Import via contract data model | Available | Institutions can populate the platform's canonical entities (persons, effort, disclosures, awards) via file or API import when a live connector does not fit their environment. This is the default path for Banner/PeopleSoft during the Founding Partner phase. |
Authentication
| System | Status | Notes |
|---|---|---|
| SAML 2.0 / OIDC SSO | Available | Required for every institutional deployment — access lives in the institution's identity provider, not in a separate user store. No pilot goes live without it. |
What integration means in practice
Institutions do not have to unify their infrastructure to use ResearchSecurity.ai. Each system is reached where it is — the platform pulls only what the certification requires and returns the reconciliation to the compliance workflow the institution already runs. The platform is additive; it removes nothing already in place.
What we do not do
- We are not a data broker — we do not sell, share, or pool your institution's data.
- We never train AI models on your data.
- We do not maintain a private registry of individuals.
- We do not authenticate against your institutional eRA Commons account. ORCID and NIH data flow through public interfaces only.
See the Trust Center for the full data-handling posture and AI governance statement.
See verification on realistic examples.
A briefing walks through disclosure verification against a scoped researcher cohort — with your compliance context, in about 30 minutes.