Skip to content
Integrations · Marketplace · Governance

One marketplace for every tool your firm already runs on.

The integrations marketplace lives at Settings then Integrations. Every third-party tool your firm already runs on is one tile away: Gmail and Microsoft 365 for email, Twilio and JustCall for voice, Xero for accounting, Google Drive, OneDrive, Dropbox and your own S3 bucket for backup, plus Stripe Connect for client payments. Every tile shows real connection state at a glance with the last sync stamp and account name inline.

Gmail

Reconnect

Microsoft 365

Connected

JustCall

Connected

Twilio Voice

Connected

Twilio Messaging

Reconnect

Xero

Connected

Google Drive

Connected

OneDrive

Connected

Dropbox

Reconnect

Bring what you use. Keep what you own.

The marketplace is the governance layer over every third-party connection: sealed credentials, versioned consent and audit rows on every connect, rotate and disconnect.

One tile per tool

Every third-party surface lives at Settings then Integrations. Real connection state, last-sync stamp and account name inline on each tile.

Sealed credential vault

Every connection is sealed with your organisation's AES-GCM key. Plaintext credentials never leave the driver that owns the connection.

Versioned consent

Consent copy is stamped on every connection row. Change the shared-liability terms and admins are re-prompted before the connection keeps running.

One-click disconnect

Disconnect any integration in a click. The connection row is retained for audit so you always see who connected what and when.

Every tile at a glance.

Twelve integrations at launch. New drivers plug into the same framework so future tools inherit the vault, the consent flow and the audit trail on day one.

Gmail

Email

Microsoft 365

Email

JustCall

Voice

Twilio Voice

Voice

Twilio Messaging

SMS + WhatsApp

Xero

Accounting

Google Drive

Backup

OneDrive

Backup

Dropbox

Backup

Customer S3

Backup

Sender Domain

Deliverability

Inbound Email

Deliverability

Stripe Connect

Payments

Anatomy of a connection.

Same shape for every integration. Consent, OAuth or credentials, sealed storage, audit. Reversible in one click.

01

Read the shared-responsibility notice

Each connect modal shows what ImmiIQ will do with the token and what the firm still owns. Consent copy is version-stamped so future changes trigger a re-prompt.

02

OAuth or paste credentials

Follow the provider's OAuth prompt or paste API keys inline. Credentials get sealed with your organisation's AES-GCM key before they touch the database.

03

Use it. Rotate it. Disconnect it.

Every connect, rotate and disconnect writes an audit row. Disconnecting drops the sealed blob in the same transaction that closes the connection row.

Security

Every connection scoped to your org. Every credential sealed with your key.

Every integration connection is scoped to your organisation and its credentials are sealed with a per-tenant AES-GCM key derived from your organisation id. Plaintext credentials never leave the vault; the sealed blob is not exposed to application code beyond the driver that owns the connection. Consent copy is version-stamped on every connection row, so a change to the shared-liability terms triggers a re-prompt before the integration keeps running. Every connect, disconnect and credential rotation writes an audit row and audit-log write failures page the operator so silent loss is impossible.

Frequently asked.

Can I bring my own tools into ImmiIQ?

Yes. The integrations marketplace lets your firm connect its own mailbox, phone system, accounting ledger and backup destination. Credentials stay sealed with your per-organisation key, consent is versioned and you can disconnect any integration in one click.

What happens to my tokens if I disconnect?

Disconnecting drops the sealed credential blob and tears down any provider push subscription in the same transaction that closes the connection row. The connection row itself is retained for audit so you always see who connected what and when.

Do the connections leak between organisations on shared infrastructure?

No. Every connection is keyed by organisation id and sealed with a per-tenant AES-GCM envelope. Cross-org access to a connection is architecturally impossible.

What if the shared-liability terms change?

Consent copy is version-stamped on every connection row. If the terms change, admins are re-prompted on their next visit before the integration keeps running.

Explore each integration.

Included on every Pro plan.

  • Marketplace-style Settings then Integrations page
  • 12 integrations at launch across email, voice, messaging, accounting, backup and payments
  • Per-tenant AES-GCM credential vault
  • Version-stamped consent copy per connection
  • Full audit trail on every connect, rotate and disconnect
  • Real connection state per tile (healthy, needs reconnect, last sync)
  • One-click disconnect with retained audit row
  • Framework-native drivers so new tools plug in without a rebuild

Try it in your firm's trial today.

Start a trial and connect your first integration in under a minute. Every credential is sealed with your organisation's key from the first connect.

Integrations Marketplace | ImmiIQ Migration CRM | ImmiIQ