One marketplace for every tool your firm already runs on.
The integrations marketplace lives at Settings then Integrations. Every third-party tool your firm already runs on is one tile away: Gmail and Microsoft 365 for email, Twilio and JustCall for voice, Xero for accounting, Google Drive, OneDrive, Dropbox and your own S3 bucket for backup, plus Stripe Connect for client payments. Every tile shows real connection state at a glance with the last sync stamp and account name inline.
Gmail
ReconnectMicrosoft 365
ConnectedJustCall
ConnectedTwilio Voice
ConnectedTwilio Messaging
ReconnectXero
ConnectedGoogle Drive
ConnectedOneDrive
ConnectedDropbox
ReconnectBring what you use. Keep what you own.
The marketplace is the governance layer over every third-party connection: sealed credentials, versioned consent and audit rows on every connect, rotate and disconnect.
One tile per tool
Every third-party surface lives at Settings then Integrations. Real connection state, last-sync stamp and account name inline on each tile.
Sealed credential vault
Every connection is sealed with your organisation's AES-GCM key. Plaintext credentials never leave the driver that owns the connection.
Versioned consent
Consent copy is stamped on every connection row. Change the shared-liability terms and admins are re-prompted before the connection keeps running.
One-click disconnect
Disconnect any integration in a click. The connection row is retained for audit so you always see who connected what and when.
Every tile at a glance.
Twelve integrations at launch. New drivers plug into the same framework so future tools inherit the vault, the consent flow and the audit trail on day one.
Gmail
Microsoft 365
JustCall
Voice
Twilio Voice
Voice
Twilio Messaging
SMS + WhatsApp
Xero
Accounting
Google Drive
Backup
OneDrive
Backup
Dropbox
Backup
Customer S3
Backup
Sender Domain
Deliverability
Inbound Email
Deliverability
Stripe Connect
Payments
Anatomy of a connection.
Same shape for every integration. Consent, OAuth or credentials, sealed storage, audit. Reversible in one click.
Read the shared-responsibility notice
Each connect modal shows what ImmiIQ will do with the token and what the firm still owns. Consent copy is version-stamped so future changes trigger a re-prompt.
OAuth or paste credentials
Follow the provider's OAuth prompt or paste API keys inline. Credentials get sealed with your organisation's AES-GCM key before they touch the database.
Use it. Rotate it. Disconnect it.
Every connect, rotate and disconnect writes an audit row. Disconnecting drops the sealed blob in the same transaction that closes the connection row.
Security
Every connection scoped to your org. Every credential sealed with your key.
Every integration connection is scoped to your organisation and its credentials are sealed with a per-tenant AES-GCM key derived from your organisation id. Plaintext credentials never leave the vault; the sealed blob is not exposed to application code beyond the driver that owns the connection. Consent copy is version-stamped on every connection row, so a change to the shared-liability terms triggers a re-prompt before the integration keeps running. Every connect, disconnect and credential rotation writes an audit row and audit-log write failures page the operator so silent loss is impossible.
Frequently asked.
Can I bring my own tools into ImmiIQ?
Yes. The integrations marketplace lets your firm connect its own mailbox, phone system, accounting ledger and backup destination. Credentials stay sealed with your per-organisation key, consent is versioned and you can disconnect any integration in one click.
What happens to my tokens if I disconnect?
Disconnecting drops the sealed credential blob and tears down any provider push subscription in the same transaction that closes the connection row. The connection row itself is retained for audit so you always see who connected what and when.
Do the connections leak between organisations on shared infrastructure?
No. Every connection is keyed by organisation id and sealed with a per-tenant AES-GCM envelope. Cross-org access to a connection is architecturally impossible.
What if the shared-liability terms change?
Consent copy is version-stamped on every connection row. If the terms change, admins are re-prompted on their next visit before the integration keeps running.
Explore each integration.
Included on every Pro plan.
- Marketplace-style Settings then Integrations page
- 12 integrations at launch across email, voice, messaging, accounting, backup and payments
- Per-tenant AES-GCM credential vault
- Version-stamped consent copy per connection
- Full audit trail on every connect, rotate and disconnect
- Real connection state per tile (healthy, needs reconnect, last sync)
- One-click disconnect with retained audit row
- Framework-native drivers so new tools plug in without a rebuild
Try it in your firm's trial today.
Start a trial and connect your first integration in under a minute. Every credential is sealed with your organisation's key from the first connect.