Skip to main content

all systems operational · status.vaultsecurity.example SOC 2 Type II · ISO 27001 · fictional demo attestations

VAULT SECURITY
Request a demo

[ VS-01 → VS-04 / Platform ]

Four modules, one graph

Point tools disagree because they each see a slice. Every Vault module reads and writes the same graph of your estate — so a detection knows its blast radius, an entitlement knows its exposure, and every control knows its evidence.

[ Architecture ]

From read-only access to audit-ready proof

The pipeline is deliberately boring: connect, model, rank, prove. What makes it work is that no step ever leaves the graph — context compounds instead of fragmenting across consoles.

  1. STAGE 01

    Connect

    Read-only API role, 15 minutes, no agents

  2. STAGE 02

    Graph

    Every resource, identity, and path — one model

  3. STAGE 03

    Prioritize

    Attack paths ranked by real blast radius

  4. STAGE 04

    Prove

    Evidence collected continuously, mapped to 27 frameworks

[ VS-01 / Posture Graph ]

Agentless cloud posture & attack paths

One graph of everything you run — every resource, identity, network path, and data store across AWS, Azure, GCP, and Kubernetes — built agentlessly from read-only API access. Vault correlates misconfigurations with exposure and identity so you fix the nine paths that matter, not triage 40,000 alerts.

Deployment
Agentless — read-only API role
Graph rebuild
Nightly full · ~2 min event deltas
Coverage
AWS · Azure · Google Cloud · Kubernetes

Agentless inventory in minutes

Connect a read-only role and Vault maps accounts, projects, subscriptions, and clusters — no agents, no sidecars, no change windows. Full first graph in under an hour on most estates.

Attack-path analysis

The graph traces real chains — internet-exposed workload → over-privileged role → production data store — and ranks them by blast radius, so 'critical' means reachable, not just misconfigured.

Toxic-combination prioritization

A public bucket is a finding. A public bucket holding PHI, writable by a stale contractor key, is an incident waiting. Vault scores the combination, not the checkbox.

IaC scanning at the gate

Terraform plans are evaluated against the same policy set before apply — findings arrive as pull-request comments with the exact resource block and a suggested fix, in under 90 seconds.

Drift detection

Event-driven deltas land in the graph within about two minutes of a change, with a diff against the last known-good state and the identity that made it.

Data exposure classification

Sampled, in-region scanning tags stores that hold PII, PHI, or payment data — so exposure findings carry data context without your data leaving your cloud.

[ VS-02 / Runtime Detect ]

Cloud detection & response

Detection that starts from your control plane, not another appliance. Vault watches cloud audit logs agentlessly for every tenant, and an optional lightweight eBPF sensor adds process-level runtime signal where the stakes justify it — with containment actions that always ask a human first, by default.

Deployment
Agentless default · optional eBPF sensor
Detection library
600+ managed rules · ATT&CK-mapped
Containment
Human-approved by default

Control-plane detections, agentless

Cloud audit and network flow logs are streamed and evaluated against a managed library of 600+ detections mapped to MITRE ATT&CK — live for every connected account from day one.

eBPF runtime sensor (optional)

A single sensor per node adds process, file, and network telemetry with a measured 0.6% p95 CPU budget. Agentless-first is the default; the sensor is for the clusters that earn it.

Findings with the whole story

Every detection lands pre-joined to the Posture Graph: the workload, its exposure, the identity involved, and what that identity could reach next. No pivoting across four consoles.

Guarded containment actions

Isolate a node, revoke a session, quarantine a key — one click, logged, and human-approved by default. Auto-containment is opt-in, per rule, per environment.

Forensic timeline

A reconstructed sequence of control-plane and runtime events around any finding, exportable for IR retainers and post-incident review.

On-call routing

Detections route by severity and ownership to your paging and chat tools with deduplication — the same alert never pages two teams.

[ VS-03 / Identity Map ]

Cloud identity & entitlements

Policy documents lie by omission. Identity Map computes effective permissions — what every human and non-human identity can actually do once groups, inheritance, and assumable roles resolve — then shows you the privilege nobody has used in 90 days and drafts the policy that removes it.

Usage window
90-day exercised-permission analysis
Remediation
Policy PRs via your source control
Elevation
JIT grants · auto-expiry · full audit trail

Effective-permission computation

Vault resolves the full chain — group membership, role assumption, resource policies, permission boundaries — into the true blast radius of each identity, per cloud, in one view.

Unused-privilege detection

Every permission is compared against 90 days of actual usage. On typical estates, 60–80% of granted privilege is never exercised — Vault lists it, ranked by risk.

One-click least-privilege PRs

For IaC-managed identities, Vault drafts the reduced policy as a pull request against your repo — reviewed, versioned, and revertible like any other change.

Non-human identity inventory

Service accounts, access keys, and workload identities with age, rotation status, and last use — the 3 a.m. incident review, available at 3 p.m. instead.

Third-party access register

Every external principal with access into your estate — vendors, SaaS integrations, former contractors — with what they can reach and when they last did.

Just-in-time elevation

Standing admin becomes request-based: time-boxed grants with approval workflows, automatic expiry, and a complete audit trail the Evidence Engine picks up for free.

[ VS-04 / Evidence Engine ]

Continuous compliance automation

Audits fail on evidence, not intent. The Evidence Engine maps your live environment to 27 frameworks — SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, FedRAMP and more — collects timestamped artifacts continuously, and gives your auditor a scoped, read-only workspace so screenshot season never happens again.

Frameworks
27 mapped · cross-framework reuse
Evidence
Timestamped · auto-recollected
Auditor access
Scoped read-only workspace

Continuous control monitoring

Controls are tested against the live graph on a schedule, not sampled once a year. When a control drifts out of conformance, the owner is paged before the auditor notices.

Satisfy once, map everywhere

One piece of evidence — encryption at rest, say — is automatically cross-mapped to every framework that requires it. Adding a framework reuses most of what you already prove.

Evidence freshness SLAs

Screenshots rot. Every artifact carries a collection timestamp and an auto-recollection schedule, so nothing you hand an auditor is older than its framework allows.

Auditor workspace

A scoped, read-only seat where your auditor pulls their own evidence — logged, watermarked, and limited to the engagement window. Field work shrinks from weeks to days.

Gap register with owners

Every failing control becomes a tracked gap with an owner, a due date, and a remediation link — exportable to your ticketing tool, reportable to your board.

Questionnaire answering

Security-questionnaire answers drafted from your live control state, with citations to the underlying evidence — review, edit, send.

[ Next step ]

See your own estate in the graph

A 45-minute demo on your environment, run by a named solutions engineer — no slideware. Or let the comparison tool tell you honestly whether you should buy us at all.

Sample site by SearchPod