Agentless inventory in minutes
Connect a read-only role and Vault maps accounts, projects, subscriptions, and clusters — no agents, no sidecars, no change windows. Full first graph in under an hour on most estates.
all systems operational · status.vaultsecurity.example SOC 2 Type II · ISO 27001 · fictional demo attestations
[ VS-01 → VS-04 / Platform ]
Point tools disagree because they each see a slice. Every Vault module reads and writes the same graph of your estate — so a detection knows its blast radius, an entitlement knows its exposure, and every control knows its evidence.
[ Architecture ]
The pipeline is deliberately boring: connect, model, rank, prove. What makes it work is that no step ever leaves the graph — context compounds instead of fragmenting across consoles.
STAGE 01
Connect
Read-only API role, 15 minutes, no agents
STAGE 02
Graph
Every resource, identity, and path — one model
STAGE 03
Prioritize
Attack paths ranked by real blast radius
STAGE 04
Prove
Evidence collected continuously, mapped to 27 frameworks
[ VS-01 / Posture Graph ]
One graph of everything you run — every resource, identity, network path, and data store across AWS, Azure, GCP, and Kubernetes — built agentlessly from read-only API access. Vault correlates misconfigurations with exposure and identity so you fix the nine paths that matter, not triage 40,000 alerts.
Connect a read-only role and Vault maps accounts, projects, subscriptions, and clusters — no agents, no sidecars, no change windows. Full first graph in under an hour on most estates.
The graph traces real chains — internet-exposed workload → over-privileged role → production data store — and ranks them by blast radius, so 'critical' means reachable, not just misconfigured.
A public bucket is a finding. A public bucket holding PHI, writable by a stale contractor key, is an incident waiting. Vault scores the combination, not the checkbox.
Terraform plans are evaluated against the same policy set before apply — findings arrive as pull-request comments with the exact resource block and a suggested fix, in under 90 seconds.
Event-driven deltas land in the graph within about two minutes of a change, with a diff against the last known-good state and the identity that made it.
Sampled, in-region scanning tags stores that hold PII, PHI, or payment data — so exposure findings carry data context without your data leaving your cloud.
[ VS-02 / Runtime Detect ]
Detection that starts from your control plane, not another appliance. Vault watches cloud audit logs agentlessly for every tenant, and an optional lightweight eBPF sensor adds process-level runtime signal where the stakes justify it — with containment actions that always ask a human first, by default.
Cloud audit and network flow logs are streamed and evaluated against a managed library of 600+ detections mapped to MITRE ATT&CK — live for every connected account from day one.
A single sensor per node adds process, file, and network telemetry with a measured 0.6% p95 CPU budget. Agentless-first is the default; the sensor is for the clusters that earn it.
Every detection lands pre-joined to the Posture Graph: the workload, its exposure, the identity involved, and what that identity could reach next. No pivoting across four consoles.
Isolate a node, revoke a session, quarantine a key — one click, logged, and human-approved by default. Auto-containment is opt-in, per rule, per environment.
A reconstructed sequence of control-plane and runtime events around any finding, exportable for IR retainers and post-incident review.
Detections route by severity and ownership to your paging and chat tools with deduplication — the same alert never pages two teams.
[ VS-03 / Identity Map ]
Policy documents lie by omission. Identity Map computes effective permissions — what every human and non-human identity can actually do once groups, inheritance, and assumable roles resolve — then shows you the privilege nobody has used in 90 days and drafts the policy that removes it.
Vault resolves the full chain — group membership, role assumption, resource policies, permission boundaries — into the true blast radius of each identity, per cloud, in one view.
Every permission is compared against 90 days of actual usage. On typical estates, 60–80% of granted privilege is never exercised — Vault lists it, ranked by risk.
For IaC-managed identities, Vault drafts the reduced policy as a pull request against your repo — reviewed, versioned, and revertible like any other change.
Service accounts, access keys, and workload identities with age, rotation status, and last use — the 3 a.m. incident review, available at 3 p.m. instead.
Every external principal with access into your estate — vendors, SaaS integrations, former contractors — with what they can reach and when they last did.
Standing admin becomes request-based: time-boxed grants with approval workflows, automatic expiry, and a complete audit trail the Evidence Engine picks up for free.
[ VS-04 / Evidence Engine ]
Audits fail on evidence, not intent. The Evidence Engine maps your live environment to 27 frameworks — SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, FedRAMP and more — collects timestamped artifacts continuously, and gives your auditor a scoped, read-only workspace so screenshot season never happens again.
Controls are tested against the live graph on a schedule, not sampled once a year. When a control drifts out of conformance, the owner is paged before the auditor notices.
One piece of evidence — encryption at rest, say — is automatically cross-mapped to every framework that requires it. Adding a framework reuses most of what you already prove.
Screenshots rot. Every artifact carries a collection timestamp and an auto-recollection schedule, so nothing you hand an auditor is older than its framework allows.
A scoped, read-only seat where your auditor pulls their own evidence — logged, watermarked, and limited to the engagement window. Field work shrinks from weeks to days.
Every failing control becomes a tracked gap with an owner, a due date, and a remediation link — exportable to your ticketing tool, reportable to your board.
Security-questionnaire answers drafted from your live control state, with citations to the underlying evidence — review, edit, send.
[ Keep reading ]
[ Next step ]
A 45-minute demo on your environment, run by a named solutions engineer — no slideware. Or let the comparison tool tell you honestly whether you should buy us at all.