THE PLATFORM

One platform for every identity that isn’t human.

Discover, prove, govern, and fix every non-human and AI identity across your estate — with proof anyone can verify, offline, without a TrustFix account. Twenty capabilities, each with its own deep dive.

01

Discover

Find every non-human identity — agentless, read-only, near-real-time.

live trust graphdrill any node
IDENTITIESWORKLOADSRESOURCESDATAai-agentci-tokenoauth-appwebhookfn:lambdasvc-acctiam-rolek8s-sas3:prodkmsrdsecrsecretspii-storeanalyticsai-agent · DRILLEDpurpose · reconcile-invoicestool ceiling · 3 of 47last attested · 11h ago
15 nodes · 2 crown jewels · 2 reachable attack paths surfaced
Discover

See who can reach what — on one live graph.

Every non-human identity, role, agent, and resource on a single live graph you can drill into. Follow the reachability and find the path that should not exist.

  • Identities, roles, agents, and resources rendered as one connected, navigable view
  • Drill any node down to its grants and the resources it can actually reach
  • See the live path from an identity to sensitive data highlighted end to end
Explore Trust Graph
Discover

Every non-human identity, ranked by risk.

Service accounts, IAM roles, OAuth apps, keys, agents, and MCP servers across your whole estate — inventoried in one place and ordered by the risk each one carries.

  • One inventory spanning every cloud and every code host you connect
  • Service accounts, IAM roles, OAuth apps, keys, agents, and MCP servers in a single view
  • Ranked by risk so the most dangerous identity is first, not lost in the noise
Explore NHI Inventory
non-human identity · inventoryOSCAL
CONTROLSCOV.
Service accounts100%
IAM roles93%
OAuth apps100%
Agents · MCP86%
ranked by riskacross cloudsacross code hosts covered partial
each cell links to a signed, replayable artifact
estate discovery · agentlessOSCAL
CONTROLSCOV.
IAM roles100%
Service accounts93%
Keys · tokens100%
OIDC · federation86%
agentlessread-onlysigned inventory covered partial
each cell links to a signed, replayable artifact
Discover

Discovery that needs no agent to install.

Agentless, read-only, near-real-time discovery — live today for AWS and GitHub, with GCP, Azure, GitLab, and Bitbucket connectors built and in preview. You grant read access; we map what is there. Nothing to deploy.

  • Fully agentless and read-only — no runtime to install, patch, or babysit
  • AWS and GitHub live today from a single read-only grant — GCP, Azure, GitLab, and Bitbucket in preview
  • Near-real-time, so the picture stays current as the estate changes
Explore Discovery
Discover

Honest coverage — what we can and can’t do.

A plain-spoken map of every non-human-identity risk class: what we detect, what we notify on, and what we can actually fix. No coverage theater — the gaps are labeled too.

  • Every non-human-identity risk class laid out in one honest matrix
  • Clear per-class labels: detect, notify, or fix — never blurred together
  • Partial depth acknowledged where it is partial, not hidden behind a tick
Explore Coverage
detection coverageOSCAL
CONTROLSCOV.
Over-priv roles100%
Leaked keys93%
Attack phases100%
Toxic combos86%
detectnotifyfix covered partial
each cell links to a signed, replayable artifact
02

Prove

Turn every claim into a signed artifact anyone can verify — offline.

verifiable trust receiptVERIFIED
Agent Passport
W3C VERIFIABLE CREDENTIAL
subjectdid:key:z6Mk…ag01
purposereconcile invoices
tool ceilingread · 3 of 47
expiresin 11h 42m
proofW3C VC · did:key
siged25519:9f3a·c71e·b042·8d6f·a915·2c80·e7b3·14df
signature verifies · offline · /trust-receipt/…
Prove

Every agent carries a verifiable passport.

Each agent gets a signed Agent Passport — purpose, tool ceiling, and expiry — served at a public URL and verifiable offline, with no TrustFix account required.

  • A signed passport per agent stating its purpose, tool ceiling, and expiry
  • Served at a public URL and verifiable fully offline — no account needed
  • Built on W3C Verifiable Credentials 2.0 and did:key, not a proprietary format
Explore Agent Passports
Prove

Prove every hop only tightens authority.

When one agent hands work to another, prove the delegated authority only got smaller — never broader — and get a signed receipt either way. Grounded in the IETF Delegation-Receipt model.

  • Every mediated delegation hop checked: authority may narrow, never broaden
  • A signed receipt for each hop — whether it was allowed or refused
  • Built on the IETF Delegation-Receipt model, an open and inspectable format
Explore Delegation Provenance
verifiable trust receiptNARROWED
Delegation Receipt
W3C VERIFIABLE CREDENTIAL
fromagent-orchestrator
toagent-billing-01
scoperead ⊂ read+write
resultauthority reduced
proofIETF receipt · signed
siged25519:9f3a·c71e·b042·8d6f·a915·2c80·e7b3·14df
signed · offline-verifiable · /trust-receipt/…
policy diff · attack path−4+3
1policy "svc-acct-prod" {
2- grant: agent → svc-acct
3- reach: → s3:prod (crown jewel)
4- effect: ALLOW kms:*
5+ grant: scoped — read-only
6+ effect: ALLOW kms:Decrypt
7+ reach: ✕ s3:prod (severed)
8 review: human approver
9}
path severed: agent → s3:prod no longer reachable
previewed & confirmed before the PR merges
Prove

Know the fix works before you merge.

Before a remediation PR lands, confirm it actually severs the attack path it claims to close. No merging on faith — you see the path go dark first.

  • Compare the attack path before and after the proposed fix, side by side
  • Confirm the path is severed — not merely narrowed on paper
  • Catch fixes that look right but leave the reachability alive
Explore Counter-Factual
Prove

Every decision written to a tamper-evident ledger.

Every decision is recorded in a signed, tamper-evident ledger an auditor can replay offline — with no TrustFix account required. Every figure you see clicks back to a real entry.

  • A signed, tamper-evident record of every decision the platform makes
  • Replayable offline by an auditor — no TrustFix account required
  • Every figure in the product traces back to a real, clickable ledger entry
Explore Trust Ledger
trust ledger · tamper-evidenthash-chained
#4,182decision · allowa91f…3e7SIGNED
#4,181remediation · merged7c0e…b12SIGNED
#4,180passport · issuedd5b2…9afSIGNED
#4,179delegation · receipt0f3a…6c1SIGNED
#4,178attestation · renewedb418…22dSIGNED
#4,177policy · narrowede90c…f54SIGNED
replayable offline · /trust-receipt/… · no account needed
03

Detect

Catch the risk — and the agentic attack — against each identity’s own baseline.

agentic attack · phase coverageOSCAL
CONTROLSCOV.
Reconnaissance100%
Priv. escalation93%
Exfiltration100%
Lateral movement86%
per-agent baselinedetectnotify covered partial
each cell links to a signed, replayable artifact
Detect

Flag the phases of an agentic attack.

Surface the phases of an agentic attack — recon, privilege escalation, exfiltration, lateral movement, and multi-agent campaigns — measured against each agent’s own baseline. This is detection and notification; you decide the response.

  • Surfaces recon, privilege escalation, exfiltration, and lateral movement
  • Catches coordinated multi-agent campaigns, not just a single rogue agent
  • Measured against each agent’s own baseline, so different agents are judged fairly
Explore AI-Attack Detection
Detect

When benign findings become a path.

Surface the moment separately-benign findings line up into a real, walkable attack path — then watch it auto-close when you fix the root cause.

  • Connects findings that each look harmless in isolation
  • Shows the real, walkable attack path they form together
  • Points you at the single root cause that collapses the whole path
Explore Toxic Combinations
policy diff · attack path−4+3
1policy "svc-acct-prod" {
2- grant: public read → over-scoped role
3- reach: → data exfil (crown jewel)
4- effect: ALLOW kms:*
5+ grant: scoped — read-only
6+ effect: ALLOW kms:Decrypt
7+ reach: ✕ data exfil (severed)
8 review: human approver
9}
path severed: public read → data exfil no longer reachable
previewed & confirmed before the PR merges
leaked credentials · blast radiusOSCAL
CONTROLSCOV.
Leaked100%
Over-scoped93%
Unrotated100%
Exposed in code86%
real blast radiusprioritizedacross estate covered partial
each cell links to a signed, replayable artifact
Detect

Find leaked keys before an attacker does.

See risk and real-world exposure on a single key in one place — leaked, over-scoped, and unrotated credentials surfaced before someone outside finds them first.

  • Risk and real-world exposure for each credential, shown side by side
  • Catches leaked, over-scoped, and unrotated keys across clouds and code hosts
  • Prioritized so the most dangerous credential surfaces first, not the loudest
Explore Credential Leaks
Detect

Nothing silently goes stale.

Trust decays over time. The clock surfaces what needs re-attesting and when — turning a pile of aging passports and credentials into an ordered worklist instead of a surprise.

  • Treats trust as something that ages, not a one-time check you do once
  • An ordered worklist of exactly what to re-attest, and when
  • Stale-now, due-soon, and fresh separated at a glance
Explore Attestation Clock
re-attestation worklist6 stale
232IN QUEUE
6stale now
14due this week
212fresh
svc-deploy-prod41%re-attest now
ai-agent-billing58%re-attest in 1d
ci-token-release72%re-attest in 3d
oauth-analytics88%re-attest in 6d
kms-rotator96%re-attest in 12d
trust ages — re-attest before it expires into a gap
04

Govern & Fix

Hold authority inside the lines you set — and close issues, don’t just list them.

the gate · decision log1,284 / hr
AGENT · ACTIONVERDICTRECEIPT
ag-support-04 · rds:DeleteDBDENY#7c0e
ag-deploy-02 · s3:PutObjectMEDIATE#d5b2
ag-billing-01 · secrets:GetALLOW#0f3a
ag-recon-09 · iam:CreateUserDENY#b418
every call checked against signed authority · receipt emitted
Govern & Fix

Allow, mediate, or deny — every decision.

Each decision a non-human identity makes is checked against its signed authority and answered: allow, mediate, or deny. Every answer comes out as a receipt you can verify.

  • Three clear outcomes per request: allow, mediate, or deny
  • Each decision checked against the identity’s own signed authority
  • A verifiable receipt emitted for every decision, not just the denials
Explore The Gate
Govern & Fix

We don’t just detect — we fix.

Remediation arrives as a pull request — each one carrying a signed decision record — and after it merges, we check it against your live logs to confirm the issue actually closed.

  • Fixes ship as pull requests you review and merge — always human-approved
  • Each PR carries a signed decision record of what changed and why
  • Verified against your live logs after merge — confirmed closed, not assumed
Explore Remediation
verifiable trust receiptMERGED
Remediation PR
W3C VERIFIABLE CREDENTIAL
targetsvc-deploy-prod
changekms:* → kms:Decrypt
approved byhuman reviewer
post-mergeconfirmed in live logs
recordsigned decision
siged25519:9f3a·c71e·b042·8d6f·a915·2c80·e7b3·14df
verified against your live logs after merge
trust boundaries · in forceOSCAL
CONTROLSCOV.
No prod → ext agents100%
CI read-only in prod93%
Reach ⊆ purpose100%
Drift surfaced86%
in forcecontinuoussurfaced covered partial
each cell links to a signed, replayable artifact
Govern & Fix

Keep authority inside the lines you set.

Set the guardrails once and let them hold: policy boundaries that keep every identity’s authority where you decided it should stay.

  • Define the boundaries that each identity’s authority is allowed to live within
  • Guardrails apply continuously, not just at review time
  • Drift outside the lines is surfaced rather than silently permitted
Explore Trust Boundaries
Govern & Fix

Replace a standing secret with one born verified.

Swap a long-lived standing secret for a secretless, proof-carrying, short-lived identity — issued already verified, so there is no static credential left to leak.

  • Retires standing secrets in favor of short-lived identities
  • Secretless and proof-carrying from the moment the identity exists
  • Nothing static left sitting in a vault or env file to be stolen
Explore Born-Verified Issuance
verifiable trust receiptISSUED
Born-Verified Identity
W3C VERIFIABLE CREDENTIAL
replacesstanding API key
typeshort-lived · secretless
carriesproof-carrying credential
lifetimeminted on demand
stateborn verified
siged25519:9f3a·c71e·b042·8d6f·a915·2c80·e7b3·14df
no static credential left to leak
05

Evidence

Make the whole posture provable — to an auditor, a board, or a regulator.

evidence pack · signedOSCAL
CONTROLSCOV.
Access control100%
Key rotation93%
Least privilege100%
Audit trail86%
signed artifactsOSCAL exportreplayable covered partial
each cell links to a signed, replayable artifact
Evidence

Controls backed by signed artifacts.

Every compliance control points to a real, replayable ledger entry — not a screenshot or a promise. Export the whole pack as NIST OSCAL.

  • Each control links to a signed, replayable artifact — not a screenshot
  • Evidence is generated as work happens, not assembled by hand at audit time
  • Export the whole pack as NIST OSCAL for the auditor’s own tooling
Explore Evidence Pack
Evidence

The board-legible view of your posture.

One clean view of your non-human identity posture that a board can actually read — trend, open paths, coverage — without a security degree to interpret it.

  • Posture trend, open paths, and coverage at a single glance
  • Plain language a board can read and act on without a translator
  • Every headline number still traces back to a signed ledger entry
Explore Board Brief
board brief · postureOSCAL
CONTROLSCOV.
Posture trend100%
Open paths93%
Coverage100%
Re-attest due86%
board-legibleclickable to proofquarterly-ready covered partial
each cell links to a signed, replayable artifact
replay posture · point in timedrag to scrub
90d agoMar 14today
role over-scoped
path opened
remediation merged
attestation renewed
◉ @ MAR 14
198
NHIs
4
stale passports
3
open paths
backed by the same signed ledger — not a reconstruction
Evidence

Replay your posture at any point in time.

Roll back to any moment and see exactly what your non-human identity posture looked like then — for an incident review, an audit window, or a board question about what you knew, and when.

  • Reconstruct your posture as of any past date, exactly as it stood
  • Answer incident and audit questions with the real history, not memory
  • Settle "what did we know, and when" with a faithful record
Explore Time Travel
Evidence

Map evidence to the frameworks that matter.

Map your signed proof to SOC 2, ISO 27001, NIST, and the EU AI Act — and export it as OSCAL or OCSF so it drops into the tools your auditors and SIEM already use.

  • SOC 2, ISO 27001, NIST, and EU AI Act mappings from one body of proof
  • Backed by signed evidence, not self-attestation
  • Exportable as OSCAL and OCSF — open formats, not a proprietary report
Explore Compliance
control coverage · signed evidenceOSCAL
CONTROLSCOV.
SOC 2100%
ISO 2700193%
NIST100%
EU AI Act86%
OSCAL exportOCSF feedreplayable ledger covered partial
each cell links to a signed, replayable artifact
One platform · proof anyone can verify

See every non-human identity — and prove it’s under control.

Read-only to start, human-approved for every fix. Bring your clouds and code hosts; we map what’s there and hand you proof you can verify yourself.

Book a demoLaunch app
Platform | TrustFix