Discover
Find every non-human identity — agentless, read-only, near-real-time.
See who can reach what — on one live graph.
Every non-human identity, role, agent, and resource on a single live graph you can drill into. Follow the reachability and find the path that should not exist.
- Identities, roles, agents, and resources rendered as one connected, navigable view
- Drill any node down to its grants and the resources it can actually reach
- See the live path from an identity to sensitive data highlighted end to end
Every non-human identity, ranked by risk.
Service accounts, IAM roles, OAuth apps, keys, agents, and MCP servers across your whole estate — inventoried in one place and ordered by the risk each one carries.
- One inventory spanning every cloud and every code host you connect
- Service accounts, IAM roles, OAuth apps, keys, agents, and MCP servers in a single view
- Ranked by risk so the most dangerous identity is first, not lost in the noise
Discovery that needs no agent to install.
Agentless, read-only, near-real-time discovery — live today for AWS and GitHub, with GCP, Azure, GitLab, and Bitbucket connectors built and in preview. You grant read access; we map what is there. Nothing to deploy.
- Fully agentless and read-only — no runtime to install, patch, or babysit
- AWS and GitHub live today from a single read-only grant — GCP, Azure, GitLab, and Bitbucket in preview
- Near-real-time, so the picture stays current as the estate changes
Honest coverage — what we can and can’t do.
A plain-spoken map of every non-human-identity risk class: what we detect, what we notify on, and what we can actually fix. No coverage theater — the gaps are labeled too.
- Every non-human-identity risk class laid out in one honest matrix
- Clear per-class labels: detect, notify, or fix — never blurred together
- Partial depth acknowledged where it is partial, not hidden behind a tick
Prove
Turn every claim into a signed artifact anyone can verify — offline.
Every agent carries a verifiable passport.
Each agent gets a signed Agent Passport — purpose, tool ceiling, and expiry — served at a public URL and verifiable offline, with no TrustFix account required.
- A signed passport per agent stating its purpose, tool ceiling, and expiry
- Served at a public URL and verifiable fully offline — no account needed
- Built on W3C Verifiable Credentials 2.0 and did:key, not a proprietary format
Prove every hop only tightens authority.
When one agent hands work to another, prove the delegated authority only got smaller — never broader — and get a signed receipt either way. Grounded in the IETF Delegation-Receipt model.
- Every mediated delegation hop checked: authority may narrow, never broaden
- A signed receipt for each hop — whether it was allowed or refused
- Built on the IETF Delegation-Receipt model, an open and inspectable format
Know the fix works before you merge.
Before a remediation PR lands, confirm it actually severs the attack path it claims to close. No merging on faith — you see the path go dark first.
- Compare the attack path before and after the proposed fix, side by side
- Confirm the path is severed — not merely narrowed on paper
- Catch fixes that look right but leave the reachability alive
Every decision written to a tamper-evident ledger.
Every decision is recorded in a signed, tamper-evident ledger an auditor can replay offline — with no TrustFix account required. Every figure you see clicks back to a real entry.
- A signed, tamper-evident record of every decision the platform makes
- Replayable offline by an auditor — no TrustFix account required
- Every figure in the product traces back to a real, clickable ledger entry
Detect
Catch the risk — and the agentic attack — against each identity’s own baseline.
Flag the phases of an agentic attack.
Surface the phases of an agentic attack — recon, privilege escalation, exfiltration, lateral movement, and multi-agent campaigns — measured against each agent’s own baseline. This is detection and notification; you decide the response.
- Surfaces recon, privilege escalation, exfiltration, and lateral movement
- Catches coordinated multi-agent campaigns, not just a single rogue agent
- Measured against each agent’s own baseline, so different agents are judged fairly
When benign findings become a path.
Surface the moment separately-benign findings line up into a real, walkable attack path — then watch it auto-close when you fix the root cause.
- Connects findings that each look harmless in isolation
- Shows the real, walkable attack path they form together
- Points you at the single root cause that collapses the whole path
Find leaked keys before an attacker does.
See risk and real-world exposure on a single key in one place — leaked, over-scoped, and unrotated credentials surfaced before someone outside finds them first.
- Risk and real-world exposure for each credential, shown side by side
- Catches leaked, over-scoped, and unrotated keys across clouds and code hosts
- Prioritized so the most dangerous credential surfaces first, not the loudest
Nothing silently goes stale.
Trust decays over time. The clock surfaces what needs re-attesting and when — turning a pile of aging passports and credentials into an ordered worklist instead of a surprise.
- Treats trust as something that ages, not a one-time check you do once
- An ordered worklist of exactly what to re-attest, and when
- Stale-now, due-soon, and fresh separated at a glance
Govern & Fix
Hold authority inside the lines you set — and close issues, don’t just list them.
Allow, mediate, or deny — every decision.
Each decision a non-human identity makes is checked against its signed authority and answered: allow, mediate, or deny. Every answer comes out as a receipt you can verify.
- Three clear outcomes per request: allow, mediate, or deny
- Each decision checked against the identity’s own signed authority
- A verifiable receipt emitted for every decision, not just the denials
We don’t just detect — we fix.
Remediation arrives as a pull request — each one carrying a signed decision record — and after it merges, we check it against your live logs to confirm the issue actually closed.
- Fixes ship as pull requests you review and merge — always human-approved
- Each PR carries a signed decision record of what changed and why
- Verified against your live logs after merge — confirmed closed, not assumed
Keep authority inside the lines you set.
Set the guardrails once and let them hold: policy boundaries that keep every identity’s authority where you decided it should stay.
- Define the boundaries that each identity’s authority is allowed to live within
- Guardrails apply continuously, not just at review time
- Drift outside the lines is surfaced rather than silently permitted
Replace a standing secret with one born verified.
Swap a long-lived standing secret for a secretless, proof-carrying, short-lived identity — issued already verified, so there is no static credential left to leak.
- Retires standing secrets in favor of short-lived identities
- Secretless and proof-carrying from the moment the identity exists
- Nothing static left sitting in a vault or env file to be stolen
Evidence
Make the whole posture provable — to an auditor, a board, or a regulator.
Controls backed by signed artifacts.
Every compliance control points to a real, replayable ledger entry — not a screenshot or a promise. Export the whole pack as NIST OSCAL.
- Each control links to a signed, replayable artifact — not a screenshot
- Evidence is generated as work happens, not assembled by hand at audit time
- Export the whole pack as NIST OSCAL for the auditor’s own tooling
The board-legible view of your posture.
One clean view of your non-human identity posture that a board can actually read — trend, open paths, coverage — without a security degree to interpret it.
- Posture trend, open paths, and coverage at a single glance
- Plain language a board can read and act on without a translator
- Every headline number still traces back to a signed ledger entry
Replay your posture at any point in time.
Roll back to any moment and see exactly what your non-human identity posture looked like then — for an incident review, an audit window, or a board question about what you knew, and when.
- Reconstruct your posture as of any past date, exactly as it stood
- Answer incident and audit questions with the real history, not memory
- Settle "what did we know, and when" with a faithful record
Map evidence to the frameworks that matter.
Map your signed proof to SOC 2, ISO 27001, NIST, and the EU AI Act — and export it as OSCAL or OCSF so it drops into the tools your auditors and SIEM already use.
- SOC 2, ISO 27001, NIST, and EU AI Act mappings from one body of proof
- Backed by signed evidence, not self-attestation
- Exportable as OSCAL and OCSF — open formats, not a proprietary report