PLATFORM · DISCOVER

Discovery that needs no agent to install.

Agentless, read-only, near-real-time discovery — live today for AWS and GitHub, with GCP, Azure, GitLab, and Bitbucket connectors built and in preview. You grant read access; we map what is there. Nothing to deploy.

estate discovery · agentlessOSCAL
CONTROLSCOV.
IAM roles100%
Service accounts93%
Keys · tokens100%
OIDC · federation86%
agentlessread-onlysigned inventory covered partial
each cell links to a signed, replayable artifact
The problem

Every security tool that asks you to deploy a runtime, a sidecar, or an agent buys itself a months-long rollout and a permanent maintenance tax. Identity discovery should not require any of that. You grant read-only access at the org root, and the map fills in — no install, nothing to keep patched, and nothing new sitting in the blast radius.

What you get

Outcomes you can take to a skeptical security team.

  • Fully agentless and read-only — no runtime to install, patch, or babysit
  • AWS and GitHub live today from a single read-only grant — GCP, Azure, GitLab, and Bitbucket in preview
  • Near-real-time, so the picture stays current as the estate changes
  • Time-to-first-map measured in minutes, not a multi-quarter rollout
How it works

Three steps, no surprises.

01
Grant read access

A single read-only org-root grant per cloud or code host is all the access we ask for.

02
We map what is there

Every identity, role, and resource is discovered from what already exists — nothing to deploy.

03
Stay current

The map refreshes near-real-time as identities and grants change underneath you.

Continue the platform
Discover · proof anyone can verify

See Discovery on your own estate.

Read-only to start, human-approved for every fix. Bring your clouds and code hosts; we map what’s there and hand you proof you can verify yourself.

Book a demoSee it live →All 20 features
Discovery — Discover | TrustFix