Security
Estate posture — what exists, what threatens it, and how that is evidenced against control frameworks.
The Security group covers estate posture: what exists, what threatens it, and how that is evidenced against control frameworks.
A deliberate product position
Cost and security are the same problem viewed from two angles.
An orphaned resource is both waste and attack surface. An over-privileged identity is both a risk and a governance failure. Running both detector families over one inventory is what resolves the duplicated effort and contradictory priorities that usually result from treating them separately.
The three modules
Inventory
The live multi-cloud asset register — with scan lineage, stale-resource detection, and explicit coverage measurement.
FinSecOps
Unified multi-cloud threat posture, an automation fabric of webhooks and event buses, and identity controls across all four providers.
Compliance
Control-mapped findings across SOC 2, CIS, NIST, and ISO 27001, with one-click evidence export.
Coverage is itself a finding
The most dangerous inference in security tooling
"No findings" does not mean "no problems" — it may mean "nothing was scanned".
Inventory reports runtime coverage explicitly: what proportion of the estate is actually being scanned. Check it before drawing any conclusion from an empty findings list.