Founding-partner program now open · request a scoped proof →
The platform · full module matrix

Four jobs. Twelve capabilities.

The detail behind the four layers — grouped by the job each capability does, with an honest read on what's live, in beta, or planned. No green-check theater.

Live today In beta Planned

Status reflects current product maturity and is confirmed in writing in any signed customer artifact. We'd rather tell you something is in beta than pretend it ships today.

01

Govern

Normalize every identity — human, non-human, and AI-agent — into one graph, and certify against real maturity.

You can't govern what you can't see. Most teams can't name half their service accounts, let alone their AI agents — so governance starts by making every identity visible in one place.

Unified identity graph Live

Human users, service accounts, API keys, and AI agents correlated across legacy and cloud into a single, queryable graph.

Access certifications Live

Campaigns that end in an auditor-grade evidence pack — reviewers certify against real access, not stale entitlements.

Access catalog & requests Beta

Self-service requests, approvals, and automatic reconciliation against the systems of record you already run.

02

Protect

Catch toxic access, dormant power, and AI-agent risk before it becomes an incident.

The access that causes breaches is rarely new — it's the dormant admin rights and quietly over-privileged agents nobody revisited. Protect is about catching those before an attacker does.

Segregation of duties Live

Detect and block toxic access combinations before they're granted, with policy you can read and audit.

Dormant & over-privileged access Beta

Surface dormant admin accounts, unused entitlements, and over-privileged agents that quietly accumulate risk.

AI-agent prompt-injection gate Beta

A pre-LLM guardrail aligned to OWASP ASI — inspect tool-use and prompts before an agent can act on them.

03

Revoke

One signal in, revoke fans out everywhere — closed-loop, outbound-only, verified.

Most tools tell you a revoke was requested. The question an auditor actually asks is whether it happened — across every system, with proof. Revoke isn't done until removal is verified and sealed.

Closed-loop revoke Live

HR or IdP signal triggers revoke across AD, Okta, AWS, and SaaS in seconds — then verifies removal actually happened.

Kill switch & dual control Live

Compromised account? Dry-run, two-person approval, revoke everywhere, verify, and seal — one controlled motion.

Outbound-only gateway Live

A customer-managed gateway dials out over mTLS. No inbound ports to open — built for restricted networks.

04

Prove

Every decision sealed into tamper-evident evidence on storage you control.

This is the gap I spent 26 years watching go unanswered: the decision lived in one system, the proof in spreadsheets and email. Prove makes the evidence math — verifiable on your own, without trusting us.

Hash-chained evidence packs Live

Every revoke, grant, and approval sealed into a SHA-256 hash-chain, signed with ECDSA — change one record and the chain breaks.

Customer-controlled storage Live

Evidence written to your own S3 with Object Lock and retention boundaries you set. Your keys (BYO-KMS) — we can't read it without you.

One-click audit export Beta

Generate a framework-mapped evidence pack (e.g. SOX §404) on demand — verifiable offline, without trusting us.

See it run in your environment.

A scoped proof shows these capabilities working against your real systems — and hands you the evidence pack to keep.