Products

One product in market.
Six the engagements keep asking for.

Every product here started as a problem a consulting engagement kept running into. That is the sequencing rule: we build what the practice proves is real, not what looks fundable. One is live today. The rest are roadmap, and we label them that way.

Live flagship product

AuditGraph

Identity Security Graph

Reveals what every human, non-human and AI identity can access, reach and impact — derived from your cloud architecture, not your logs.

AuditGraph models the identity estate as a graph and computes consequence from configuration: role assignments, scope hierarchies, federation, PIM eligibility. Because it reads architecture rather than telemetry, it produces a complete answer on the roughly 70% of tenants that do not run the logging a behavior-based product requires. Azure is generally available; AWS and GCP connectors are roadmap.

Built for SecurityIAMAudit
Core capabilities
  • Human, non-human and AI identities in one graph — AI agents modeled as a subtype of NHI, never a separate product
  • Inheritance-aware reachability: scope hierarchies resolved, not transcribed
  • Nine lineage verdicts assigned continuously, with no dependency on sign-in logs
  • Attack paths and blast radius computed before exploitation
  • Bands derived from measured facts — no proprietary risk score, anywhere
  • Evidence trails and control mappings for NIST, CIS, HIPAA, SOC 2 and ISO 27001
Pricing
$500 platform / cloud / mo + $69 per subscription / mo

Free tier with no time limit · 30-day trial of every feature · no card · commitment discounts to 35%

Product roadmap

Six more, sequenced by demand.

None of the following is available today, and no launch dates are promised. They are published because a roadmap you can read is more useful than one you cannot — and because which of them ships first is a decision our engagements will make, not our marketing.

RoleIQ

Authorization Intelligence
Roadmap

Role mining, RBAC and ABAC recommendations, separation-of-duties analysis and access optimization.

Every large organization has a role model that drifted. RoleIQ is intended to mine what access people actually hold and use, propose a role structure that fits it, and surface the toxic combinations that separation-of-duties policy already forbids on paper.

  • Role mining from effective entitlements rather than intended design
  • RBAC and ABAC model recommendations
  • Separation-of-duties conflict analysis
  • Access optimization with least-privilege targets
For IAM teamsERP teamsEnterprise architects
Tell us this is the one you need →

GovernanceHub

Architecture Governance
Roadmap

Architecture Review Board workflow, standards, exception management and decision tracking.

Architecture governance usually lives in a wiki, a spreadsheet and somebody’s memory. GovernanceHub is intended to make it an operating system: standards that are queryable, exceptions with owners and expiry dates, and decisions with a record of why they were made.

  • ARB submission and review workflow
  • Architecture standards as living, queryable records
  • Exception management with owners and expiry
  • Risk acceptance and decision tracking
For Enterprise architecturePlatform teamsCTO office
Tell us this is the one you need →

ComplianceIQ

Compliance Automation
Roadmap

Control mapping, evidence collection, audit readiness, risk register and policy management.

Compliance evidence goes stale the moment it is collected. ComplianceIQ is intended to make evidence a continuous output of the environment rather than a quarterly project, mapping one fact set to whichever framework is asking.

  • Multi-framework control mapping from a single fact set
  • Continuous evidence collection tied to live configuration
  • Audit readiness tracked over time, not sampled at audit
  • Risk register and policy management
For ComplianceInternal auditMid-market security
Tell us this is the one you need →

CostLens

FinOps & Cloud Economics
Roadmap

Cloud cost visibility, optimization recommendations, forecasting and budget tracking.

Most cost tools attribute spend to resources. The more useful question is which workload — and which identity — caused it. CostLens is intended to give cost an owner rather than a line item.

  • Cost visibility across accounts and subscriptions
  • Optimization and right-sizing recommendations
  • Forecasting with budget guardrails
  • Per-workload and per-team attribution
For FinOpsPlatform engineeringFinance
Tell us this is the one you need →

HealthCloud Compass

Healthcare Cloud Governance
Roadmap

HIPAA control tracking, cloud governance, data flow mapping and audit readiness for healthcare estates.

Healthcare runs on integrations, and each one moves regulated data somewhere. HealthCloud Compass is intended to make those flows explicit and tie them to the HIPAA controls that govern them — built on the sector where our own engagement history is deepest.

  • HIPAA control tracking against live configuration
  • Data flow mapping across clinical and analytics estates
  • Cloud governance guardrails for regulated workloads
  • Audit readiness for HIPAA and HITRUST
For Healthcare securityComplianceClinical platform teams
Tell us this is the one you need →

VendorTrust

Third-Party Risk
Roadmap

Security questionnaires, vendor assessments, third-party risk and a hosted trust center.

Every organization is now on both sides of the vendor questionnaire — sending them and answering them. VendorTrust is intended to serve both directions from one record, so the answers you publish and the answers you demand stay consistent.

  • Questionnaire issuance and response tracking
  • Vendor assessment with reassessment cadence
  • Third-party risk register
  • Hosted trust center for inbound diligence
For SecurityProcurementGRC
Tell us this is the one you need →
How they fit together

Different questions.
The same estate.

These are not seven unrelated products that share a logo. Each asks a different question of the same underlying facts — who holds what access, what it reaches, what it costs, and whether any of it is defensible to an auditor.

That is why AuditGraph is first. The identity graph is the substrate: RoleIQ optimizes the authorization model on top of it, ComplianceIQ evidences it, GovernanceHub records the decisions that shaped it. Building the substrate first is the only sequencing that avoids four products each rediscovering the estate.

Substrate AuditGraph — the identity graph and what it reaches
Optimize RoleIQ — the authorization model on top of it
Evidence ComplianceIQ · HealthCloud Compass — proving it to a framework
Govern GovernanceHub — the decisions and exceptions behind it
Account CostLens · VendorTrust — what it costs and who else touches it
A line we deliberately did not cross

AI identity is not a separate product.

An AI agent authenticates, holds role assignments and reaches data — which makes it a non-human identity. AuditGraph treats it as one: a subtype rather than a separate species, so it inherits every engine that already exists for service principals and managed identities.

Launching a standalone AI identity product would be the easier pitch in 2026. It would also mean duplicating reach, lifecycle and governance, then reconciling two answers about the same estate. We would rather ship one graph that is right than two that disagree.

Get started

Start with the one that exists.

AuditGraph is live, has a free tier with no time limit, and needs read-only access to a single subscription to tell you something you did not already know.