tour

what it looks like before you connect anything.

Four screens from a workspace with three clouds and seventeen accounts in it. Nothing here is real — the accounts are unissuable, the domain is reserved, the resources are generated — but the product is, and this is what it does with a scan.

01 · the list you land on

Everything found in every connected account, in one table. Narrow it by cloud, by account, by region, by service, by type, or by what nobody has tagged — or search for a name you only half remember. The counts down the side are the answer to "how much of this is there", which is usually the first question and rarely one a console will answer.

a resource list showing 6,227 resources across 17 accounts, with aws, azure, and google cloud types in the same table
one list, every account, all three clouds. The by-type column puts an aws snapshot, an azure disk and a google cloud disk in the same frame.

02 · one thing, opened

A scan stores the resource rather than a headline about it: what it is, where it lives, when it was first seen and last confirmed, how it is tagged, and the provider's own attributes exactly as they came back. Every scan keeps its own version, so the record answers questions asked afterwards — what this allowed in june, when it first appeared, what changed since.

one resource opened, showing its name, type, provider, region and account, when it was discovered and last verified, its tags, and the provider's own attributes
what a scan keeps about a single resource. The attributes at the bottom are the provider's own, stored rather than summarized — and the history tab holds every version a scan has seen.

03 · what it reaches

From any resource, everything it can get to, grouped by how many steps away each thing is. The connections are worked out after the scan and each one is labeled — 11 kinds in all — so the picture says what the relationship is rather than that something is nearby. A link into an account you have not scanned still shows up, so a boundary never quietly disappears.

a diagram of everything one network security group reaches, spreading outward in rings, with resources from all three clouds on the same picture
everything one security group can reach. Each ring is one step further out — and a link into an account you haven't scanned still shows up.

04 · what changed

Service limits are recorded like everything else, which makes them the clearest case for keeping history at all: a ceiling only the provider can move is the one change nobody is notified about. The previous value is still on file, and that is the only reason anyone can tell it moved.

a service limit that cannot be raised on request, showing 80,000 write units superseded and 40,000 current
a limit only the provider can move, after the provider moved it. The previous value is still on file, which is the only reason anyone can tell.

that took one account and one scan.

A first scan takes about five minutes. 3 cloud accounts free, unlimited seats, no card — and what pro costs.