Proof over time

A security posture you can hand to a skeptic.

Not a dashboard that asks to be believed. A row of dated, signed proofs — each one re-checkable by the person you give it to, without trusting us.

Upload your configuration files. The engine reads what is actually there, finds the attack paths those configs open, and when a path to a crown jewel is cut, it says so in a signed, point-in-time artifact anyone can re-verify offline. Auditors, insurers, boards: they re-run the check, they do not take the word.

The sample is the full engine on a fictional company. No card, no signup, nothing touches your environment.

Modeled
up to $5.0M
modeled
Phishing victim (Marketing user)Entra group: CloudOps (admin)MDE: Ops Admin laptopsFortiGate zone: vpn-poolFortiGate zone: prod-paymentsAWS IAM user: cloudops-admin◆ Secrets Manager: stripe-live-keys
6 hops to Secrets Manager: stripe-live-keys · ~47m to data
Cheapest cut: CloudOps excluded from CA admin policy
Modeled
up to $5.0M
modeled
Phishing victim (Marketing user)Entra group: MarketingMDE: Corp Laptops device groupFortiGate zone: internal-corpFortiGate zone: prod-paymentsAWS IAM role: PowerUserRole (overprovisioned)◆ S3 bucket: acme-customer-pii
6 hops to S3 bucket: acme-customer-pii · ~1h to data
Cheapest cut: MFA not enforced for Marketing group
Modeled
up to $5.0M
modeled
Exposed SSL-VPN portal (no MFA)FortiGate zone: internal-corpFortiGate zone: prod-paymentsAWS IAM role: PowerUserRole (overprovisioned)◆ RDS: prod-payments-db
4 hops to RDS: prod-payments-db · ~28m to data
Cheapest cut: SSL-VPN MFA not required
Show 12 more paths
Modeled
up to $5.0M
modeled
Legacy auth not blocked (IMAP / POP)Entra group: MarketingMDE: Corp Laptops device groupFortiGate zone: internal-corpFortiGate zone: prod-paymentsAWS IAM role: PowerUserRole (overprovisioned)◆ S3 bucket: acme-customer-pii
6 hops to S3 bucket: acme-customer-pii · ~1h to data
Cheapest cut: Legacy auth not blocked tenant-wide
Modeled
up to $5.0M
modeled
Phishing victim (Marketing user)Entra group: CloudOps (admin)MDE: Ops Admin laptopsFortiGate zone: internal-corpFortiGate zone: prod-paymentsAWS IAM user: cloudops-admin◆ Secrets Manager: stripe-live-keys
6 hops to Secrets Manager: stripe-live-keys · ~53m to data
Cheapest cut: cloudops-admin user lacks MFA on console
Modeled
up to $4.5M
modeled
Internet (Cloudflare-fronted prod app)Cloudflare WAF for app.acme.io (custom skip rule for legacy partner)◆ Origin: app.acme.io (production payments API)
2 hops to Origin: app.acme.io (production payments API) · ~22m to data
Cheapest cut: Cloudflare custom rule with action=skip on managed ruleset
Modeled
up to $2.8M
modeled
Internet (post-drift exposure)◆ S3 reporting-snapshots (drift: s3-bucket-public-read-prohibited NON_COMPLIANT)
1 hop to S3 reporting-snapshots (drift: s3-bucket-public-read-prohibited NON_COMPLIANT) · ~18m to data
Cheapest cut: S3 bucket reporting-snapshots: public-read-prohibited NON_COMPLIANT
Modeled
up to $6.0M
modeled
Okta user: eng-lead@acme (Super Admin)Okta Super Admin roleEntra group: CloudOps (admin)MDE: Ops Admin laptopsFortiGate zone: vpn-poolFortiGate zone: prod-paymentsAWS IAM user: cloudops-admin◆ Secrets Manager: stripe-live-keys
7 hops to Secrets Manager: stripe-live-keys · ~51m to data
Cheapest cut: Standing SUPER_ADMIN assignment without JIT
Modeled
up to $2.5M
modeled
Phishing victim (Marketing user)Entra group: CloudOps (admin)MDE: Ops Admin laptopsCrowdStrike Falcon: Engineering host group (200 hosts)◆ Falcon exclusion: rundll32 / appdata\Local\Temp\* permit
4 hops to Falcon exclusion: rundll32 / appdata\Local\Temp\* permit · ~35m to data
Cheapest cut: Falcon exclusion list contains rundll32 + temp paths
Modeled
up to $5.0M
modeled
Branch office Cisco ASA outside interface (sec-level 0)Branch office LAN (sec-level 100)FortiGate zone: internal-corpFortiGate zone: prod-paymentsAWS IAM role: PowerUserRole (overprovisioned)◆ S3 bucket: acme-customer-pii
5 hops to S3 bucket: acme-customer-pii · ~41m to data
Cheapest cut: Cisco ASA shadowed deny rule on branch-outside-in
Modeled
up to $1.8M
modeled
Phishing victim (Marketing user)Entra group: CloudOps (admin)Compromised mailbox (CFO auto-forward to personal)◆ External recipient — exfil destination
3 hops to External recipient — exfil destination · ~24m to data
Cheapest cut: External auto-forwarding allowed org-wide
Modeled
up to $7.5M
modeled
Phishing victim (Marketing user)Entra group: CloudOps (admin)MDE: Ops Admin laptopsFortiGate zone: internal-corpFortiGate zone: prod-paymentsAWS IAM user: cloudops-adminGCP SA: analytics-runner (proj-data)◆ GCP project "proj-prod-payments" admin scope (1 admin SA)
7 hops to GCP project "proj-prod-payments" admin scope (1 admin SA) · ~58m to data
Cheapest cut: Cross-project TokenCreator from analytics → prod
Modeled
up to $6.5M
modeled
Phishing victim (Marketing user)Entra group: CloudOps (admin)MDE: Ops Admin laptopsFortiGate zone: internal-corpFortiGate zone: prod-paymentsAWS IAM user: cloudops-adminAzure SP: deploy-bot◆ Azure subscription m365-ecosystem (Owner inherits to all RGs)
7 hops to Azure subscription m365-ecosystem (Owner inherits to all RGs) · ~56m to data
Cheapest cut: Standing Owner assignment at subscription scope (no JIT)
Modeled
up to $3.0M
modeled
Phishing victim (Marketing user)Entra group: CloudOps (admin)Adversary using stolen valid creds (Sentinel-prod blind to)◆ Undetected: Valid Accounts: Cloud Accounts (T1078.004)
3 hops to Undetected: Valid Accounts: Cloud Accounts (T1078.004) · ~31m to data
Cheapest cut: Coverage gap: T1078.004 has no enabled detection rule
Modeled
up to $6.5M
modeled
Okta IDP (from network diagram)Okta user: eng-lead@acme (Super Admin)Okta Super Admin roleEntra group: CloudOps (admin)MDE: Ops Admin laptopsFortiGate zone: internal-corpFortiGate zone: prod-paymentsAWS IAM user: cloudops-admin◆ Secrets Manager: stripe-live-keys
8 hops to Secrets Manager: stripe-live-keys · ~1h to data
Cheapest cut: Standing SUPER_ADMIN assignment without JIT
Best single fix
Remediating entra-ca-exclude-001 breaks 9 of the 28 paths enumerated — the board draws the top 15.
generated 2026-08-21 · sample fixture · modeled — your run reads your configs instead

How a proof is born

  1. 01You upload an artifact. A firewall export, an identity configuration, a cloud posture file. No agent, no scanner, nothing touches your live environment. What we read is labeled PROVEN because it was parsed from the file itself; what we infer from your answers is labeled MODELED and never dressed as more.
  2. 02The engine maps the paths. From exposed edge to crown jewel, across the configs on file. The cheapest set of changes that severs the most paths — the min-cut — is priced and ranked.
  3. 03You fix, you re-upload, the claim is re-tested. A finding closes when the next artifact proves the path is gone, not when someone marks a ticket done.
  4. 04The proof is frozen. Dated, signed, scoped to the exact surface you uploaded, and packaged with the evidence chain — so the person holding it can re-run the verification in their browser and get the same answer.

What each proof states — and refuses to state

A CyberTwin proof is deliberately narrow, because narrow is what survives cross-examination. It states: as of this date, over these uploaded artifacts, no modeled route was found from the exposed edge to this asset. It does not claim to watch your network. It does not claim tomorrow. It is a point-in-time record, and it says so on its face — that honesty is the reason a counterparty can accept it.

Where a path to the asset still exists, the engine refuses to certify. A proof you can fail is the only kind worth passing.

Why a row of them beats any dashboard

One proof answers one date. A sequence of them answers the question boards and insurers actually ask: is this posture managed, or lucky? Quarter after quarter, each artifact lands beside the last — same scope, same method, same signature chain — and the row itself becomes the evidence that your security program closes what it finds.

Watch it produce a proof — right now, on us

The sample company is the whole engine running on a fictional fintech: the attack paths, the min-cut, the dollar figures (MODELED, sourced, and labeled), and the signed proof at the end. Re-check the artifact yourself when it is done.

PROVEN means parsed from an artifact you uploaded. MODELED means inferred from your answers and industry data, labeled as such on every figure. Every proof is point-in-time; the date is part of the claim, never fine print.