Proof over time
A security posture you can hand to a skeptic.
Not a dashboard that asks to be believed. A row of dated, signed proofs — each one re-checkable by the person you give it to, without trusting us.
Upload your configuration files. The engine reads what is actually there, finds the attack paths those configs open, and when a path to a crown jewel is cut, it says so in a signed, point-in-time artifact anyone can re-verify offline. Auditors, insurers, boards: they re-run the check, they do not take the word.
The sample is the full engine on a fictional company. No card, no signup, nothing touches your environment.
Show 12 more paths
How a proof is born
- 01You upload an artifact. A firewall export, an identity configuration, a cloud posture file. No agent, no scanner, nothing touches your live environment. What we read is labeled PROVEN because it was parsed from the file itself; what we infer from your answers is labeled MODELED and never dressed as more.
- 02The engine maps the paths. From exposed edge to crown jewel, across the configs on file. The cheapest set of changes that severs the most paths — the min-cut — is priced and ranked.
- 03You fix, you re-upload, the claim is re-tested. A finding closes when the next artifact proves the path is gone, not when someone marks a ticket done.
- 04The proof is frozen. Dated, signed, scoped to the exact surface you uploaded, and packaged with the evidence chain — so the person holding it can re-run the verification in their browser and get the same answer.
What each proof states — and refuses to state
A CyberTwin proof is deliberately narrow, because narrow is what survives cross-examination. It states: as of this date, over these uploaded artifacts, no modeled route was found from the exposed edge to this asset. It does not claim to watch your network. It does not claim tomorrow. It is a point-in-time record, and it says so on its face — that honesty is the reason a counterparty can accept it.
Where a path to the asset still exists, the engine refuses to certify. A proof you can fail is the only kind worth passing.
Why a row of them beats any dashboard
One proof answers one date. A sequence of them answers the question boards and insurers actually ask: is this posture managed, or lucky? Quarter after quarter, each artifact lands beside the last — same scope, same method, same signature chain — and the row itself becomes the evidence that your security program closes what it finds.
Watch it produce a proof — right now, on us
The sample company is the whole engine running on a fictional fintech: the attack paths, the min-cut, the dollar figures (MODELED, sourced, and labeled), and the signed proof at the end. Re-check the artifact yourself when it is done.
PROVEN means parsed from an artifact you uploaded. MODELED means inferred from your answers and industry data, labeled as such on every figure. Every proof is point-in-time; the date is part of the claim, never fine print.