Manifesto

Know what’s actually running.

Four beliefs the product is built on, including the ones that cost us something to hold.

Terraform tells you what should exist. Not what does.

Your state file records an intention, frozen at the last apply. Your cloud account records what is actually there this morning. Nothing keeps those two equal, and nothing announces the moment they stop being equal.

They come apart in ordinary ways. A security group opened by hand during an outage and never merged back. A controller from another tool editing the same resource. A permission granted in a console because the pull request would have taken two days. None of it is malicious and none of it shows up in a plan you did not run.

So we read both and compare them field by field, on a schedule you set. Scans are point-in-time by design: we tell you what differed when we looked, and when we looked. Not a live feed, and we will not describe it as one.

A tool you won’t mute in week two

Noise is how drift tools die. Not inaccuracy: noise. A tool that reports two hundred differences on day one gets a Slack channel, then a mute, then a calendar reminder nobody honours.

So every finding has to earn the interruption. Differences that are the cloud defaulting a field you never set are not drift. A finding that you have judged and dismissed stays dismissed, and says who dismissed it and when. If the same drift returns after being resolved, it reopens rather than arriving as something new.

Ownership is assigned by a person, not inferred. We would rather show a finding with no owner than guess wrong and route it to someone who cannot act on it.

Your keys never leave your cluster

You install this with helm install into a cluster you run. Your cloud credentials are entered once, encrypted, and stay in your database. Findings stay in your database. There is no account to create and no vendor tenant your data lives in, because there is no vendor tenant.

Access is read-only. Remediation ships as a pull request against your repository: reviewed by your engineers, merged on your schedule, never applied by us. Nothing phones home: no telemetry, no analytics, no licence server, no endpoint we operate. It runs air-gapped.

Three paths do send data outward, and they only exist because you configure them: notification webhooks, and the GitHub and GitLab integrations that open remediation pull requests. Those carry finding data to destinations you choose. We will not tell you nothing leaves your environment, because that would not be true.

Honesty is a feature

There are three different things a vendor can mean by "we cover this", and most of the industry lets them blur together. We keep them apart.

Some resource types have had drift injected into a live cloud account and detected, field by field. A much larger set passes golden-fixture tests against recorded payloads (real verification, but of the engine, not of a live cloud). A third set we can only enumerate: we will tell you the resource exists and nothing more.

Which types sit in which tier is published, and generated from the engine itself at build time rather than typed into a slide. When those numbers move, the page moves with them. When they do not move, we do not round up.

We are pre-launch. No customers yet, no SOC 2, and a coverage list with visible edges. Everything above is what we will be measured against once there are people to do the measuring.

Install in 15 minutes