Platform · Security assurance
Security assurance platform
Continuous assessment of what an organization exposes, tested the way an adversary would test it, with every finding backed by evidence, ranked by the risk it poses to the business, and carried through to a specific fix and to the evidence that controls are working.
The premise
Proof, not noise.
A scanner with a dashboard produces lists. What an organization needs is to know what is actually wrong, how much it matters to the business, and what to do about it, in that order. Every finding here carries its evidence, every fix is specific, and every compliance check points to the control it supports.
Tested as it would be attacked
The attack surface is discovered and tested with the same kinds of techniques a capable adversary would use, within an agreed scope, so the results describe real exposure rather than theoretical exposure.
Ranked by what matters
Two findings of the same technical severity are not equal when one sits in an experiment and the other in a system that holds customer data or moves money.
Evidence for every claim
No vague warnings. Each finding states what is wrong, where, how it was established and how to fix it.
Assessment
The surface mapped, tested and kept current.
A living inventory of the surface
Every known point of exposure, from access control and interfaces to secrets, supply chain, infrastructure, privacy and payment integrations, classified by risk, mapped to the checks that cover it and tracked as monitored, unmonitored, remediated or accepted. New services register their surface as they deploy, so the gaps are visible.
Established tooling, integrated properly
The analysis tools professional testers rely on, for code, dependencies, containers, networks and known weaknesses, with every result parsed into the same structured finding rather than passed through as raw output.
Checks of our own
Exposed credentials in code and its history, access control and sandbox boundaries, configuration and service exposure, dependencies checked against advisories of compromised packages, and the integrity of audit logs.
One findings record
Every finding, whatever produced it, has a severity, evidence, a location and a remediation, in one record where findings from different sources can be correlated.
Risk
Fix first what an adversary would use first.
Asset criticality
Where the affected component sits, from an experimental sandbox through internal tooling and revenue systems to customer-facing systems and the assets the business cannot lose.
Exposure
Whether the weakness is reachable only from inside or from the public internet.
Exploit maturity
From a theoretical weakness to a published proof of concept, a working exploit and active use in the wild, with known vulnerabilities scored by the published probability that they will be exploited soon, not only by their theoretical severity.
Business impact
Exposure of revenue and customer data, and the regulatory consequences that follow.
Cost to fix
A configuration change and an architectural change are weighed differently when deciding what comes first.
One composite score
The dimensions combine into a single ranking of what to fix first against the organization's actual threat landscape, not an alphabetical list of identifiers.
Triage
The layer between findings and fixes.
Chains no single check sees
Findings are read together, with their evidence, location and the criticality of what they affect, to find combinations of minor weaknesses that add up to a serious one.
An ordered plan
Remediation is sequenced with its dependencies in mind, so that fixing one problem does not open another, and the most consequential path is closed first.
Impact in business terms
Each priority is explained by what it puts at risk, not only by a severity number.
Guidance for the actual system
Remediation is written for the specific component and the way it is deployed, ready to act on.
Foundations
Hardening the parts everything else relies on.
One authentication library
A single source of truth for sessions, passwords and keys across every service: memory-hard password hashing, signing keys that rotate with a grace period for tokens in flight, verified keys rather than random strings, and hardware security keys for passwordless sign-in.
Code that proves it is unaltered
Source files are signed at the level of their syntax, so tampering is detected even when the change is made to look harmless.
Service to service, mutually verified
An internal certificate authority issues identities to services, which verify each other on every connection, with role-based access enforced by cryptographically verified tokens.
A guarded supply chain
Every package is checked against advisories of known-malicious releases before it is installed and verified against pinned content hashes afterwards, while the health of upstream registries is watched continuously.
Monitoring
Exact evidence of what changed, where and when.
Sensitive files watched
Changes to configuration, credentials, security-critical code and model checkpoints are detected as they happen.
Logs that cannot be quietly edited
Audit logs are checked for truncation, deletion and tampering.
Early signs of intrusion
Changes to permissions on sensitive files and sudden rises in refused access, an early sign of credential stuffing or attempts to escalate privilege.
Re-tested on a schedule
Assessments repeat automatically, and every alert arrives in the same structured form as a finding: severity, evidence, location and remediation.
Compliance evidence
Evidence mapped to controls, not a questionnaire.
Findings are mapped to the control identifiers of the major frameworks for security and availability, for the privacy of children's data, and for payment card data. Each control is assessed against what the scans actually found. Formal attestation remains the role of an independent licensed auditor; what this produces is the evidence an auditor asks for.
Assessed, not asserted
Each control is marked as passing, failing or partial on the strength of real findings, with the evidence attached and the findings linked.
Gaps with their remedies
Every failing or partial control comes with the remediation that would close it.
Packages for the auditor
Evidence is assembled control by control into a package an auditor can review directly.
Continuous, not annual
Because the evidence comes from continuous assessment, it describes the state of the controls now, not on the day of the last review.
Services
Three ways to engage.
Testing is carried out only on systems the client owns or is authorized to test, under a written scope agreed before any work begins.
Penetration testing
An end-to-end assessment of the agreed scope, delivered as an executive summary, detailed findings with evidence, a prioritized remediation plan and a verification re-test after the fixes.
Continuous monitoring
Ongoing automated assessment with prompt alerting, a daily posture score, trend reporting and tracking of every remediation to closure.
Compliance readiness
Automated evidence collection and gap analysis against the frameworks that apply, prepared for review by the client's auditor.
Connections
The same ideas, elsewhere in our work.
Agent runtime & orchestration
The same zero-trust stance applied to software agents: nothing inherits permission, every refusal is recorded, and the record shows it if anyone tries to change it.
Trading & research platform
Systems that move money sit at the top of any ranking of what an organization cannot lose, and are assessed and watched accordingly.
Accounting & tax system
Every finding carries its evidence the way every figure in a ledger traces to its source document. A claim without its evidence is not accepted in either.
Robotics & learning lab
A learning lab used by children is held to the rules that protect children's data, and the same controls that are checked for clients are checked there.
Engage
By engagement.
Every engagement begins with a conversation and is scoped before work begins.
Assessment
A penetration test of an agreed scope, with evidence, a ranked plan and a re-test.
Subject: AuditMonitoring
Continuous assessment, alerting and posture reporting.
Subject: AccessPartnerships
Firms and platforms that serve many organizations.
Subject: PartnershipInvestment
Briefings and a demonstration, under confidentiality.
Subject: Fundingcontact@carbonyl.org