Skip to main content

How it works

From cloud to remediation in five steps

Tricognita is a security control plane, not a runtime agent. You grant read-only IAM access; we do the rest.

1

Connect your cloud accounts

You apply a CloudFormation template (provided) that creates a cross-account IAM role with the read-only permissions Tricognita needs. We assume that role via AWS STS — no long-lived credentials cross the boundary.

Equivalent flows exist for Azure (OIDC federation) and GCP (workload identity federation).

2

We scan your environment

Tricognita scans your cloud inventory against the CIS Benchmarks, AWS Well-Architected, NIST CSF, and a curated set of attack-relevant misconfigurations. Initial scans typically complete in 5–15 minutes; ongoing scans are scheduled or triggered manually.

Findings populate your dashboard progressively as the scan runs. You don't wait for completion to start triaging.

3

See findings in context

Findings appear with severity, affected resource, and the evidence behind the verdict. The attack graph shows how individual findings chain into reachable attack paths — a public S3 bucket alone is concerning; the same bucket reachable through a Lambda with admin IAM is an incident.

The SOC and queue views surface what to triage next, sorted by priority across incidents and high-severity findings.

4

Approve remediation

ARIA (our AI-assisted remediation engine) proposes a fix for each finding: the action, the target resource, the predicted impact, and the rollback plan. The approver — typically you — reviews and either approves, modifies, or rejects.

By default, no action runs without human approval. The autonomous mode exists for narrow well-understood patterns and is opt-in per tenant. Most pilots run in manual-approval mode for their entire engagement.

5

Report and improve

The executive dashboard gives a CISO-level read of posture trend, active incidents, and remediation throughput. Exports cover compliance evidence (PDF, CSV, SOC 2 evidence pack) and SIEM ingest (NDJSON).

Webhook subscriptions push the same event stream to your Slack, SIEM, ticketing system, or custom infrastructure.

What this means operationally

  • Day 1: Connect one cloud account. See your real posture within the hour.
  • Week 1: Triage the first wave of critical and high findings. Run your first remediation approvals.
  • Month 1: Integrate with Slack and your SIEM. Schedule weekly scans. Run your first executive review.
  • Month 3: Posture score trending up. Most critical findings either remediated or consciously accepted with documented exception.