How it works
From cloud to remediation in five steps
Tricognita is a security control plane, not a runtime agent. You grant read-only IAM access; we do the rest.
Connect your cloud accounts
You apply a CloudFormation template (provided) that creates a cross-account IAM role with the read-only permissions Tricognita needs. We assume that role via AWS STS — no long-lived credentials cross the boundary.
Equivalent flows exist for Azure (OIDC federation) and GCP (workload identity federation).
We scan your environment
Tricognita scans your cloud inventory against the CIS Benchmarks, AWS Well-Architected, NIST CSF, and a curated set of attack-relevant misconfigurations. Initial scans typically complete in 5–15 minutes; ongoing scans are scheduled or triggered manually.
Findings populate your dashboard progressively as the scan runs. You don't wait for completion to start triaging.
See findings in context
Findings appear with severity, affected resource, and the evidence behind the verdict. The attack graph shows how individual findings chain into reachable attack paths — a public S3 bucket alone is concerning; the same bucket reachable through a Lambda with admin IAM is an incident.
The SOC and queue views surface what to triage next, sorted by priority across incidents and high-severity findings.
Approve remediation
ARIA (our AI-assisted remediation engine) proposes a fix for each finding: the action, the target resource, the predicted impact, and the rollback plan. The approver — typically you — reviews and either approves, modifies, or rejects.
By default, no action runs without human approval. The autonomous mode exists for narrow well-understood patterns and is opt-in per tenant. Most pilots run in manual-approval mode for their entire engagement.
Report and improve
The executive dashboard gives a CISO-level read of posture trend, active incidents, and remediation throughput. Exports cover compliance evidence (PDF, CSV, SOC 2 evidence pack) and SIEM ingest (NDJSON).
Webhook subscriptions push the same event stream to your Slack, SIEM, ticketing system, or custom infrastructure.
What this means operationally
- Day 1: Connect one cloud account. See your real posture within the hour.
- Week 1: Triage the first wave of critical and high findings. Run your first remediation approvals.
- Month 1: Integrate with Slack and your SIEM. Schedule weekly scans. Run your first executive review.
- Month 3: Posture score trending up. Most critical findings either remediated or consciously accepted with documented exception.