About

Vulnerability lifecycle and non-human identity, under one record

TRUSTIVAN started as a vulnerability lifecycle tool and grew a second half: governing the non-human and agentic identities that act on a company's behalf. Both halves answer the same question — is this decision recorded, and can it be checked?

Why one product

A finding and an identity need the same record

A vulnerability that resurfaces after a rescan and a credential nobody remembers granting are the same failure: a decision that was made and then forgotten. TRUSTIVAN's AppSec side tracks the first; NHI Security tracks the second. Neither is convincing without the other, so we build them together.

Principles

What every page and every finding has to keep

Evidence before claims

A finding ships with the source record attached, and a page states "unknown" rather than guess when the evidence is missing.

Deny by default

Access, scanners and policy verdicts start closed. Opening one is a decision somebody made, not a default nobody noticed.

Say what is missing

This site lists what TRUSTIVAN does not do — reachability analysis, PR scanning, mail delivery, SOC 2 — next to what it does, on the same pages.

One history, not two

AppSec and NHI Security are one product because a finding and an identity both need the same thing: a record that survives a rescan.

The team

A small engineering team

We do not publish headcount or funding figures we cannot keep current, and we would rather this page stay short than say something about the company that goes stale in a quarter.