NHI risk assessment
Discover your NHI risk — with evidence you keep.
A scoped, read-only connector to one account or tenant. An inventory of the non-human identities and agent tools living there, the ownership gaps, the credentials that should worry you — and a report that belongs to you whatever you decide next.
What the assessment covers
- A scoped, read-only connectorAvailableOne account, tenant or organisation you choose, with credentials you issue and can revoke
- Inventory of non-human identities and toolsAvailableIAM roles and machine users, service accounts, workloads, GitHub Apps, Vault AppRoles and MCP tools — classified and counted
- Ownership gapsAvailableIdentities with no owner, and owner tags that resolve to nobody in your organisation
- Overdue, expiring and exposed credentialsAvailableRotation, expiry and sharing, plus exposures reported through the ingestion API — linked to the identities they unlock
- Effective access highlightsAvailableAn upper bound of what the riskiest identities can reach, across accounts and environments
- An evidence-backed report you keepAvailableSeverity, rationale, evidence and a recommended action on every finding — yours whatever you decide next
Coverage depends on the connector: last use is reported only by AWS, for roles and access keys, and no connector discovers an agent. Where evidence is missing the report says unknown — never a guess.
Who it is for
- Security leaders who need a baseline before budgeting an NHI or agent-security program
- IAM teams extending joiner-mover-leaver to service accounts, keys and integrations
- Platform and AI teams about to roll out agents, copilots or MCP servers at scale
What we need from you
- A sponsor who owns the outcome
- Read-only credentials to one account, tenant or organisation
- Thirty minutes to agree scope with a security engineer
- A contact who can answer ownership questions
Prefer email? hello@trustivan.com · Questions about data handling: see Security & Trust
How it works
From scope to evidence in four steps
Read-only throughout. No agents to deploy, nothing modified in your environment, and a report you keep regardless of what happens next.
Scope
Agree the account or tenant, the read-only role and who owns the result — thirty minutes with a security engineer.
Connect
The scoped connector inventories identities, credential metadata, permissions and MCP tools. Nothing is modified.
Review
Walk through the findings together — with the evidence, the blast radius and a recommendation on each one.
Keep
The report is yours. Continue as a design partner, book a demo, or take the findings to your own tooling.