NHI risk assessment

Discover your NHI risk — with evidence you keep.

A scoped, read-only connector to one account or tenant. An inventory of the non-human identities and agent tools living there, the ownership gaps, the credentials that should worry you — and a report that belongs to you whatever you decide next.

What the assessment covers

  • A scoped, read-only connectorAvailableOne account, tenant or organisation you choose, with credentials you issue and can revoke
  • Inventory of non-human identities and toolsAvailableIAM roles and machine users, service accounts, workloads, GitHub Apps, Vault AppRoles and MCP tools — classified and counted
  • Ownership gapsAvailableIdentities with no owner, and owner tags that resolve to nobody in your organisation
  • Overdue, expiring and exposed credentialsAvailableRotation, expiry and sharing, plus exposures reported through the ingestion API — linked to the identities they unlock
  • Effective access highlightsAvailableAn upper bound of what the riskiest identities can reach, across accounts and environments
  • An evidence-backed report you keepAvailableSeverity, rationale, evidence and a recommended action on every finding — yours whatever you decide next

Coverage depends on the connector: last use is reported only by AWS, for roles and access keys, and no connector discovers an agent. Where evidence is missing the report says unknown — never a guess.

Who it is for

  • Security leaders who need a baseline before budgeting an NHI or agent-security program
  • IAM teams extending joiner-mover-leaver to service accounts, keys and integrations
  • Platform and AI teams about to roll out agents, copilots or MCP servers at scale

What we need from you

  • A sponsor who owns the outcome
  • Read-only credentials to one account, tenant or organisation
  • Thirty minutes to agree scope with a security engineer
  • A contact who can answer ownership questions

Prefer email? hello@trustivan.com · Questions about data handling: see Security & Trust

Submitting opens your email client with the details pre-filled.

How it works

From scope to evidence in four steps

Read-only throughout. No agents to deploy, nothing modified in your environment, and a report you keep regardless of what happens next.

  1. Scope

    Agree the account or tenant, the read-only role and who owns the result — thirty minutes with a security engineer.

  2. Connect

    The scoped connector inventories identities, credential metadata, permissions and MCP tools. Nothing is modified.

  3. Review

    Walk through the findings together — with the evidence, the blast radius and a recommendation on each one.

  4. Keep

    The report is yours. Continue as a design partner, book a demo, or take the findings to your own tooling.