Solutions
One graph. Different obligations.
Cloud attack-path analysis and web and API pentesting. What changes is the data you have to protect.
What Trident tests
Who runs it
Your first enterprise deal wants a pentest
Findings arrive as pull requests.
Public webhook routeInstance metadataProduction bucket
Nobody can draw the estate anymore
One graph across every account.
Sandbox CI roleCross-account AssumeRoleAnalytics warehouse
Tenant #2 shouldn’t cost analyst #2
Per-client rollups, one queue.
Public searchShared tenant grantOrder history
SOC 2 programs
Technical evidence a reviewer can trace back to a control.
Verified findingControl mappedEvidence on file
Where the data is regulated
Prove a transfer can’t move someone else’s money
Prove a transfer can’t move money.
Merchant tokenTransfers endpointFunding accounts
The examiner’s evidence list arrived
Evidence an examiner can file.
Analyst sessionOne role, both stepsWire ledger
PHI sits four hops from your portal
The path to PHI, severed.
Patient portalPeered data subnetPatient records
Your auditor asked for a technical evaluation
§164.312, tested with evidence.
Clinic networkCleartext feedePHI on the wire
Not sure which one you are?
Cloud accounts and an app in front
Start with cloud paths and web testing
Still comparing approaches
Read the field guides