A topology built from what runs
Nested region, VPC, availability zone, subnet and resource, drawn from a live read-only snapshot, not a hand-maintained diagram that drifts the moment it is saved.
See it in the demoBuilds the topology from a live read-only snapshot, infers what is really connected from security groups and peering, and classifies every resource for assessment scope, so the diagram and the scope are the same source of truth.
Interactive demo with a live topology, PCI scoping and asset inventory, no signup
01
A read-only collection reads every VPC, subnet, gateway, load balancer, database, compute node and route table, no agents, nothing written back.
02
Connectivity is derived from the evidence, security-group references, subnet placement, route tables and peering, not from names. Inferred edges are drawn distinct from observed ones.
03
Every resource is classified for PCI-DSS scope, CDE, connected-to, security-impacting or out-of-scope, from that graph, with the reasoning attached to each node.
04
The same snapshot becomes an asset inventory enriched with end-of-life dates and a cross-account view, so a topology, a scope and a lifecycle report all come from one collection.
What You Can Do
Nested region, VPC, availability zone, subnet and resource, drawn from a live read-only snapshot, not a hand-maintained diagram that drifts the moment it is saved.
See it in the demoSecurity-group references, route tables, gateway endpoints and peering are read to work out what is actually connected. Inferred paths are dashed and labelled, distinct from observed load-balancer and database traffic.
See it in the demoEach resource is classified CDE, connected-to, security-impacting or out-of-scope using a QSA rubric over the real segmentation, so scope is defensible, not a spreadsheet someone filled in by hand.
See it in the demoClick a node and read why it is in scope, payment-api transmits PAN; the analytics database has no path to the CDE and is genuinely isolated. The reasoning is the deliverable, not just the colour.
See it in the demoThe same snapshot is enriched with end-of-life and end-of-support dates across operating systems, databases and runtimes, flagged Active, EOL-approaching, End-of-support or End-of-life.
See it in the demoA Windows Server 2012 R2 host that reaches the cardholder database sits past end of life inside PCI scope, one asset that is both a network fact and an audit finding, surfaced in both views.
See it in the demoPeering and transit paths between accounts are drawn with the NACL rule count on each hop, so a permissive or uncollected peer stands out as an unproven boundary.
See it in the demoFilter the inventory by type or lifecycle status, search across the estate, scope-filter the diagram, and export the topology and inventory as JSON and CSV for the assessment file.
See it in the demoCollection uses a customer-scoped read-only role with no persisted credentials and no default-chain fallback. Empty accounts render an empty state rather than a broken diagram.
See it in the demoBusiness Outcomes
Current
The diagram is a snapshot of what is running now, so it never drifts from reality the way a maintained-by-hand one does.
Defensible
Scope is derived from segmentation evidence with the reasoning attached, so it survives a QSA asking why a resource is in or out.
One collection
A topology, a PCI scope, an asset inventory and a cross-account view all come from a single read-only snapshot.
Point it at a read-only role and get a live topology, a defensible PCI scope and an end-of-life inventory in minutes.