Your network diagram is a Visio from two years agoYour PCI scope is an argument nobody can settle

Builds the topology from a live read-only snapshot, infers what is really connected from security groups and peering, and classifies every resource for assessment scope, so the diagram and the scope are the same source of truth.

Try it

Interactive demo with a live topology, PCI scoping and asset inventory, no signup

How It Works

Snapshot, infer, classify, curate.

01

Snapshot

A read-only collection reads every VPC, subnet, gateway, load balancer, database, compute node and route table, no agents, nothing written back.

02

Infer

Connectivity is derived from the evidence, security-group references, subnet placement, route tables and peering, not from names. Inferred edges are drawn distinct from observed ones.

03

Classify

Every resource is classified for PCI-DSS scope, CDE, connected-to, security-impacting or out-of-scope, from that graph, with the reasoning attached to each node.

04

Curate

The same snapshot becomes an asset inventory enriched with end-of-life dates and a cross-account view, so a topology, a scope and a lifecycle report all come from one collection.

What You Can Do

Everything the curator does.

A topology built from what runs

Nested region, VPC, availability zone, subnet and resource, drawn from a live read-only snapshot, not a hand-maintained diagram that drifts the moment it is saved.

See it in the demo

Connectivity inferred from evidence

Security-group references, route tables, gateway endpoints and peering are read to work out what is actually connected. Inferred paths are dashed and labelled, distinct from observed load-balancer and database traffic.

See it in the demo

PCI scope decided from the graph

Each resource is classified CDE, connected-to, security-impacting or out-of-scope using a QSA rubric over the real segmentation, so scope is defensible, not a spreadsheet someone filled in by hand.

See it in the demo

Every classification carries its reason

Click a node and read why it is in scope, payment-api transmits PAN; the analytics database has no path to the CDE and is genuinely isolated. The reasoning is the deliverable, not just the colour.

See it in the demo

An inventory that knows what is dying

The same snapshot is enriched with end-of-life and end-of-support dates across operating systems, databases and runtimes, flagged Active, EOL-approaching, End-of-support or End-of-life.

See it in the demo

EOL that is also a compliance finding

A Windows Server 2012 R2 host that reaches the cardholder database sits past end of life inside PCI scope, one asset that is both a network fact and an audit finding, surfaced in both views.

See it in the demo

Cross-account connectivity

Peering and transit paths between accounts are drawn with the NACL rule count on each hop, so a permissive or uncollected peer stands out as an unproven boundary.

See it in the demo

Search, filter and export

Filter the inventory by type or lifecycle status, search across the estate, scope-filter the diagram, and export the topology and inventory as JSON and CSV for the assessment file.

See it in the demo

Read-only, customer-scoped, agentless

Collection uses a customer-scoped read-only role with no persisted credentials and no default-chain fallback. Empty accounts render an empty state rather than a broken diagram.

See it in the demo

Business Outcomes

What it changes.

Current

The diagram is a snapshot of what is running now, so it never drifts from reality the way a maintained-by-hand one does.

Defensible

Scope is derived from segmentation evidence with the reasoning attached, so it survives a QSA asking why a resource is in or out.

One collection

A topology, a PCI scope, an asset inventory and a cross-account view all come from a single read-only snapshot.

One snapshot, one source of truth.

Point it at a read-only role and get a live topology, a defensible PCI scope and an end-of-life inventory in minutes.