Harden Your Entire Ecosystem

The unified platform for CSPM, ISPM, and SCM.
Automate audits against 20+ frameworks (CIS, NIST, ISO 27001, PCI DSS, MITRE ATT&CK and more) across your Multi-Cloud, Identity, and Network Data Sources.

Retrievy Mascot
Unified Security Posture

CSPM, ISPM
& SCM Platform.

One unified score across Cloud, Identity, and Network. X-Ray engines plus the Hardening Kanban to fix what's broken.

Multi-Cloud Posture Command Center SCAN-OK AUTH: ACTIVE AWS AZURE GCP OCI CLOUDFLARE SCANNING...
Cloud Posture

Multi-Cloud CSPM Engine

Connect AWS, Azure, GCP, OCI, and Cloudflare in under 5 minutes. Audit your entire inventory for misconfigurations and shadow resources automatically.

Explore CSPM
FortiGate Policy Inspection Pipeline POLICY #42 · INTERNAL → INTERNET LAN SSL IPS AV WEB NET DOMINO EFFECT · 3 DEPENDENT RULES
Network Hardening

FortiGate Policy X-Ray

Inspect every policy across SSL, IPS, AV, WebFilter, and DNS layers. Catch the Domino Effect blast radius before changes reach production.

Explore X-Ray
The Score That Cannot Be Gamed

Retrievy Score Engine

One unified score across Cloud, Identity, and Network. Asymptotic decay rewards faster remediation, so the score reflects real posture, not paperwork.

Risk-accepted and pending-verification findings are excluded by design.

Unified Retrievy Score CSPM ISPM SCM 84 RETRIEVY SCORE 7-DAY TREND +12 pts ASYMPTOTIC DECAY
Active Directory and GPO Tree DC=CORP SERVERS WORKSTNS USERS BASELINE SQL WIN11 CIS ENDPOINT PWD POL MFA GPO X-RAY · 6 OBJECTS · 2 WARN
Identity Guard (ISPM)

AD & GPO X-Ray

Deep-scan on-prem AD and Entra ID for toxic permission chains, missing MFA, and shadow admins. Inspect every Group Policy Object with the GPO X-Ray engine.

Explore ISPM
Hardening Kanban Board TRIAGE IN PROGRESS HARDENED
Remediation Workflow

Hardening Kanban

Turn X-Ray findings into an organized board. Move from discovery to Hardened with integrated evidence tracking on every card.

One Finding, Many Framework Mappings CIS NIST ISO 27001 PCI DSS MITRE SOC 2 HIPAA FedRAMP FINDING #1 +12 MORE
Compliance Coverage

20+ Frameworks, Auto-Mapped

Every finding maps to CIS, NIST CSF, ISO 27001, PCI DSS, MITRE ATT&CK, SOC 2, HIPAA, FedRAMP and more. One scan, every framework.

How It Works

Your Path to
Compliance

Stop wasting time on manual audits. Turn your complex multi-cloud and infrastructure configurations into an actionable hardening roadmap in three simple steps.

Cloud Integration Handshake

1. Connect Environments

Integrate your Multi-Cloud, AD, and Firewalls in minutes using secure read-only for zero-trust visibility.

CIS Compliance Mapping

2. Scan

Our platform automatically scans your Cloud, Identity, and On-Premises infrastructure against the most trusted frameworks, instantly revealing compliance gaps.

Harden & Report Workflow

3. Harden & Report

Remediate findings using our Kanban board or a Remediation Project and generate executive PDF reports to demonstrate your improved security posture.

Operation Modes

Built for
Security Teams

Stop losing time on manual configuration reviews. Retrievy automates the audit across your entire ecosystem so you can focus on the hardening.

Cloud Architect icon
Cloud Security (CSPM)

The Cloud Architect

Ensure every new Cloud Landing Zone (AWS, Azure, GCP, OCI) meets CIS, NIST, and ISO 27001 controls from day one. Auto-scan configurations and prevent architectural drift.

Security Engineer icon
Security Operations

The SecOps Engineer

Drown out the noise with the Hardening Kanban. Transform 1,000+ findings into a prioritized list of actionable fixes.

Compliance Officer icon
Identity Guard (ISPM)

The Identity Administrator

Identify over-privileged identities, AD misconfigurations, and dormant accounts to eliminate security backdoors in Active Directory and Entra ID.

CISO icon
Risk & Management

The CISO

Track your security posture evolution across all environments. Prove hardening progress to the board with executive-grade PDF reports.

Consultant icon
Consultant & Multi-Tenant

The IT Consultant

Manage security for multiple clients from a single pane of glass. Give each client their own isolated vault of security findings.

Infra Lead icon
Infrastructure (SCM)

The Network Engineer

Audit firewall rules and configuration settings (like Fortigate) instantly to maintain SCM compliance and close network vulnerabilities.

Pricing Tiers

Invest in
Resilience

Choose the plan that fits your infrastructure. Scale your security audits without scaling your budget.

Essentials
$ /mo

Per workspace

Billed annually ($1,490/yr)

For day-to-day hardening across Cloud, Identity, and Network in a single workspace.

  • Up to 2 Data Sources

    A Data Source is an isolated security scope, such as an Azure Subscription, AWS Account, OCI Tenancy, or On-Premise Server.

  • Up to 3 User Seats
  • 90-Day Scan History
  • CSPM, ISPM & SCM unified: cloud, identity, and network audits in one workspace
  • Findings auto-mapped to NIST CSF, CIS Controls, and MITRE ATT&CK
  • Retrievy X-Ray engines for deep configuration analysis
  • Identity-risk audit across Active Directory and Microsoft 365
  • Live scan progress and email alerts on new findings
  • Framework Builder - Custom compliance frameworks
Most Popular
Advanced
$ /mo

Per workspace

Billed annually ($3,490/yr)

For teams that also need executive PDFs, SSO, audit logs, and priority scans.

  • Up to 4 Data Sources

    A Data Source is an isolated security scope, such as an Azure Subscription, AWS Account, OCI Tenancy, or On-Premise Server.

  • Up to 10 User Seats
  • 180-Day Scan History
  • Everything in Essentials, plus:
  • Executive + technical PDF reports for boardroom and engineering audiences
  • Detailed audit trail for compliance reporting
  • Single Sign-On (Google + Microsoft)
  • Priority scan queue with 3× throughput
  • Interactive FortiGate dependency graph for blast-radius analysis
Build Your Own
$400 /mo

Per workspace

Size the platform to your environment. Pay for the data sources and seats you actually need.

5

Each data source is one isolated security scope (an Azure subscription, AWS account, OCI tenancy, FortiGate, or on-premise server).

10

Operators with access to the workspace. $10 / seat / month.

Monthly Total $400
MSSP Elite Soon

Built for Managed Security Service Providers. MSSP teams will be able to allocate data sources and seats flexibly across all of their customer tenants, instead of locking each licence to a single workspace. Coming soon.

01

Unified Engine Score

CSPM, ISPM, and SCM findings roll up into a single Retrievy Engine Score. One posture grade you can defend to the board, with the math behind it always one click away.

02

Continuous Drift Detection

Every scan snapshots your firewall, AD, and GPO configuration. We consolidate mutations into a single alert, so a Friday afternoon policy change reaches you before Monday's audit finds it.

03

Audit-Ready Reports

Executive PDFs for leadership and technical exports for engineering. Same audit, two ready-to-send documents mapped to NIST CSF, CIS Controls, and MITRE ATT&CK.

Security Research

Retrievy
Insights

Security Knowledge Base

Frequently Asked
Questions

Have more questions? Our team is here to help you simplify and harden your multi-cloud infrastructure.

Retrievy is a unified CSPM, ISPM, and SCM platform built to make your life easier. Unlike traditional tools that overwhelm you with complex data, we focus on solving actual problems by automating the entire security lifecycle. From discovery to remediation via our native Hardening Kanban.
We provide a unified approach spanning three domains: CSPM for Multi-Cloud (AWS, Azure, GCP, OCI, Cloudflare), ISPM for Identity (Active Directory, Entra ID, Microsoft 365), and SCM for Infrastructure and Network devices such as FortiGate firewalls.
The Hardening Kanban is our proprietary workflow engine that turns complex audit findings into actionable tasks. It allows your team to prioritize risks by severity, view deep technical context, and track the journey of every finding from Triage Required to Hardened / Resolved.
Retrievy performs deep audits of your identity infrastructure, detecting over-privileged users, lack of MFA, risky conditional access policies, and toxic permission chains that could lead to unauthorized access.
Onboarding takes minutes, not days. Once you connect your environments via our secure handshake protocols, Retrievy immediately begins automated scanning to provide you with your first comprehensive security audit and compliance score.
Yes. Our global overview dashboards visualize your Compliance Score and Historical Evolution, allowing you to demonstrate ROI and security improvements to stakeholders with real-time data and trend analysis.
Security is our foundation. We use a strict Database-per-Tenant isolation model to ensure your scan data is never co-mingled. We only require Read-Only access to your environments, adhering to the principle of least privilege.
Remediation Projects allow you to group specific security initiatives into dedicated workspaces. This is ideal for tracking targeted consultancy goals or internal security sprints, providing clear timelines and baseline improvements for specific focus areas.
The Framework Builder lets you assemble your own compliance catalog by picking requirements from any system framework we ship (CIS Benchmarks, NIST CSF 2.0, ISO/IEC 27001:2022, PCI DSS 4.0, MITRE ATT&CK, and more). Combine Cloud, Identity, and Network controls into one audit, evolve each framework through immutable versions (v1, v2, v3, with clone-forward once a version is bound to a Remediation Project), and move catalogs between workspaces via portable JSON export. Built for MSSPs tailoring client-specific bundles, internal teams aligning audits to a contractual control set, and any organisation whose policy doesn't fit a single off-the-shelf framework.
Privacy protocol

Cookie Preferences

We use essential cookies to make our site work. With your consent, we may also use non-essential cookies to improve user experience and analyze website traffic. By clicking "Accept All", you agree to our website's cookie use as described in our Cookie Policy. Details