See Every Risk. Fix What Matters. Stay Ahead.

Continuous security posture management across Active Directory, Microsoft 365, Azure, AWS, FortiGate and more.

Check icon No credit card Check icon Full-feature access Check icon Runs on your own data
Retrievy R mark

How Retrievy protects your data

Enterprise icon

Enterprise Ready

SSO, RBAC, and full audit trails

Database isolation icon

Privacy First

Per-tenant database isolation, never pooled

Encryption icon

Secure by Design

Read-only collection, AES-256 encrypted

Growth icon

Built for Scale

MSSP multi-tenancy built in

The Platform

Three Consoles.
One Posture.

Cloud, identity and network configuration each have their own tool and their own idea of what "fixed" means. Retrievy audits all three from one read-only connection and scores them on one scale.

Multi-Cloud Posture Command Center SCAN-OK AUTH: ACTIVE AWS AZURE GCP OCI CLOUDFLARE SCANNING...
Cloud Posture · CSPM

Know what is exposed in every account

Cloud estates grow faster than anyone can review them, and the account nobody owns is the one that leaks. Retrievy connects AWS, Azure, GCP, OCI, and Cloudflare read-only, inventories what is actually running, and ranks the misconfigurations by the exposure they create.

Explore CSPM
FortiGate Policy Inspection Pipeline POLICY #42 · INTERNAL → INTERNET LAN SSL IPS AV WEB NET DOMINO EFFECT · 3 DEPENDENT RULES
Network Hardening · SCM

See what a firewall rule really allows

Rulebases outlive the people who wrote them. Policy X-Ray reads the running FortiGate configuration and shows where inspection is switched off, which rules are shadowed or unused, and what else breaks if you remove one.

Explore X-Ray
Measurement

One number leadership can defend

Posture is hard to report because every tool counts differently. The Retrievy Score consolidates cloud, identity, and network into one measure that moves only when risk is actually removed, and every point of it traces back to the findings behind it.

Risk-accepted and pending-verification findings are excluded by design, so the number cannot be improved by closing tickets.

Unified Retrievy Score CSPM ISPM SCM 84 RETRIEVY SCORE 7-DAY TREND +12 pts ASYMPTOTIC DECAY
Active Directory and GPO Tree DC=CORP SERVERS WORKSTNS USERS BASELINE SQL WIN11 CIS ENDPOINT PWD POL MFA GPO X-RAY · 6 OBJECTS · 2 WARN
Identity Posture · ISPM

Find who can quietly take the domain

Privilege accumulates through group nesting, delegation, and Group Policy nobody has opened in years. Retrievy resolves effective permissions across Active Directory and Entra ID, then names the accounts behind every path to Tier Zero.

Explore ISPM
Hardening Kanban Board TRIAGE IN PROGRESS HARDENED
Remediation

Turn findings into work that closes

A list of a thousand findings is not a plan. The Hardening Kanban gives each one an owner, a documented fix, and evidence, and marks it resolved only after a later scan confirms the change.

One Finding, Many Framework Mappings CIS NIST ISO 27001 PCI DSS MITRE SOC 2 HIPAA FedRAMP FINDING #1 +12 MORE
Compliance Readiness

Answer an audit without rebuilding the evidence

Every finding carries its mapping to CIS, NIST CSF, ISO 27001, PCI DSS, MITRE ATT&CK, SOC 2, HIPAA, and FedRAMP. Control coverage becomes a report you export, not a project you run each quarter.

See your own posture before you decide anything

Connect one Data Source and run a scan. The first results arrive in minutes, on your environment, with nothing to install in production.

Integrations

It Reads the Estate
You Already Run.

Connections are read-only and use each provider's own audit interfaces. Nothing sits in the traffic path, and a Data Source can be disconnected at any time.

Active Directory

Domain, OU, and Group Policy configuration, with effective permissions resolved.

Microsoft Entra ID

Directory roles, conditional access, MFA coverage, and privileged assignments.

Microsoft 365

Tenant security settings, sharing defaults, and admin role exposure.

Windows Server

Host configuration measured against the CIS Windows benchmarks.

FortiGate

Full running configuration, policy inspection coverage, and rule hygiene.

Microsoft Azure

Subscriptions, IAM assignments, network exposure, and storage posture.

Amazon Web Services

Accounts and organizations, IAM, public exposure, logging, and encryption.

Google Cloud

Projects, service accounts, and network and storage configuration.

Oracle Cloud

Compartments, identity policies, and tenancy-level hardening checks.

Cloudflare

Zone, DNS, and account security settings across your properties.

Findings from every connection land in the same workspace and the same score, so a firewall rule and an over-privileged directory account are ranked against each other rather than in separate reports.

Operation Modes

Built for
Security Teams.

The team that finds a misconfiguration is rarely the team that fixes it. Retrievy gives each of them the same evidence, scoped to what they are allowed to see.

Security Operations icon

Security Operations

Findings arrive ranked by severity and real exposure, mapped to MITRE ATT&CK, and grouped so one change closes many. The queue is short enough to work through, and it stays short because closure is verified by the next scan.

IT Operations icon

IT Operations

Keep Active Directory, Group Policy, and Windows Server inside a known-good baseline. When something moves off it, you see which policy changed, which objects it reaches, and when the drift started.

Cloud Teams icon

Cloud Teams

Every new account, subscription, project, or landing zone is audited against CIS and NIST from its first scan, so a shortcut taken during a launch is caught while it is still a setting and not yet an architecture.

Compliance icon

Compliance

Evidence is collected continuously instead of assembled the week before an audit. Control coverage across CIS, NIST CSF, ISO 27001, PCI DSS, and SOC 2 is a report you export, with the finding behind each control attached.

Enterprise IT icon

Enterprise IT

One workspace across on-premises and cloud, with single sign-on, role-based access, and an audit trail of who changed what. Roles can be limited to named Data Sources, so a regional team sees its own estate and nothing else.

Multi-tenant icon

MSPs and MSSPs

Run every customer from one platform, each in its own database rather than a shared table with a tenant column. Scope analysts per client, and hand over reports that carry the customer's posture and not your other accounts.

Security Outcomes

What Changes in
Your Environment.

Retrievy connects read-only to your cloud accounts, Active Directory, Microsoft 365 and firewalls, audits them on a schedule you set, and ranks every finding by the exposure it creates. Six things move once it is running.

Reduce attack surface

Public storage, permissive firewall rules, unused policies, and stale accounts are the paths that get used. Retrievy lists each one with the exposure it creates, so the work goes where an attacker would actually go.

Findings Ranked by exposure
Critical Storage bucket readable by anyone
High Security group open to 0.0.0.0/0
High Admin portal reachable from the internet
Medium Snapshot shared outside the account
Each row carries the resource, the account, and what it exposes.

Detect identity risks

Shadow administrators, nested privilege, delegation nobody remembers granting, and accounts without MFA. Every gap is reported with the identities behind it, so it lands on a person rather than on a counter.

Identity X-Ray Privilege path
svc-backup Backup Operators Server Operators Domain Admins
Effective Three hops, none of them granted directly.
Resolved from nesting, not read off a role list.

Improve compliance readiness

Evidence is collected continuously instead of assembled the week before an audit. Findings carry their framework mappings, exceptions carry a reason and an owner, and the whole picture exports as an executive or technical report.

Compliance Control coverage
CIS Benchmarks mapped
NIST CSF 2.0 mapped
ISO/IEC 27001:2022 mapped
PCI DSS 4.0 mapped
Every control opens the findings that satisfy or break it.

Discover configuration drift

Every scan is compared against the last. You see what changed, which objects or accounts it reaches, and when it started, which is usually the difference between a five-minute rollback and a week of archaeology.

Drift This scan vs baseline
Group Policy · Default Domain Policy
- Minimum password length 14
+ Minimum password length 8
Reaches Domain Users, every workstation
Compared against the previous scan, not against a memory.

Continuously monitor your environment

Scans run on the schedule you set, not when somebody remembers. New findings raise an alert, the score moves only when risk does, and a daily snapshot keeps the trend honest over months rather than over one screenshot.

Data Sources Scan schedule
Amazon Web Services every 8h
Microsoft Azure every 8h
Active Directory every 12h
FortiGate every 12h
A new finding notifies its owner. A daily snapshot keeps the trend.

Shorten time to remediation

Every finding ships with the fix for the exact platform it was found on, an owner, and a verification step, so the gap between detection and closure is measured instead of assumed.

Finding Lifecycle
Open detected by a scan
In progress owner assigned
Pending verification claimed fixed
Resolved · verified confirmed by the next scan
A finding that comes back reopens itself instead of staying closed.
Resource Center

Retrievy
Insights.

Research, methodology, and framework references from the team building the platform. Written for the people who have to implement the control.

View all insights
Security Knowledge Base

Frequently Asked
Questions.

The questions that come up most during an evaluation, answered without a sales call. Anything not covered here, ask us directly.

Retrievy is a unified CSPM, ISPM, and SCM platform built to make your life easier. Unlike traditional tools that overwhelm you with complex data, we focus on solving actual problems by automating the entire security lifecycle. From discovery to remediation via our native Hardening Kanban.
We provide a unified approach spanning three domains: CSPM for Multi-Cloud (AWS, Azure, GCP, OCI, Cloudflare), ISPM for Identity (Active Directory, Entra ID, Microsoft 365), and SCM for Infrastructure and Network devices such as FortiGate firewalls.
The Hardening Kanban is our proprietary workflow engine that turns complex audit findings into actionable tasks. It allows your team to prioritize risks by severity, view deep technical context, and track the journey of every finding from Triage Required to Hardened / Resolved.
Retrievy performs deep audits of your identity infrastructure, detecting over-privileged users, lack of MFA, risky conditional access policies, and toxic permission chains that could lead to unauthorized access.
Onboarding takes minutes, not days. Once you connect your environments via our secure handshake protocols, Retrievy immediately begins automated scanning to provide you with your first comprehensive security audit and compliance score.
Yes. Our global overview dashboards visualize your Compliance Score and Historical Evolution, allowing you to demonstrate ROI and security improvements to stakeholders with real-time data and trend analysis.
Security is our foundation. We use a strict Database-per-Tenant isolation model to ensure your scan data is never co-mingled. We only require Read-Only access to your environments, adhering to the principle of least privilege.
Remediation Projects allow you to group specific security initiatives into dedicated workspaces. This is ideal for tracking targeted consultancy goals or internal security sprints, providing clear timelines and baseline improvements for specific focus areas.
The Framework Builder lets you assemble your own compliance catalog by picking requirements from any system framework we ship (CIS Benchmarks, NIST CSF 2.0, ISO/IEC 27001:2022, PCI DSS 4.0, MITRE ATT&CK, and more). Combine Cloud, Identity, and Network controls into one audit, evolve each framework through immutable versions (v1, v2, v3, with clone-forward once a version is bound to a Remediation Project), and move catalogs between workspaces via portable JSON export. Built for MSSPs tailoring client-specific bundles, internal teams aligning audits to a contractual control set, and any organisation whose policy doesn't fit a single off-the-shelf framework.
Get Started

Start with One
Data Source.

The trial runs the full platform against your own environment, read-only, with no agent in the data path and no card required. If you stop there, the report is still yours.

Read-only by design Your data stays in its own database No credit card, no auto-renewal

Questions before you start? Talk to us.