Skip to content
Methodology

How Retrievy turns configuration evidence into a security decision.

Every number on a Retrievy screen traces back to something collected from a system you connected. This page explains that path end to end, including where it stops.

How evidence flows

The evidence chain

Each stage consumes the stage before it. Nothing appears in a score that did not enter here.

  1. 1 Source

    Collect

    Read-only collection from the sources you connect: cloud APIs, a least-privilege Active Directory agent, or read-only SSH to a device. Nothing is inferred from a questionnaire.

  2. 2 Analysis

    Evaluate

    Collected state is compared against the checks that apply to that source type. A check either has the evidence it needs or reports that it does not.

  3. 3 Priority

    Score

    Findings are weighted by severity and decay asymptotically, so a large estate cannot average away a critical finding and an old finding cannot quietly stop counting.

  4. 4 Proof

    Verify

    A later scan re-collects the same evidence. A finding closes when the fresh evidence no longer shows it, not when someone marks the task done.

Severity is assigned, not negotiated.

Every check carries a severity that reflects the exposure it represents, not how hard it is to fix. A finding that is inconvenient to remediate is not thereby less severe, and the score does not soften because the work is large.

The Retrievy Score weights unresolved findings by that severity and decays their contribution asymptotically rather than linearly. The practical effect is that a score cannot be improved by adding clean resources around a critical finding, which is the failure mode of a simple pass-rate percentage.

Framework mapping is an organizing view.

A finding is mapped to the controls it provides evidence for across CIS Controls, NIST CSF, ISO 27001, PCI DSS and MITRE ATT&CK. One collected fact can therefore appear under several frameworks, because the same configuration is evidence for several control objectives.

This is a presentation of your own evidence, organized the way an auditor asks for it. A framework mapping organizes evidence; it is not a certification. It does not assert that a control is implemented, only that a finding relates to it.

Exceptions are recorded, not hidden.

A risk you accept deliberately is different from one you have not seen. An accepted exception is excluded from the score, carries an owner and an expiry, and remains visible with its justification attached.

Exceptions expire on purpose. An acceptance made eighteen months ago against a system that has since changed is not evidence about the system as it stands today.

Coverage is stated, never assumed.

Where a source was not connected, or a scope was not granted, the affected surfaces say so rather than showing a clean result. An empty list and a list you are not permitted to see are different answers, and conflating them is how a dashboard tells someone everything is fine when they can see nothing at all.

Boundaries

What this methodology does not claim

  • A framework mapping organizes evidence; it is not a certification.
  • A score is a prioritization aid, not an assurance that an estate is secure.
  • Checks run against collected configuration. Nothing is exploited, and no control is tested by attacking it.
  • An absence of findings means nothing was found in the evidence collected, within the scopes granted.
  • Retrievy never changes your systems. Remediation is described, owned and verified; the change itself is yours.
Questions

Frequently asked questions

Does a high Retrievy Score mean we are compliant?
No. The score reflects unresolved findings weighted by severity across the sources you connected. Compliance is a determination made by an auditor against a defined scope. A framework mapping organizes evidence; it is not a certification.
Why can one finding appear under several frameworks?
Because one collected fact can be evidence for several control objectives. A domain controller signing setting is evidence for a CIS Safeguard, a NIST CSF subcategory and an ISO control at the same time. Mapping it once per framework is presentation, not duplication of the finding.
How is a finding actually closed?
A later scan re-collects the same evidence. If the condition is gone, the finding moves to verified. Marking a remediation task complete does not close it, because the task is a claim and the scan is evidence.
Is any customer data shown on this page?
No. This page explains method only. Product screenshots elsewhere on this site use illustrative data from fictional environments, and customer scan data is never published.

See the method against your own evidence.

Connect one source read-only and follow a finding from collection through scoring, mapping and verification.