Perimeter + Foresight + Sentry

Cloud Security,
Posture, Prediction & Investigation

Built for multicloud. Proven on AWS.

AWS · Available Azure · Early access GCP · Planned

Perimeter scans cloud posture. Foresight predicts drift and failure. Sentry investigates high-risk findings with evidence, remediation plans, and connected compliance context.

TesseriQ product suite

Detect what's wrong. Predict what's next. Investigate what matters.

Perimeter is the continuous cloud security platform, with AWS available today, Azure entering early access, and GCP planned. Foresight is the predictive intelligence product that turns security, reliability, and cost signals into early warnings. Sentry turns high-risk findings into evidence-backed decisions.

Perimeter

Runtime Security Platform

Continuous cloud security posture management. Production AWS scans, IaC and Dockerfile review, architecture diagram analysis, CVE correlation, compliance evidence, and AI Security Chat.

534
Scanner rules
60+
AWS services
130+
IaC rules
30
Diagram rules
Learn more

Foresight

Predictive Risk Intelligence

Forecasts which findings, workloads, IAM policies, and cost patterns are about to escalate. It learns from CloudTrail sequences, CloudWatch metrics, drift history, and remediation outcomes.

30s
Realtime drift trigger
30m
Batch prediction cycle
Causal
Sequence reasoning
Growth+
Bundled tier
Learn more

Sentry

AI Investigation Engine

Investigates high-risk findings from Perimeter and Foresight. It collects AWS evidence, separates true positives from noise, estimates blast radius, and drafts remediation plans with human approval gates.

TP/FP
Risk classification
S3
Evidence bundle
Human
Gate on uncertainty
Enterprise
Included tier
Learn more

How it works

1
Scan Posture
Perimeter
2
Detect Drift
Foresight
3
Predict
Foresight (Growth+)
4
Investigate
Sentry (Enterprise)
5
Prove Compliance
Perimeter evidence

Shift-left IaC, Dockerfile, and architecture-diagram review run independently before deployment. Perimeter connects findings to reviewed compliance mappings without a model call in the scan path.

Shift left

IaC, Dockerfile, and diagram review

Terraform, CloudFormation, Pulumi YAML, Dockerfiles, draw.io, Excalidraw, and image-based architecture diagrams are checked before deployment.

Threat depth

AI, secrets, and identity abuse

Detect LLMjacking, GPU abuse, exposed Bedrock/SageMaker paths, five secret sources, privilege escalation, and lateral role-chaining.

Operations

CVE, cost, SLA, and reports

Nightly ECR and SSM CVE correlation, waste detection, SLA tracking, score history, and PDF audit packs keep work moving.

Trust model

Provider-native, least-privilege access

AWS access uses STS AssumeRole with a tenant-specific ExternalId. Scans are read-only, no long-lived AWS credentials are stored, and every privileged action is audit logged.

Perimeter

Cloud Security with AWS Depth Today

Built on a provider-aware foundation. AWS production coverage includes 534 runtime rules, 130+ build-time rules, diagram review, CVE correlation, and compliance evidence. Azure onboarding and scanning are entering early access, with GCP planned next.

AWS · Available Azure · Early access GCP · Planned

534 Runtime Rules

Deep checks across 60+ AWS services — VPC, IAM, S3, ECS, EKS, Lambda, RDS, and rare services competitors miss.

CIEM & Insider Threat

8 entitlement rules + 6 behavioral CloudTrail rules. Detect over-permissioned roles, mass secret reads, and geo anomalies.

Secrets & LLMjacking

Scan 5 secret sources + 15 AI/ML threat rules. Detect GPU abuse, Bedrock misconfig, and lateral movement chains.

Compliance Evidence

Reviewed control relevance for CIS, PCI-DSS, SOC 2, HIPAA, ISO 27001, NIST, MITRE ATT&CK, and GDPR, with PDF evidence packs. The mappings are maintained through Verdict, TesseriQ's internal compliance workflow—not a separate product or SKU.

Risk Intelligence

Attack paths, SLA tracking, score history, CVE runs, cost waste, and Claude-powered chat grounded in your findings.

Foresight

PREDICTIVE · GROWTH+

Predictive security and operations product for TesseriQ customers

Available with Perimeter Growth+
Predict what will go wrong — before it does

Foresight shifts cloud security from reactive detection to proactive forecasting. While existing tools answer "what is wrong now?", Foresight answers "what will go wrong next, and when?" — by analyzing CloudTrail patterns, CloudWatch metrics, IAM policy evolution, and configuration drift history to forecast likely security issues ahead of time — with target lead times from hours to weeks.

Without Foresight (Reactive)
Detect misconfiguration after it occurs
Alert on Lambda timeout after invocation fails
Report cost anomaly after billing cycle
With Foresight (Predictive)
Predict misconfiguration 24–72 hours before
Forecast timeout risk 15 days ahead
Forecast cost spike 3–5 days before it hits

Nine Prediction Domains

Security Drift Forecasting

Flag periods of elevated misconfiguration risk using sprint-cycle timing and change-frequency signals.

Lambda Timeout Prediction

Forecast timeout failures and memory exhaustion using P99 duration trend analysis.

EKS Capacity Forecasting

Predict cluster capacity exhaustion and pod scheduling failures 1–2 weeks ahead.

IAM Permission Creep

Track IAM policy velocity to predict admin-equivalent permissions within 6 weeks.

Cost Anomaly Forecasting

Predict cost spikes and budget overruns 3–5 days before they hit your billing cycle.

Drift Window Prediction

Anticipate windows of manual infra change from historical change-frequency and temporal patterns.

RDS / Aurora Capacity

Forecast storage, connection, and CPU/IOPS pressure on RDS and Aurora before they saturate.

API Gateway Capacity

Forecast latency and throttling risk on REST APIs from request-rate and error trends.

S3 Exposure & Cost

Forecast bucket configuration drift and storage-cost growth from snapshot history.

ML Model Stack

Meta Prophet — seasonality-aware time-series forecasting
Isolation Forest — anomaly detection on IAM velocity
Linear + heuristic models — robust fallbacks when history is sparse or new
Claude Haiku — narrative generation & root cause hypothesis

Pre-Staged Remediation

SG drift → time-scoped rule that auto-expires
Lambda timeout → CloudFormation changeset ready
IAM creep → least-privilege policy PR generated
Drift window → Terraform plan/apply before window
≥0.74
Target F1 score across all 6 domains
<60s
Feedback loop latency via EventBridge
≥30%
Pre-remediation rate target (Critical/High)

Foresight is bundled with Perimeter Growth and above (toggleable in Settings). Predicted findings appear in your existing dashboard with a badge.

Sentry

AI INVESTIGATION · ENTERPRISE

Evidence-backed investigation for critical cloud findings

Enterprise included · Assure add-on
From alert volume to analyst-ready verdicts

Sentry sits after Perimeter and Foresight. Perimeter detects current risk, Foresight predicts likely drift, and Sentry investigates the alerts that matter most. It pulls CloudTrail, AWS Config, IAM access context, and actor history, then produces a structured verdict with cited evidence, blast radius, and a remediation plan.

Without Sentry
Analysts manually chase evidence across CloudTrail, Config, IAM, and tickets
High-severity queues include true risk, duplicates, and context-light false positives
Audit evidence is assembled after the incident, often from scattered logs
With Sentry
Each investigation returns true positive, false positive, or needs human review
Reports cite evidence, affected resources, exposure window, and remediation steps
Uncertain or high-autonomy actions route to a human gate instead of auto-fixing

What Sentry investigates

CloudTrail timeline

Who changed what, when, and whether the actor behavior is unusual.

AWS Config state

Current resource posture and relevant configuration history.

IAM blast radius

Effective access, privilege expansion, and impacted resources.

Audit evidence

Raw evidence bundle stored separately from the summarized report.

≤5
Investigation iterations before human fallback
25
Max tool calls per investigation
Plan
Remediation guidance, not autonomous execution

Sentry is included in Enterprise and available as a paid add-on for Assure teams that need analyst-ready investigation reports and audit trails.

Integrations

Fits into your workflow

Perimeter, Foresight, and Sentry integrate with the tools your team already uses.

Jira
Tickets
Slack
Alerts
PagerDuty
On-call
Okta SSO
Identity
Splunk
SIEM
Webhooks
Custom

Plus: Linear, Asana, OpsGenie, ServiceNow, Microsoft Teams, Datadog, GitHub Actions, GitLab CI, Azure AD, and SAML 2.0.

Pricing

Built for startups and mid-market teams worldwide.

Free to start. Scale to enterprise without the enterprise procurement cycle. Regional pricing: India plans are billed in INR (GST 18% extra); international plans are billed in USD. Annual prepay: 2 months free. Foresight is bundled in Growth and above. Sentry is included in Enterprise and available as an Assure add-on for investigation-heavy teams. Published plans cover AWS accounts today; Azure early-access packaging is scoped with design partners.

Community

Free, forever

₹0 /mo $0/mo
1 AWS account · 1 user · ~100 cloud resources · no card
  • ~150 core rules: IAM, S3, EC2, VPC, SG
  • On-demand scans, 14-day history
  • Public Architecture Diagram Scanner, 5 uploads/hr
  • ·No IaC, drift, chat, exports, Foresight, or Sentry
  • ·Community Discord support
Book a demo

Starter

Funded seed startups

₹4,999 /mo + GST $99/mo internationally
2 accounts · 3 seats · ~500 cloud resources
  • All 534 security rules
  • Daily scheduled scans
  • IaC, Dockerfile, and persisted diagram scans
  • Full findings workflow, SLA tracking, CSV export
  • ·No AI Chat, Foresight, or Sentry
  • Email support (24h)
Book a demo

Assure

Compliance & audit

₹1,19,999 /mo + GST $1,999/mo internationally
15 accounts · 15 seats · ~15,000 cloud resources · audit retention
  • Everything in Growth
  • 8 frameworks: CIS, PCI, SOC 2, HIPAA, ISO, MITRE, NIST, GDPR
  • PDF evidence packs, audit CSV, 1-year compliance retention
  • AI Chat: 25/user/hr, 75/tenant/hr
  • Foresight bundled
  • Sentry available as paid add-on
  • Priority + Slack-shared-channel (4h)
Talk to sales

Enterprise

BFSI · MSSP · custom

Custom
Custom floor · multi-year options
  • Everything in Assure, unlimited accounts and seats
  • SSO/SAML + MSSP multi-tenant
  • Custom frameworks (RBI, IRDAI, MeitY)
  • AI Chat: 100/user/hr, 300/tenant/hr
  • Dedicated infra, customer KMS, optional VPC-deployed Foresight
  • Sentry included: AI investigations, evidence bundles, blast-radius reports
  • 24×7 phone/WhatsApp/Slack (1h SLA)
Talk to sales
Annual prepay

2 months free — pay 10 months, get 12. Cash collected upfront.

GST & TDS

18% GST added at checkout. CGST/SGST or IGST as applicable. TDS deductions (2% u/s 194J) accepted with certificate workflow.

Billing

India plans: INR via Razorpay (UPI/NEFT/card). International plans: USD invoicing. Quarterly invoicing default.

Secure your cloud, end-to-end

Start with Perimeter on AWS today and join Azure early access as coverage comes online. Add Foresight to predict drift, and bring in Sentry for evidence-backed investigation. Perimeter includes reviewed compliance evidence tied to its findings. Zero credentials stored — cross-account read-only role with mandatory ExternalId.