Perimeter + Foresight + SENTRY + Verdict

AWS Cloud Security,
Posture, Prediction, Investigation & Compliance Intelligence

TesseriQ secures AWS from posture to prediction to evidence-backed investigation.

Perimeter continuously scans what is wrong now. Foresight predicts what is likely to drift, fail, or spike next. SENTRY investigates high-risk findings with evidence and remediation plans. Verdict connects reviewed security evidence to compliance controls—without claiming that a scanner alone proves compliance.

TesseriQ product suite

Detect what's wrong. Predict what's next. Investigate what matters. Map the impact.

Perimeter is the continuous AWS security platform. Foresight is the predictive intelligence product that turns security, reliability, and cost signals into early warnings. SENTRY turns high-risk findings into evidence-backed decisions. Verdict adds reviewed compliance relevance and control impact.

Perimeter

Runtime Security Platform

Continuous AWS security posture management. Runtime scans, IaC and Dockerfile review, architecture diagram analysis, CVE correlation, compliance evidence, and AI Security Chat.

534
Scanner rules
60+
AWS services
130+
IaC rules
30
Diagram rules
Learn more

Foresight

Predictive Risk Intelligence

Forecasts which findings, workloads, IAM policies, and cost patterns are about to escalate. It learns from CloudTrail sequences, CloudWatch metrics, drift history, and remediation outcomes.

30s
Realtime drift trigger
30m
Batch prediction cycle
Causal
Sequence reasoning
Growth+
Bundled tier
Learn more

SENTRY

AI Investigation Engine

Investigates high-risk findings from Perimeter and Foresight. It collects AWS evidence, separates true positives from noise, estimates blast radius, and drafts remediation plans with human approval gates.

TP/FP
Verdict support
S3
Evidence bundle
Human
Gate on uncertainty
Enterprise
Included tier
Learn more

Verdict

Compliance Intelligence Engine

Maps security rules and findings to shared controls, then expands them through human-reviewed framework crosswalks. Production tagging is deterministic, explainable, and designed for Perimeter and other security products.

12
Framework families
3
Cloud providers
0
LLM calls at scan time
Human
Production review gate
Learn more

How it works

1
Scan Posture
Perimeter
2
Detect Drift
Foresight
3
Predict
Foresight (Growth+)
4
Investigate
SENTRY (Enterprise)
5
Map Control Impact
Verdict

Shift-left IaC, Dockerfile, and architecture-diagram review run independently before deployment. Verdict tags reviewed compliance relevance after findings are created, with no LLM call in the scan path.

Shift left

IaC, Dockerfile, and diagram review

Terraform, CloudFormation, Pulumi YAML, Dockerfiles, draw.io, Excalidraw, and image-based architecture diagrams are checked before deployment.

Threat depth

AI, secrets, and identity abuse

Detect LLMjacking, GPU abuse, exposed Bedrock/SageMaker paths, five secret sources, privilege escalation, and lateral role-chaining.

Operations

CVE, cost, SLA, and reports

Nightly ECR and SSM CVE correlation, waste detection, SLA tracking, score history, and PDF audit packs keep work moving.

Trust model

No AWS credentials stored

TesseriQ uses STS AssumeRole with a tenant-specific ExternalId. Scans are read-only and every privileged action is audit logged.

Verdict

Reviewed compliance intelligence, attached to every finding

Verdict converts security rules and findings into explainable control impact across multiple frameworks. Automation proposes the mapping; named human reviewers decide what can reach production.

For Perimeter and security products

Map once. Reuse across frameworks and clouds.

A detection rule maps to a shared common control. Reviewed crosswalks then connect that control to relevant framework requirements, while provider-qualified evidence keeps AWS, Azure, and GCP checks isolated.

API-first
Built for CSPM, identity, DevSecOps, Kubernetes, and vulnerability platforms.
Provider-aware
One neutral engine with separate AWS, Azure, and GCP evidence mappings.
Fail closed
Missing, stale, or unreviewed mappings remain explicitly unmapped.
Audit-ready
Version, reviewer, provenance, and rule hash travel with every published mapping.

Production path

Deterministic at scan time

NO LLM
finding / aws / R-019
common_control: CC-AC-004
mapping_status: reviewed
framework_relevance: PCI DSS · ISO 27001 · SOC 2
snapshot: signed · immutable · versioned

Perimeter loads a signed mapping snapshot and tags findings in memory. There is no remote lookup and no model call for each finding, keeping runtime behavior fast, predictable, and reproducible.

01 · Ingest Security rule or check

Stable product, provider, rule, and outcome identity.

02 · Normalize Shared common control

One reusable technical control instead of repeated mappings.

03 · Review Human-approved crosswalk

Versioned review gates prevent draft assertions from leaking.

04 · Publish Framework relevance

Signed snapshots for deterministic product integration.

Framework catalog

Designed around the frameworks customers ask for

The current catalog spans 12 framework families, including SOC 2, ISO 27001, PCI DSS, NIST CSF, NIST SP 800-53, HIPAA, GDPR, and provider-specific CIS benchmarks. Only verified, reviewed mappings are eligible for production output.

SOC 2 ISO 27001 PCI DSS NIST CSF NIST 800-53 HIPAA GDPR CIS Benchmarks
Become a Verdict design partner
Verdict reports compliance relevance, control impact, and technical evidence. Scanner results alone are not certification or proof that an organization is compliant.
Perimeter

Runtime Security at AWS Depth

Continuous posture management with 534 runtime rules, 130+ build-time rules, diagram review, CVE correlation, and compliance evidence.

534 Runtime Rules

Deep checks across 60+ AWS services — VPC, IAM, S3, ECS, EKS, Lambda, RDS, and rare services competitors miss.

CIEM & Insider Threat

8 entitlement rules + 6 behavioral CloudTrail rules. Detect over-permissioned roles, mass secret reads, and geo anomalies.

Secrets & LLMjacking

Scan 5 secret sources + 15 AI/ML threat rules. Detect GPU abuse, Bedrock misconfig, and lateral movement chains.

Compliance Evidence

CIS, PCI-DSS, SOC 2, HIPAA, ISO 27001, NIST, MITRE ATT&CK, and GDPR. PDF evidence packs.

Risk Intelligence

Attack paths, SLA tracking, score history, CVE runs, cost waste, and Claude-powered chat grounded in your findings.

Foresight

PREDICTIVE · GROWTH+

Predictive security and operations product for TesseriQ customers

Available with Perimeter Growth+
Predict what will go wrong — before it does

Foresight shifts cloud security from reactive detection to proactive forecasting. While existing tools answer "what is wrong now?", Foresight answers "what will go wrong next, and when?" — by analyzing CloudTrail patterns, CloudWatch metrics, IAM policy evolution, and configuration drift history to forecast likely security issues ahead of time — with target lead times from hours to weeks.

Without Foresight (Reactive)
Detect misconfiguration after it occurs
Alert on Lambda timeout after invocation fails
Report cost anomaly after billing cycle
With Foresight (Predictive)
Predict misconfiguration 24–72 hours before
Forecast timeout risk 15 days ahead
Forecast cost spike 3–5 days before it hits

Nine Prediction Domains

Security Drift Forecasting

Flag periods of elevated misconfiguration risk using sprint-cycle timing and change-frequency signals.

Lambda Timeout Prediction

Forecast timeout failures and memory exhaustion using P99 duration trend analysis.

EKS Capacity Forecasting

Predict cluster capacity exhaustion and pod scheduling failures 1–2 weeks ahead.

IAM Permission Creep

Track IAM policy velocity to predict admin-equivalent permissions within 6 weeks.

Cost Anomaly Forecasting

Predict cost spikes and budget overruns 3–5 days before they hit your billing cycle.

Drift Window Prediction

Anticipate windows of manual infra change from historical change-frequency and temporal patterns.

RDS / Aurora Capacity

Forecast storage, connection, and CPU/IOPS pressure on RDS and Aurora before they saturate.

API Gateway Capacity

Forecast latency and throttling risk on REST APIs from request-rate and error trends.

S3 Exposure & Cost

Forecast bucket configuration drift and storage-cost growth from snapshot history.

ML Model Stack

Meta Prophet — seasonality-aware time-series forecasting
Isolation Forest — anomaly detection on IAM velocity
Linear + heuristic models — robust fallbacks when history is sparse or new
Claude Haiku — narrative generation & root cause hypothesis

Pre-Staged Remediation

SG drift → time-scoped rule that auto-expires
Lambda timeout → CloudFormation changeset ready
IAM creep → least-privilege policy PR generated
Drift window → Terraform plan/apply before window
≥0.74
Target F1 score across all 6 domains
<60s
Feedback loop latency via EventBridge
≥30%
Pre-remediation rate target (Critical/High)

Foresight is bundled with Perimeter Growth and above (toggleable in Settings). Predicted findings appear in your existing dashboard with a badge.

SENTRY

AI INVESTIGATION · ENTERPRISE

Evidence-backed investigation for critical cloud findings

Enterprise included · Assure add-on
From alert volume to analyst-ready verdicts

SENTRY sits after Perimeter and Foresight. Perimeter detects current risk, Foresight predicts likely drift, and SENTRY investigates the alerts that matter most. It pulls CloudTrail, AWS Config, IAM access context, and actor history, then produces a structured verdict with cited evidence, blast radius, and a remediation plan.

Without SENTRY
Analysts manually chase evidence across CloudTrail, Config, IAM, and tickets
High-severity queues include true risk, duplicates, and context-light false positives
Audit evidence is assembled after the incident, often from scattered logs
With SENTRY
Each investigation returns true positive, false positive, or needs human review
Reports cite evidence, affected resources, exposure window, and remediation steps
Uncertain or high-autonomy actions route to a human gate instead of auto-fixing

What SENTRY investigates

CloudTrail timeline

Who changed what, when, and whether the actor behavior is unusual.

AWS Config state

Current resource posture and relevant configuration history.

IAM blast radius

Effective access, privilege expansion, and impacted resources.

Audit evidence

Raw evidence bundle stored separately from the summarized report.

≤5
Investigation iterations before human fallback
25
Max tool calls per investigation
Plan
Remediation guidance, not autonomous execution

SENTRY is included in Enterprise and available as a paid add-on for Assure teams that need analyst-ready investigation reports and audit trails.

Integrations

Fits into your workflow

Perimeter, Foresight, and SENTRY integrate with the tools your team already uses.

Jira
Tickets
Slack
Alerts
PagerDuty
On-call
Okta SSO
Identity
Splunk
SIEM
Webhooks
Custom

Plus: Linear, Asana, OpsGenie, ServiceNow, Microsoft Teams, Datadog, GitHub Actions, GitLab CI, Azure AD, and SAML 2.0.

Pricing

Built for startups and mid-market teams worldwide.

Free to start. Scale to enterprise without the enterprise procurement cycle. Regional pricing: India plans are billed in INR (GST 18% extra); international plans are billed in USD. Annual prepay: 2 months free. Foresight is bundled in Growth and above. SENTRY is included in Enterprise and available as an Assure add-on for investigation-heavy teams.

Community

Free, forever

₹0 /mo $0/mo
1 AWS account · 1 user · ~100 cloud resources · no card
  • ~150 core rules: IAM, S3, EC2, VPC, SG
  • On-demand scans, 14-day history
  • Public Architecture Diagram Scanner, 5 uploads/hr
  • ·No IaC, drift, chat, exports, Foresight, or SENTRY
  • ·Community Discord support
Book a demo

Starter

Funded seed startups

₹4,999 /mo + GST $99/mo internationally
2 accounts · 3 seats · ~500 cloud resources
  • All 534 security rules
  • Daily scheduled scans
  • IaC, Dockerfile, and persisted diagram scans
  • Full findings workflow, SLA tracking, CSV export
  • ·No AI Chat, Foresight, or SENTRY
  • Email support (24h)
Book a demo

Assure

Compliance & audit

₹1,19,999 /mo + GST $1,999/mo internationally
15 accounts · 15 seats · ~15,000 cloud resources · audit retention
  • Everything in Growth
  • 8 frameworks: CIS, PCI, SOC 2, HIPAA, ISO, MITRE, NIST, GDPR
  • PDF evidence packs, audit CSV, 1-year compliance retention
  • AI Chat: 25/user/hr, 75/tenant/hr
  • Foresight bundled
  • SENTRY available as paid add-on
  • Priority + Slack-shared-channel (4h)
Talk to sales

Enterprise

BFSI · MSSP · custom

Custom
Custom floor · multi-year options
  • Everything in Assure, unlimited accounts and seats
  • SSO/SAML + MSSP multi-tenant
  • Custom frameworks (RBI, IRDAI, MeitY)
  • AI Chat: 100/user/hr, 300/tenant/hr
  • Dedicated infra, customer KMS, optional VPC-deployed Foresight
  • SENTRY included: AI investigations, evidence bundles, blast-radius reports
  • 24×7 phone/WhatsApp/Slack (1h SLA)
Talk to sales
Annual prepay

2 months free — pay 10 months, get 12. Cash collected upfront.

GST & TDS

18% GST added at checkout. CGST/SGST or IGST as applicable. TDS deductions (2% u/s 194J) accepted with certificate workflow.

Billing

India plans: INR via Razorpay (UPI/NEFT/card). International plans: USD invoicing. Quarterly invoicing default.

Secure your AWS cloud, end-to-end

Start a 14-day Perimeter trial on your own AWS account. Add Foresight to predict drift, bring in SENTRY for evidence-backed investigation, and use Verdict to attach reviewed compliance relevance to findings. Zero credentials stored — cross-account read-only role with mandatory ExternalId.