SecValley, the Security Evidence Platform

Every finding shows its work.

SecValley reads your Microsoft 365, Entra ID, Azure and AWS tenants and tells you what your evidence actually supports, including the parts it could not read. Your auditor makes the call.

Next

GitHub Google Cloud
Google Workspace Okta Firewalls NAS
Microsoft 365 Entra ID Azure AWS
SEALED RECORDCIS Microsoft 365 6.0.1
Control1.1.3 Ensure that between two and four global admins are designated
Verdictpass3 of 12 privileged accounts hold Global Administrator
Collected2026-08-24 03:12:41 UTC, connection contoso-m365
Maps toCIS M365 1.1.3, attested: none yet
Sources
Read:Entra directory roles, role assignments2 sources
Read:PIM eligible assignments1 source
unansweredSign-in activity: audit log read denied1 source
11read 1unanswered 12sealed

Illustrative animation, not a customer result.

Built by the engineers and responders who cleaned up after the breaches.

Read-only. Agentless. No mail, files or messages are read.

01 Products

One evidence base. Three products.

Three products read the same sealed records. Nothing is re-collected, re-typed or screenshotted. Each one answers a different reader.

Live
Your team

Security Posture

Misconfigurations, attack paths and remediation across Microsoft 365, Entra ID, Azure and AWS against CIS benchmarks, per connection, on a schedule.

Explore Security Posture
Early access
Your auditor

Compliance

Controls, applicability, evidence, policies, people, risks and incidents in one module. An observation window that builds from operating controls. What a machine observed and what a person attested are shown apart. Only your auditor can declare you compliant.

See the compliance module
Live
Your carrier

Insurance Posture

Upload the application you signed. We map it to the questions carriers ask, check each answer against your live environment, and show where the answers drifted. Accuracy, not approvability.

Insurance Posture
02 Coverage

Coverage, declared per scan

Every scan writes down what it read and what it could not. The log is kept with the records, and your auditor and your carrier see the same lines you see.

SCAN LOGcontoso, 4 connections, 2026-08-24 03:12 UTC

    
Every line above is kept with the record. A read that was denied is written down, counted, and reported as unanswered.
03 Scope

What we read

Hundreds of configuration sources per connection, read through the vendor APIs, in read-only mode. The scan log names each one. Below is the shape of it, not the list.

Microsoft 365

Every workload with an admin surface: mail flow, sharing, collaboration, data governance, device management and more.

Entra ID

Identity, access and privilege: who can sign in, from where, with what role, for how long.

Azure

Every subscription in scope: identity, data, network, compute, secrets and the security services around them.

AWS

Every region in scope: identity, data, network, compute, logging and monitoring, across the organization.

Frameworks
Live
Benchmarks

CIS for Microsoft 365, Entra ID, Azure and AWS, pinned to the version the benchmark publishes. Every control maps to the records that answer it.

Building
Audit frameworks

SOC 2 first, mapped criterion by criterion from the same records. A criterion without machine evidence stays open in the module; it is never filled in.

Next
Everything after

ISO 27001, HIPAA, PCI DSS and GCP follow the same rule: one record base, a framework is a map over it, and coverage is declared per scan.

declared

What we do not do.

We do not issue audit reports, opinions or certifications. We are not an insurance carrier, broker or agent. We do not read your mail, files or messages; scans are configuration only.

Not to be confused with digital evidence management for law enforcement. SecValley evidence is cloud configuration, sealed at collection.

Let's Talk Security

Whether you need a platform demo or want to discuss your security challenges, we're here to help.

  • ✓ Quick response - we get back to you ASAP
  • ✓ No obligation consultation
  • ✓ Talk directly with security experts

We respect your privacy. No spam, ever.