TesseriQ secures AWS from posture to prediction to evidence-backed investigation.
Perimeter continuously scans what is wrong now. Foresight predicts what is likely to drift, fail, or spike next. SENTRY investigates high-risk findings with evidence and remediation plans. Verdict connects reviewed security evidence to compliance controls—without claiming that a scanner alone proves compliance.
TesseriQ product suite
Perimeter is the continuous AWS security platform. Foresight is the predictive intelligence product that turns security, reliability, and cost signals into early warnings. SENTRY turns high-risk findings into evidence-backed decisions. Verdict adds reviewed compliance relevance and control impact.
Runtime Security Platform
Continuous AWS security posture management. Runtime scans, IaC and Dockerfile review, architecture diagram analysis, CVE correlation, compliance evidence, and AI Security Chat.
Predictive Risk Intelligence
Forecasts which findings, workloads, IAM policies, and cost patterns are about to escalate. It learns from CloudTrail sequences, CloudWatch metrics, drift history, and remediation outcomes.
AI Investigation Engine
Investigates high-risk findings from Perimeter and Foresight. It collects AWS evidence, separates true positives from noise, estimates blast radius, and drafts remediation plans with human approval gates.
Compliance Intelligence Engine
Maps security rules and findings to shared controls, then expands them through human-reviewed framework crosswalks. Production tagging is deterministic, explainable, and designed for Perimeter and other security products.
How it works
Shift-left IaC, Dockerfile, and architecture-diagram review run independently before deployment. Verdict tags reviewed compliance relevance after findings are created, with no LLM call in the scan path.
Terraform, CloudFormation, Pulumi YAML, Dockerfiles, draw.io, Excalidraw, and image-based architecture diagrams are checked before deployment.
Detect LLMjacking, GPU abuse, exposed Bedrock/SageMaker paths, five secret sources, privilege escalation, and lateral role-chaining.
Nightly ECR and SSM CVE correlation, waste detection, SLA tracking, score history, and PDF audit packs keep work moving.
TesseriQ uses STS AssumeRole with a tenant-specific ExternalId. Scans are read-only and every privileged action is audit logged.
Verdict converts security rules and findings into explainable control impact across multiple frameworks. Automation proposes the mapping; named human reviewers decide what can reach production.
For Perimeter and security products
A detection rule maps to a shared common control. Reviewed crosswalks then connect that control to relevant framework requirements, while provider-qualified evidence keeps AWS, Azure, and GCP checks isolated.
Production path
Perimeter loads a signed mapping snapshot and tags findings in memory. There is no remote lookup and no model call for each finding, keeping runtime behavior fast, predictable, and reproducible.
Stable product, provider, rule, and outcome identity.
One reusable technical control instead of repeated mappings.
Versioned review gates prevent draft assertions from leaking.
Signed snapshots for deterministic product integration.
Framework catalog
The current catalog spans 12 framework families, including SOC 2, ISO 27001, PCI DSS, NIST CSF, NIST SP 800-53, HIPAA, GDPR, and provider-specific CIS benchmarks. Only verified, reviewed mappings are eligible for production output.
Continuous posture management with 534 runtime rules, 130+ build-time rules, diagram review, CVE correlation, and compliance evidence.
Deep checks across 60+ AWS services — VPC, IAM, S3, ECS, EKS, Lambda, RDS, and rare services competitors miss.
8 entitlement rules + 6 behavioral CloudTrail rules. Detect over-permissioned roles, mass secret reads, and geo anomalies.
Scan 5 secret sources + 15 AI/ML threat rules. Detect GPU abuse, Bedrock misconfig, and lateral movement chains.
CIS, PCI-DSS, SOC 2, HIPAA, ISO 27001, NIST, MITRE ATT&CK, and GDPR. PDF evidence packs.
Attack paths, SLA tracking, score history, CVE runs, cost waste, and Claude-powered chat grounded in your findings.
Predictive security and operations product for TesseriQ customers
Foresight shifts cloud security from reactive detection to proactive forecasting. While existing tools answer "what is wrong now?", Foresight answers "what will go wrong next, and when?" — by analyzing CloudTrail patterns, CloudWatch metrics, IAM policy evolution, and configuration drift history to forecast likely security issues ahead of time — with target lead times from hours to weeks.
Flag periods of elevated misconfiguration risk using sprint-cycle timing and change-frequency signals.
Forecast timeout failures and memory exhaustion using P99 duration trend analysis.
Predict cluster capacity exhaustion and pod scheduling failures 1–2 weeks ahead.
Track IAM policy velocity to predict admin-equivalent permissions within 6 weeks.
Predict cost spikes and budget overruns 3–5 days before they hit your billing cycle.
Anticipate windows of manual infra change from historical change-frequency and temporal patterns.
Forecast storage, connection, and CPU/IOPS pressure on RDS and Aurora before they saturate.
Forecast latency and throttling risk on REST APIs from request-rate and error trends.
Forecast bucket configuration drift and storage-cost growth from snapshot history.
Foresight is bundled with Perimeter Growth and above (toggleable in Settings). Predicted findings appear in your existing dashboard with a ⬡ badge.
Evidence-backed investigation for critical cloud findings
SENTRY sits after Perimeter and Foresight. Perimeter detects current risk, Foresight predicts likely drift, and SENTRY investigates the alerts that matter most. It pulls CloudTrail, AWS Config, IAM access context, and actor history, then produces a structured verdict with cited evidence, blast radius, and a remediation plan.
Who changed what, when, and whether the actor behavior is unusual.
Current resource posture and relevant configuration history.
Effective access, privilege expansion, and impacted resources.
Raw evidence bundle stored separately from the summarized report.
SENTRY is included in Enterprise and available as a paid add-on for Assure teams that need analyst-ready investigation reports and audit trails.
Integrations
Perimeter, Foresight, and SENTRY integrate with the tools your team already uses.
Plus: Linear, Asana, OpsGenie, ServiceNow, Microsoft Teams, Datadog, GitHub Actions, GitLab CI, Azure AD, and SAML 2.0.
Pricing
Free to start. Scale to enterprise without the enterprise procurement cycle. Regional pricing: India plans are billed in INR (GST 18% extra); international plans are billed in USD. Annual prepay: 2 months free. Foresight is bundled in Growth and above. SENTRY is included in Enterprise and available as an Assure add-on for investigation-heavy teams.
Free, forever
Funded seed startups
Series A · full detection
Compliance & audit
BFSI · MSSP · custom
2 months free — pay 10 months, get 12. Cash collected upfront.
18% GST added at checkout. CGST/SGST or IGST as applicable. TDS deductions (2% u/s 194J) accepted with certificate workflow.
India plans: INR via Razorpay (UPI/NEFT/card). International plans: USD invoicing. Quarterly invoicing default.
Start a 14-day Perimeter trial on your own AWS account. Add Foresight to predict drift, bring in SENTRY for evidence-backed investigation, and use Verdict to attach reviewed compliance relevance to findings. Zero credentials stored — cross-account read-only role with mandatory ExternalId.