AuditGraph
Map. Monitor. Secure. · by NexgenixLabs
Map. Monitor. Secure. · Identity Attack Surface Management · Azure · AWS · GCP

Know every identity.
Know what it can reach.
Before attackers do.

AuditGraph maps every human and non-human identity across your cloud estate — then calculates blast radius from your architecture. No logs. No agents. No week-long onboarding.

Azure-deep today. AWS-ready now. GCP coming soon.

Start Free Trial — No card required See How It Works
app.auditgraph.ai — Registration opening soon
No agents required
No log ingestion
5-min onboarding
Read-only API
app.auditgraph.ai/dashboard
● LIVE
TENANT: CONTOSO.ONMICROSOFT.COM
Identity Posture Dashboard
74
HIGH
AGIRS SCORE
IDENTITY BREAKDOWN — 1,296 TOTAL
Human
847
NHIs
312
MSIs
94
Guests
43
ORPHANED ×18 AT_RISK ×7 STALE ×24 GHOST_MSI ×3 HEALTHY ×1,244
⚠️
3 critical findings require immediate action
Non-human identity with Owner role — no expiry, no governance
Multi-cloud IASM
Azure deep · AWS ready · GCP coming
$500 + $69/sub — transparent pricing
95%+ identity attack surface
5 min to first findings
// The Problem

Your identity attack surface is growing
silently, every day.

👻
Ghost identities accumulate

Deleted VMs leave orphaned MSIs with active Contributor roles. Departed employees still hold keys. Nobody's counting.

🔇
Log-based tools miss static risk

Tools waiting for sign-in logs miss identities that have never signed in — but are fully provisioned and dangerous.

💰
Incumbents price out mid-market

Incumbent IASM and CSPM platforms are priced for Fortune 500 procurement cycles — six-figure annual contracts, months of onboarding. Mid-market enterprises are left securing complex cloud environments with spreadsheets and gut feel.

📊
No blast radius visibility

Non-human identities accumulate high-privilege roles across accounts and subscriptions. Nobody maps what they can reach — until a breach forces the question.

// The AuditGraph Approach

We read your architecture.
Not your logs.

🗺️
Static association analysis

AuditGraph maps identity-to-resource relationships from your live cloud configuration across Azure, AWS, and GCP. No activity logs. No agents. No pipelines.

🎯
Blast radius from scope strings

Every role assignment scope string is parsed. We tell you exactly what a compromised identity could access — at subscription, resource group, and resource level.

📡
9 lineage verdict types

Every identity receives a verdict automatically: ORPHANED, AT_RISK, STALE, GHOST_MSI, HEALTHY, and more — continuously, without waiting for logs.

Connect in minutes. Results immediately.

Read-only permissions only. Azure via Microsoft Graph + ARM. AWS via IAM read access. First findings appear in under 5 minutes. Zero infrastructure changes.

// Identity Lineage Engine

Every identity gets
a verdict.

AuditGraph's static association analysis produces a lineage verdict for every identity in your tenant — no log dependency, no delay, no guesswork.

"We don't ask what your non-human identity did last week. We map what it can reach right now — from your live cloud architecture."

ORPHANED
Parent resource gone. Role assignments still active.
AT_RISK
High blast radius. Weak or missing governance.
STALE
Provisioned but shows no active usage or associations.
GHOST_MSI
System MSI whose compute resource no longer exists.
FEDERATED_MISCONFIGURED
Federated credential subject mismatch — token replay risk.
HEALTHY
Well-scoped, governed, acceptable blast radius.
IDENTITY LINEAGE — NHI: api-backend-prod
NHI api-backend-prod App Registration api-backend Role Assignment Contributor /sub/… Subscription sub-prod-001 Blast Radius ALL RESOURCES AT_RISK owns has role scoped to exposes
// What We Cover

Every identity type.
Every cloud.

We don't care what the identity is attached to — VM, container, Lambda, or a bot. We care what it can reach. AuditGraph maps identity-to-resource exposure regardless of where that identity lives in your infrastructure.

☁️
Microsoft Azure Deep Coverage
Entra ID · Managed Identities · App Registrations · Service Principals · Guest Users
🟠
Amazon Web Services Preview
IAM Users · IAM Roles · Service Accounts · Lambda Execution Roles · Cross-account Trust
🔵
Google Cloud Platform Coming Soon
Service Accounts · Workload Identity · IAM Bindings · GKE Identities
👤
Human Identities
People with access

Employees, admins, guests, and external collaborators. AuditGraph maps every human identity against its role assignments, surfaces MFA gaps, and flags over-privileged admin accounts across all connected clouds.

Employees Admins Guest Users External Collaborators
⚙️
Non-Human Identities The Silent Majority
Everything that isn't a person

Service accounts, managed identities, app registrations, IAM roles, pipeline service principals, AI agents — all are non-human identities. They outnumber human identities 3:1 in most enterprises, accumulate permissions over time, and nobody's watching.

System-managed
Azure MSIs · AWS Lambda roles · GCP service accounts
User-assigned
UAMIs · Cross-account roles · Shared service accounts
App & pipeline
App registrations · GitHub Actions · ADO · Federated creds
AI agents
Copilot bots · OpenAI apps · LangChain workloads
// Risk Scoring

One score.
The full picture.

AGIRS is the AuditGraph Identity Risk Score — a composite 0–100 metric that weights human identity risk, non-human identity risk, and governance effectiveness into a single actionable number across your entire cloud estate.

AGIRS = 0.40 × HIRI + 0.40 × NHIRI + 0.20 × GEI
Human Identity Risk Index · Non-Human Identity Risk Index · Governance Effectiveness Index
40%
HIRI

Human identity risk — privileged admins, stale accounts, MFA gaps, and over-scoped direct role assignments.

40%
NHIRI

Non-human risk — orphaned SPNs, over-privileged MSIs, federated misconfigurations, and ghost identities.

20%
GEI

Governance effectiveness — remediation velocity, review cadence, and active posture management.

// How It Works

From zero to full identity visibility
in 5 minutes.

No agents to deploy. No log pipelines to build. No week-long onboarding. Just connect and see.

1
Connect Your Tenant

Grant read-only Graph + ARM permissions. No write access. No infrastructure changes.

2
AuditGraph Enumerates

Every identity across all types — human, non-human, AI agents, and workloads — enumerated automatically across your connected clouds.

3
Lineage Engine Runs

Static association analysis maps every identity, calculates blast radius, assigns verdicts — no logs needed.

4
Act on Findings

Prioritized remediation queue sorted by blast radius impact — with specific, actionable remediation steps.

// Pricing

Simple pricing.
Pay only for what you connect.

One flat platform fee. Then $69/month per connected cloud subscription or account. Start free — no time limit, no credit card.

Free
No time limit
$0
Forever · No credit card needed

Always-on identity posture visibility. Limited resources, no expiry, no pressure.

  • 1 cloud subscription / account
  • Up to 100 identities
  • Identity verdicts + AGIRS score
  • Weekly scan cadence
  • Remediation queue (Pro only)
Get Started Free →
Start Here
Trial
14 days
$0
All features · No credit card

Every feature unlocked for 14 days. See your full identity attack surface before you commit to anything.

  • All 6 identity planes
  • Unlimited identities
  • Full remediation queue
  • AI Agent Identity Governance
  • Daily scans · API access · SSO
Start Free Trial →

Upgrades to Pro after 14 days

Pro
Cancel anytime
$500
platform / mo
+
$69
per subscription / mo

Everything in Trial, continuously. Add or remove subscriptions anytime — pay only for what you connect.

  • Everything in Trial
  • Add / remove subscriptions anytime
  • Continuous daily scanning
  • Priority support + compliance reports
Get Started →

Enterprise IASM platforms typically run $50K–$300K/year with months of onboarding. AuditGraph Pro is purpose-built for mid-market — full identity attack surface coverage, transparent pricing, live in 5 minutes. Questions? Talk to us →

// Get Started

Stop guessing.
Start knowing your exposure.

Connect your Azure tenant or AWS account in 5 minutes. No agents. No log ingestion. No week-long onboarding. First findings appear immediately.

Start Free Trial — No credit card ↗ Talk to the Team

Free forever · 14-day full trial · $500 platform + $69/sub · Cancel anytime · Trust Center →