Skip to content

Capability

CNAPP / CSPM

Follow an identity and permission path to the reachable assets and data, compute the blast radius, identify the smallest access-edge cut set, and attach the remediation to the existing FAIR financial-impact spine.

Design partnerPublic capability

What Valty does

Cloud findings, IaC and Kubernetes posture, identity and permission paths, CIEM blast radius, minimal cut sets, remediation proof, and cloud-to-dollar risk. Valty turns this domain's signals into priced, proof-backed risk you can act on.

Where the boundary sits

Design-partner engine. Incomplete identity or permission data is degraded, never assumed safe; native enforcement remains customer-owned.

Best next step for Cloud security, CISO: choose “See how this attaches to CRQ” to review the workflow, evidence boundary, and fit for your environment.

CNAPP / CSPM product surface
CNAPP / CSPMIdentity-path provenance, reachable asset and data set, minimal remediation cut set, cloud finding evidence card, and FAIR impact traceOpen full-size product view ↗

CIEM blast radius

Follow the identity path to the smallest cut that changes financial exposure.

Valty carries identity and permission paths across the unified evidence graph, identifies the reachable assets and data, and ties the smallest remediation cut set to the FAIR impact already on the graph.

Path

Identity and permission edges keep provenance

Each accepted path retains its source and confidence so a reviewer can inspect how the principal reaches the resource.

Radius

Blast radius names reachable assets, identities, and data

The impact set stays machine-checkable rather than collapsing into a generic criticality label.

Cut set

The smallest remediation set breaks the priced path

Valty ranks the access edges whose removal severs the origin from the financially anchored assets.

Impact

FAIR impact reuses the existing dollar spine

The graph attaches to recorded financial exposure and does not invent a second, disconnected risk score.

Identity path

Every access edge stays attached to the cut set.
1 cut / 3 paths
01PrincipalOrigin
02RoleInherited
03ResourceReachable
04CutSmallest set
Graph rule

Valty complements the cloud and graph tools already in place. Incomplete identity or permission paths degrade confidence; they never count as safe.

See how exposure reaches dollars

Proof matrix

Capability proof requirements

Every claim shows its source, confidence, and limits, so you can trust the number before you act on it.

ClaimSourceConfidenceFreshness
Capability claimCloud findings, IaC and Kubernetes posture, identity and permission paths, CIEM blast radius, minimal cut sets, remediation proof, and cloud-to-dollar riskDesign partnerPublic capability
Evidence artifactIdentity-path provenance, reachable asset and data set, minimal remediation cut set, cloud finding evidence card, and FAIR impact traceSource-linkedReviewed before publish
BoundaryDesign-partner engine. Incomplete identity or permission data is degraded, never assumed safe; native enforcement remains customer-owned.Claim-reviewedQuarterly or on product change