Every signature was valid.
The money still left.

MoveProof is breach-and-attack simulation for the money layer of regulated finance. We map every path from an identity to your money, prove which ones actually work, and hand you the smallest change that closes them - before anyone tries.

32%of breaches now start with stolen access, not an exploit - attackers log in, they don't hack in. (Verizon 2025)
$5.56Mthe average financial-services breach - the second-costliest sector, and access is the way in. (IBM 2025)
8 daysKiln, Sep 2025: a stolen developer credential quietly held withdrawal authority over customer funds for eight days before $41M moved.

Verizon DBIR 2025, IBM 2025, and public reporting on each incident. See all three

How we're different

We don't stop the transaction.
We remove the path before anyone walks it.

Runtime screening tries to catch a bad transaction in the second it fires - when the money is already moving. We work earlier. We prove the path from an identity to your money exists the day it appears, and hand you the smallest fix to close it while there is still time. In the Kiln incident the attacker held withdrawal authority for eight days before a single dollar left. That is the window we give you back.

No transaction to race. No 3am alert. The route is closed before it is ever walked.
What it does

Six consoles each hold a piece of the answer.
None of them holds the answer.

Your cloud tool knows who can assume a role. Your custody or ledger system knows who can approve a transfer. Nothing joins them, so nobody can tell you whether one compromised account reaches the treasury. That is the question we answer, continuously.

01

One authority model

Identity, cloud, code, policy, approver and money system, read into a single model. Not six consoles reviewed separately once a quarter.

02

Paths, not misconfigurations

We look for sequences that end in value leaving. A setting nobody can reach is not a finding, and it does not appear on your list.

03

Proven, not flagged

Every candidate route is executed against a copy of your own state. What survives is a finding. What dies is never shown to you.

04

The effective human count

How many people actually stand in the way once groups, delegation, break-glass and automation are resolved. It is often lower than the policy says.

05

A fix per system

The smallest change that closes the path, written for the system that owns it - an IAM policy, a custody rule, a branch protection, a contract role.

06

Re-verified on every change

A new role, a redeployed signer or a shipped fix starts a new pass. A finding is closed only when the route is run again and fails.

The output

You give us read-only access. We give you one sentence.

ci-deploy can move $33,261,897 with zero humans in the way.

One modeled company. All 3 values are computed, not estimated.

Every finding is a route someone can actually walk, with the value that can leave at the end of it and the number of people who could stop it. Ranked by money, not by severity score.

Behind it sits the proof: the exact sequence, the systems it crosses, and the run against a copy of your own state that showed it works.

Where the money sits

6 layers. One route to the money.

These are the 6 places an institution's money can be reached. No vendor watches more than two of them. We run the whole row.

01

Identity

who you are

Okta, Entra
02

Cloud

where the keys live

AWS, KMS
03

Code

how code ships

GitHub, CI
04

Policy

what is allowed

custody rules
05

Approver

what authorizes movement

MPC, HSM
06

Money system

wallet · vault · account

contract roles
The route the money takesthe money
Every large crypto loss walked this rail. Not one of them broke a single layer.

How an attacker crosses them

The authority graph

One graph. Every route it can find.

Every identity, role, policy, signer and contract role, held in one model, then searched for the routes that end in money leaving.

MoveProof — Authority Graph Synthetic data 143 nodes · 200 edges · 1 proven route
John Smith okta · identity deploy-svc aws · iam role ci-deploy github · actions custody policy fireblocks · rules Treasury-Hot $33,261,897
Finding · Critical

Vault egress with no human approval

A build identity reaches the treasury through a custody rule that auto-approves egress. Every step is configured correctly. Together they are a route - flagged the day it appears, not the second the money moves.

Effective humans0
Value at risk$33,261,897
Layers crossed5 of 6
Why nobody else answers this

Every category sees one part of the route.

These are all good products and most operators run several. The gap is not quality - it is that each of them is scoped to one layer, and an attacker is not.

ApproachSees identity
and cloud
Sees custody
policy
Sees chainRuns
continuously
Blind spot
Cloud security posture✓———Cloud only
Identity governance✓———Identity only
Custody platform controls—✓✓—Inside one vendor
Contract audit——✓—Point in time
Runtime transaction screening——✓✓Needs a transaction to exist
MoveProof✓✓✓✓The whole path, before a transaction exists

Categories, not products. Most operators run three or more of these already.

Find out how many humans stand between one account and your treasury.