Prove who can move the money.
MoveProof maps the attacker's path to your money: it reads the systems that decide authority, models who can reach what, and proves which of those routes actually end in value leaving. You get a short ranked list of real paths and the smallest change that closes each one.
What the platform does.
One authority model
Identity, cloud, code, policy, approver and money system, read into a single model. Not six consoles reviewed separately once a quarter.
Paths, not misconfigurations
We look for sequences that end in value leaving. A setting nobody can reach is not a finding, and it does not appear on your list.
Proven, not flagged
Every candidate route is executed against a copy of your own state. What survives is a finding. What dies is never shown to you.
The effective human count
How many people actually stand in the way once groups, delegation, break-glass and automation are resolved. It is often lower than the policy says.
A fix per system
The smallest change that closes the path, written for the system that owns it - an IAM policy, a custody rule, a branch protection, a contract role.
Re-verified on every change
A new role, a redeployed signer or a shipped fix starts a new pass. A finding is closed only when the route is run again and fails.
Read-only, across six layers.
We read the configuration that defines authority. We never hold a key, a signer, or any credential that can move value. For a bank the boxes change name - core banking, treasury, payment rail, approver - and the graph is identical.
Who can become who
Okta · Entra ID · Google Workspace
Where the keys live
AWS · GCP · Azure · KMS
How code reaches production
GitHub · GitLab · CI/CD
What is allowed to move
MPC and HSM policy exports
What authorizes movement
Signer sets · quorums · co-signers
Wallet · vault · treasury · account
Contract roles · multisig · timelocks
Connectors are read-only by construction. There is no mode in which MoveProof can sign or transfer.
Four steps. Then it never stops.
Configuration drift does not keep a schedule, so neither do we. Every change to your environment starts a new pass, and a fix is only closed when the route is re-run and fails.
Connect, read-only
Identity, cloud, code, custody policy and chain roles. Nothing that can sign. Nothing that can transfer.
We map who can reach the money
Every layer in one model, not six consoles checked separately.
We prove it, we do not flag it
Each candidate route is proven safely against a copy of your own state. Never production.
You get the smallest fix
Ranked by money at risk, with the exact change that closes the path - and it re-runs on every change after that.
Ranked by money at risk.
Not a list of misconfigurations. A list of routes, each proven, ordered by what can leave and how many humans could stop it. Each one lands as an alert the day the path appears - with the fix attached - not as a block when the money is already moving.
| Sev | Path | Starts at | Humans | Value at risk |
|---|---|---|---|---|
| CRIT | ci-deploy → svc-trading → policy #3 → MPC → out | aws / iam role | 0 | $33,261,897 |
| CRIT | gh-maintainer → callback code → co-signer → out | github / repo | 0 | unbounded |
| HIGH | idp-admin → MFA reset → console → whitelist | okta / admin | 1 | $12,400,000 |
| HIGH | 2 approvers, 1 IdP administrator | okta / group | 1 | $88,200,000 |
| MED | whitelist entry added by a departed employee | custody / wl[7] | – | – |
Humans is the only column that has to be above zero. We alert on the path before a transaction exists - we do not block one in flight. One modeled company.
A security company should be auditable first.
Read-only, always
We read configuration. We never hold a key, a signer, or any credential that can move value.
Never production
Candidate routes are proven against a copy of your own state. Nothing we run touches a live system.
Scoped and returnable
Configuration only, scoped to what a finding needs, and returned or destroyed on request.