Platform

Prove who can move the money.

MoveProof maps the attacker's path to your money: it reads the systems that decide authority, models who can reach what, and proves which of those routes actually end in value leaving. You get a short ranked list of real paths and the smallest change that closes each one.

Capabilities

What the platform does.

01

One authority model

Identity, cloud, code, policy, approver and money system, read into a single model. Not six consoles reviewed separately once a quarter.

02

Paths, not misconfigurations

We look for sequences that end in value leaving. A setting nobody can reach is not a finding, and it does not appear on your list.

03

Proven, not flagged

Every candidate route is executed against a copy of your own state. What survives is a finding. What dies is never shown to you.

04

The effective human count

How many people actually stand in the way once groups, delegation, break-glass and automation are resolved. It is often lower than the policy says.

05

A fix per system

The smallest change that closes the path, written for the system that owns it - an IAM policy, a custody rule, a branch protection, a contract role.

06

Re-verified on every change

A new role, a redeployed signer or a shipped fix starts a new pass. A finding is closed only when the route is run again and fails.

What you connect

Read-only, across six layers.

We read the configuration that defines authority. We never hold a key, a signer, or any credential that can move value. For a bank the boxes change name - core banking, treasury, payment rail, approver - and the graph is identical.

Identity

Who can become who

Okta · Entra ID · Google Workspace

Cloud

Where the keys live

AWS · GCP · Azure · KMS

Code

How code reaches production

GitHub · GitLab · CI/CD

Policy

What is allowed to move

MPC and HSM policy exports

Approver

What authorizes movement

Signer sets · quorums · co-signers

Money system

Wallet · vault · treasury · account

Contract roles · multisig · timelocks

Connectors are read-only by construction. There is no mode in which MoveProof can sign or transfer.

Deployment

Four steps. Then it never stops.

Configuration drift does not keep a schedule, so neither do we. Every change to your environment starts a new pass, and a fix is only closed when the route is re-run and fails.

Any of these starts a runa new IAM role a changed custody rulea redeployed co-signer a fix we just shipped
1

Connect, read-only

Identity, cloud, code, custody policy and chain roles. Nothing that can sign. Nothing that can transfer.

2

We map who can reach the money

Every layer in one model, not six consoles checked separately.

3

We prove it, we do not flag it

Each candidate route is proven safely against a copy of your own state. Never production.

4

You get the smallest fix

Ranked by money at risk, with the exact change that closes the path - and it re-runs on every change after that.

Detection, remediation and a verified fix in one pass.
What you receive

Ranked by money at risk.

Not a list of misconfigurations. A list of routes, each proven, ordered by what can leave and how many humans could stop it. Each one lands as an alert the day the path appears - with the fix attached - not as a block when the money is already moving.

SevPathStarts atHumansValue at risk
CRITci-deploy → svc-trading → policy #3 → MPC → outaws / iam role0$33,261,897
CRITgh-maintainer → callback code → co-signer → outgithub / repo0unbounded
HIGHidp-admin → MFA reset → console → whitelistokta / admin1$12,400,000
HIGH2 approvers, 1 IdP administratorokta / group1$88,200,000
MEDwhitelist entry added by a departed employeecustody / wl[7]––
2 of these 5 have nobody in the way.

Humans is the only column that has to be above zero. We alert on the path before a transaction exists - we do not block one in flight. One modeled company.

How we handle access

A security company should be auditable first.

Access

Read-only, always

We read configuration. We never hold a key, a signer, or any credential that can move value.

Execution

Never production

Candidate routes are proven against a copy of your own state. Nothing we run touches a live system.

Data

Scoped and returnable

Configuration only, scoped to what a finding needs, and returned or destroyed on request.

Find out how many humans stand between one account and your treasury.