See who has access to your cloud, and what they could reach.
A low friction, read only scan of the permissions layer. One click install, no agents, no contract required to see the findings.

An identity scan, not another vulnerability scanner
We do not replace your CVE scanner and we are not a CSPM. Avistar reads the permissions layer: who and what holds standing access, how far that access reaches, and where it should be cut back. Enterprise CNAPP pricing for a mid market identity problem is why most teams never solve this. We priced and scoped it for the way real environments get assessed.
What we look at
Identity classification, wildcard access, privilege escalation paths, missing MFA on service accounts, evidence at the policy level.
What we are not
Not a CVE scanner. Not a CSPM. Not a SIEM. Deeper than a general maturity assessment, narrower than a CNAPP.

The Most Dangerous AI Looks Exactly Like The One You Trust
Read the article on Forbes
Built by people who have shipped identity and infrastructure work inside teams from
Built for the team that owns the risk and the partner that fixes it
For security teams
Replace the spreadsheet of service accounts with a continuously updated inventory, ranked by what each credential can actually reach, and mapped to the controls you already report against. Many teams run cloud on a single point of failure: one person who knows the account. The scan makes that knowledge shared.
Explore the platformFor MSPs & MSSPs
Low friction pre sales awareness: a read only scan gets you into a prospect's environment before a contract exists. Multi tenant from day one, per tenant pricing, one pane of glass across client accounts, and human in the loop remediation so the billable work stays yours. Roll the cost into the scope of work.
See the channel modelDiscover, attribute, score, remediate, continuously
Point in time audits describe the cloud you had last quarter. Avistar reruns the loop as the environment changes, so new, drifting, and orphaned credentials surface as they appear.
Discover
Attribute
Score
Remediate

Inventory with enough context to act on
Low friction install
One click CloudFormation in AWS and read only roles in Azure and GCP. No agents, no sidecars, no production change window.
Ownership attribution
Owner, workload, and last activity on every credential give the context that turns a list into a work queue.
Blast radius scoring
Risk ranked by reachable resources and privilege, not by raw finding count.
Control mapping
Findings map to ISO 27001, SOC 2, NIST, FedRAMP, and HIPAA controls so evidence is a byproduct of the work.
Written for the engineer and for the person who signs off
The same findings render two ways, so the technical review and the board or audit conversation run off one source.
For cloud and security engineers
Identity classification, wildcard access, privilege escalation paths, missing MFA on service accounts, and evidence at the policy level. Export through API or MCP into whatever you already run.
For executive and compliance stakeholders
Who has standing access to your cloud, and what could they reach. Findings land in the control language you already report in: CIS, FedRAMP, HIPAA, ISO 27001, NIST, and SOC 2.
The identities that never show up in an access review
Orphaned credentials
Keys and service accounts with no owner and no recent activity, still holding live permissions.
Over privileged service accounts
Standing privilege far beyond what the workload has ever used.
AI agent sprawl
Agents and automations provisioning their own access outside the identity review cycle.
Rotation hygiene
Long lived secrets tracked against policy, with rotation driven from the findings themselves.

Where machine identity gaps cost the most
The same inventory, mapped to the control language each sector reports in.
Machine identity questions, answered
The questions security teams and partners ask before the first assessment.
See every machine identity in your cloud
Book a walkthrough, or start with a single client gap assessment: agentless, read only, no commitment.