Home › Posture assessment
Phase 2 · pre-release & on change
A fixed-fee, point-in-time assessment: your repository, your cloud, your stores and your declared intent, read together and compared. 63 checks across the RAG and agent stack — AWS, Google Cloud and self-hosted.
The serious findings live between surfaces — in the code, in the infrastructure, and in facts only your team knows, like which index holds more than one customer’s data. The assessment reads all four and compares them. Where reality disagrees with what you declared, that disagreement is the finding.
| What reads it | Your repository | Your cloud | Your stores | Your declared intent |
|---|---|---|---|---|
| SAST / SCA | ✓ | — | — | — |
| CNAPP / AI-SPM | ✓ | ✓ | ◑ | — |
| Penetration test | ◑ | ◑ | ◑ | ◑ |
| Runtime guardrail | — | — | — | — |
| Skulk assessment | ✓ | ✓ | ✓ | ✓ |
◑ partial — a CNAPP discovers your stores but does not read the query that reaches them; a pen test sees everything it is given, for a week, and records none of it.
An engagement can stop at any rung. Nothing below the rung you grant is ever presented as assessed — it is named on the coverage ledger instead.
The report is the deliverable — not a dashboard, not a subscription. Every finding carries a file and line, a traced graph path, or a named configuration field. If it cannot be shown, it is not reported: there is no “potential issue” category.
An anonymized end-to-end sample — a fictional company, real check output — showing the finding format, the evidence lines and the coverage ledger exactly as they appear in a live engagement.
Anything unreadable or out of reach lands on the coverage ledger. Nothing unread is ever presented as clean.