Skip to main content10ETLabsRequest demo

How it works

You keep the role. We map what it can list.

This page is the operating sequence — not the module catalog and not the trust inventory. The homepage animation is the story; this is what actually runs after you click Verify.

Architecture · data flow

01Your clouds, your role

Deploy the onboarding template: a reader role on AWS, Azure, or GCP, a list-only ClusterRole on Kubernetes, or an API token on a VPS. You keep the identity and can revoke it any time.

Sample findings. Scores follow the 10ET Score formula: severity base plus exposure, admin privilege, and data or AI weight.

  1. 01

    You keep the identity

    Deploy the onboarding template in your account: CloudFormation, ARM, Terraform, a Kubernetes ClusterRole, or a VPS token. 10ETLabs assumes that identity. We do not ask for a break-glass user.

  2. 02

    Verify before Assess

    Verify proves the role can list. Assess is the job that inventories and writes findings. You choose when a scan runs — including an optional daily or weekly schedule.

  3. 03

    Workers map the control plane

    Scan jobs run on workers that scale independently. They list APIs the role allows, upsert assets by native ID, and emit posture findings. Optional Prowler on AWS merges into the same queue when enabled.

  4. 04

    10ET Score ranks findings

    10ET Score uses exposure, privilege, and whether the asset is data or AI. It ranks individual findings. We do not invent a reachability path from inventory list order.

  5. 05

    People work the queue

    Security triages. Platform owns connections. Compliance exports CSV from the same findings. Assign, ticket to Jira or ServiceNow, or ask 10ET about this tenant — guidance only.

  6. 06

    Nothing mutates the estate

    Logout revokes refresh. Support impersonation is VIEWER and MFA-stepped. v1 never patches a security group or pushes IAM from 10ETLabs.

After the first Assess

What a finding is

A rule, a resource, a severity, a 10ET Score, and remediation text. Status is OPEN until someone on your tenant resolves or suppresses it.

What a path is

A chain of links we read from your cloud. Today paths cover AI workloads on AWS (SageMaker notebooks and endpoints, Bedrock custom models, agents, and knowledge bases), Azure (Azure ML and AI Foundry endpoints, models, training jobs, data connections, and compute instances) and Google Cloud (Vertex AI models, training and tuning jobs, Vector Search, RAG corpora, Agent Engine, and Workbench), plus Lambda URLs with no auth. Elsewhere Attack paths stays empty — we will not invent a hop list from unrelated public, admin, and data assets.

What a framework score is

PASS and FAIL only, from implemented rules that a connected provider can emit. Unimplemented mappings stay Not assessed — never 100%. Not an annual attestation PDF.

Reader permissions are on Cloud access. What we persist is on Trust.

Walk through Verify on your accounts

Bring a reader role. We will not ask for write.