Getting started
Create your organisation, connect a cloud account, and run your first scan.
1. Create your organisation
Register an account, then create an organisation from the dashboard. Every organisation is fully isolated — its own users, connections, findings, and permissions.
2. Connect a cloud account
Go to Integrations and add a connection for AWS, Azure, GCP, or Kubernetes. Each provider has a short setup script (Terraform, or a Helm chart for Kubernetes) that creates a strictly read-only role scoped to exactly what's collected — never the provider's broad built-in "reader" permission.
- Choose a provider and add a connection
- Run the setup script it shows you, in your own account
- Paste the identifier it outputs back into the connection
- Click Validate connection
3. Run your first scan
Click Run scan. Within a few minutes, security findings, compliance status, performance/reliability risks, and cost recommendations appear on the Dashboard. Re-running a scan is safe and idempotent — it updates existing findings and automatically resolves ones for resources that no longer exist or are no longer misconfigured.
4. Choose which compliance frameworks apply to you
Under Administration, turn on only the frameworks relevant to your organisation (ISO 27001, PCI DSS, SOC 2, Cyber Essentials, and others). Nothing is scored against a framework you haven't explicitly enabled.