Configuration security · 23 providers

Know what changed.
Know what is exposed.

Your code has Git history. Your production configuration does not. ConfigTrace continuously snapshots cloud, SaaS, identity, and developer infrastructure, detects configuration drift, and surfaces risky current posture — from exposed cloud resources to weakened MFA, privileged identities, dangerous OAuth grants, and policy changes. 23 providers, including AWS, Kubernetes, Okta, Microsoft Entra ID, GitHub, and more.

Connect provider Baseline snapshot Detect drift Alert team Review & remediate

Metadata-only monitoring. No customer data, source code, secret values, payment details, or database rows.

Watch ConfigTrace in 70 seconds

See how ConfigTrace tracks configuration drift, surfaces security posture findings, and connects risk to related activity across cloud, SaaS, and developer infrastructure.

Track what changed. Know the posture. Connect the evidence.

Production-critical settings need a history of changes, a view of risky current states, and a way to connect risk to related activity evidence. ConfigTrace gives you all three, from the same connected providers.

Mode 01

Drift Detection

Track production-critical setting changes across cloud, SaaS, and developer infrastructure. See what changed, when, and why it matters.

  • Stripe webhook URL changed
  • GitHub branch protection changed
  • GitLab protected branch approval removed
  • Cloudflare DNS / WAF changed
  • Terraform Cloud workspace execution mode changed
  • Datadog monitor notification settings changed
Mode 02

Security Posture

Find risky current states from provider configuration metadata before they become operational or security review problems.

  • AWS database port open to the internet
  • Firebase public write rule
  • GitHub webhook using HTTP
  • Clerk multi-factor authentication not enforced
  • PagerDuty escalation policy missing a tier
Drift Snapshots Security Rules Active Posture Findings Activity Ingestion Activity Signals Risk × Activity Correlations Case Builder Evidence Timeline Cross-provider Security Reports Metadata-only · no secret values

ConfigTrace evaluates provider configuration metadata and activity event records. It does not inspect payloads, secret values, variable values, state files, or customer data, and it does not confirm breach, compromise, or data exposure. Activity signals and correlations are risk indicators that may require review — not proof of unauthorized access.

In 3 minutes, you get:
01
A baseline snapshot
Capture your current configuration across cloud, SaaS, identity, and developer infrastructure providers — from AWS and Kubernetes to Okta, Microsoft Entra ID, GitHub, and Terraform Cloud — as your known-good starting point.
02
Scheduled drift detection
ConfigTrace re-syncs connected providers on a schedule and diffs field-by-field against the previous state. Sync Now is always available on demand.
03
A risk-classified timeline
Every change is labelled low, medium, high, or critical based on blast radius — not just whether something moved. Triage at a glance, not after the incident.
04
Alerts, review, and remediation
Slack, email, webhook, and browser push alerts. A Needs Review queue, change rooms, fix plan previews, and admin-gated GitHub draft PRs.
Your code has Git history. Your settings do not.

Production does not only break because code changes. It breaks because someone changed a setting outside Git — in a cloud console, a vendor dashboard, a CLI, or a misconfigured Terraform run. Code reviews don't see it. CI/CD doesn't catch it. Logs only show the symptom.


ConfigTrace gives those changes a timeline, a risk engine, a review workflow, and a remediation path — the same discipline Git gives source code.

  • ×
    AWS security group opened to the internet An inbound rule widened in the console. No ticket, no review, no trail.
  • ×
    Stripe webhook URL silently changed Payment events start routing elsewhere. Reconciliation breaks days later.
  • ×
    GitHub branch protection weakened Required reviewers removed on the production environment. Direct pushes go undetected.
  • ×
    Supabase RLS policy disabled A row-level security policy is dropped. Data exposure found during audit.
  • ×
    Cloudflare WAF rule removed A bot-fight or rate-limit rule gets disabled. Attack surface widens with no signal.
  • ×
    Firebase Firestore rules loosened A rule change makes a collection publicly readable. Discovered days later.
  • ×
    Vercel production branch changed A project's production source branch silently flips. Deployments stop matching main.
  • ×
    Shopify checkout webhook dropped An order-notification endpoint stops delivering. Order pipelines go quietly stale.
  • ×
    GitLab branch protection weakened Required merge request approvals removed from a protected branch. Commits bypass review.
  • ×
    PagerDuty escalation policy changed An escalation step is removed or reordered. On-call engineers miss a critical alert window.
  • ×
    Microsoft Entra Global Administrator assigned A tenant-wide privileged role is granted in the Entra admin center. No ticket, no review, no trail.
  • ×
    Okta sign-on policy stops requiring MFA A policy edit quietly weakens authentication. Discovered only after something goes wrong.

Security lives in configuration.

Not just cloud infrastructure. The controls that decide who gets in, what they can reach, and whether production stays safe live across cloud, identity, application, and delivery-pipeline configuration — outside Git, outside code review.

Cloud exposure

Security groups, firewall rules, storage public access, DNS records, IAM policy bindings, and network posture across AWS, Azure, Google Cloud, and Cloudflare.

Identity & privilege

Global Administrators, privileged groups, directory roles, service principals, OAuth consent, and admin-role assignments across Entra ID, Okta, and Auth0.

Authentication

MFA requirements, Conditional Access policies, authentication strengths, sign-on policy, and authenticator configuration across Entra ID, Okta, Auth0, and Clerk.

Application & workload security

Redirect URIs, enterprise app assignments, Graph application permissions, OAuth grants, and Kubernetes workload privilege, RBAC, and network exposure.

Delivery pipeline

Branch protection, deployment protection rules, CI/CD variable posture, webhook configuration, and production-branch settings across GitHub, GitLab, and Terraform Cloud.

Reliability controls

Alert routing, escalation policies, webhook delivery configuration, monitor notification settings, and run-trigger posture across PagerDuty, Datadog, and Terraform Cloud.

Track privilege before it becomes invisible.

Kubernetes, Okta, and Microsoft Entra ID materially changed what ConfigTrace watches. Identity is now a first-class configuration surface, not an afterthought — because the fastest way into a system is rarely a code vulnerability. It's a Global Administrator role that got assigned quietly, a sign-on policy that stopped requiring MFA, or an OAuth grant nobody reviewed.


ConfigTrace tracks configuration-level changes to privilege and authentication posture — configuration evidence, not breach detection. It tells you what changed and what is currently exposed, not that an account was compromised.

  • Global Administrator / privileged directory role assignment
  • Privileged group and service-principal membership
  • Okta administrator role assignment
  • High-risk Microsoft Graph application permissions and OAuth consent
  • MFA / sign-on policy weakening
  • Conditional Access policy changes
  • Authentication method and authentication strength posture
SECURITY FINDING Microsoft Entra ID · synthetic example
Critical
EN
Microsoft Entra ID Global Administrator privilege assigned
Identity: engineer@example.com · Source: direct role assignment · Tier: critical. This identity currently holds Global Administrator privilege.
High
OK
Okta Sign-on policy · MFA requirement removed
This policy currently allows access without a second factor.
A Security Finding describes risky configuration posture that exists right now — not proof of compromise or unauthorized access. It is a signal to review, not a confirmed incident.

Detect. Explain. Alert. Review. Remediate. Prove trust.

ConfigTrace is a closed loop across the lifecycle of a risky configuration change — from the moment it happens, to the moment it's reviewed, fixed, and explained back to your team and customers.

01 · DETECT
Detect drift
  • 23 provider integrations
  • Scheduled background sync
  • Baseline snapshots per provider
  • Field-level diff vs. last known state
  • Activity event ingestion per provider
02 · EXPLAIN
Explain impact
  • Risk classification (low → critical)
  • Blast radius view
  • Activity signals tied to risk findings
  • Risk × activity correlations
  • Plain-English "why this matters"
03 · ALERT
Alert the team
  • Email digests of high & critical drift
  • Slack App with interactive buttons
  • Generic webhooks for any system
  • Browser / PWA push notifications
  • Routing per workspace and severity
04 · REVIEW
Review safely
  • Needs Review queue
  • Acknowledge, snooze, or escalate
  • Incident-style change rooms
  • Notes & activity log per change
  • Expected change windows for noise control
05 · REMEDIATE
Remediate with review
  • Plain-English remediation guidance
  • Fix plan preview
  • Dry-run remediation preview
  • Terraform fix suggestion preview (IaC mapping)
  • Admin-gated, review-first GitHub draft PRs
06 · PROVE TRUST
Prove trust
  • Case builder with evidence timeline & graph
  • Provider Trust Center per workspace
  • Security packet export
  • Drift Control Score
  • Policy engine & approval workflows

From "something changed" to exactly what.

Without a security timeline, a production incident starts with a question nobody can answer. With one, the answer is already there.

Before · Without ConfigTrace

"Prod is degraded. Did code ship? Did DNS change? Did someone touch Cloudflare or Stripe? Was a webhook moved? Who has access? When did it happen?"

Incident open · root cause unknown · multiple consoles to check
After · With ConfigTrace
May 27, 2026 · 09:42 UTC — Sync #184
AWS SecurityGroup sg-prod-web · ingress 22/tcp Critical
− ip_ranges: ["10.0.0.0/8"] + ip_ranges: ["0.0.0.0/0"]
SSH widened to the public internet. Detected, classified, routed to Slack and email, queued for review.

A change tells you what moved. A finding tells you what's risky right now.

ConfigTrace tracks both, because they answer different questions. A Change gives you chronology — exactly what was modified, when. A Security Finding gives you current posture — what configuration state exists right now that needs review, regardless of when it happened.

Change · What moved

MFA requirement changed from required to not required on the Okta sign-on policy "Default".

Field-level diff · timestamped · attributable to a sync
Security Finding · What's risky now
Okta Sign-on policy "Default" High
This policy currently allows access without a second factor — independent of when the change happened or whether it was reviewed.

A second example: a Change records that a Global Administrator role was assigned to an identity. The corresponding Security Finding is that this identity currently holds Global Administrator privilege — and stays open until the role is removed, independent of how long ago it was granted. Both matter: one gives you the timeline, the other gives you today's exposure.

23 providers. Configuration, posture, and identity across cloud, SaaS, identity, and developer infrastructure.

Every sync is diffed field-by-field against the last known state — so you see exactly what changed, not just that something did. ConfigTrace reads configuration metadata only. No secret values, no variable values, no state files, no database rows.

Cloud & Infrastructure
AW
AWS
Live
Connect with an IAM user or role scoped to read-only access. ConfigTrace monitors the security configuration that controls who can reach your infrastructure.
Monitors
  • EC2 security group inbound / outbound rules
  • IAM policy documents and attached policies
  • Route 53 DNS record sets
  • S3 bucket policies and public access settings
AZ
Azure
Live
Connect with an Azure service principal scoped to Reader access. ConfigTrace monitors the resource configuration that governs your Azure infrastructure security posture.
Monitors
  • IAM role assignments and resource-level access control
  • Network security group rules and open ports
  • Key Vault access policies and settings
  • Storage account public access configuration
GC
Google Cloud
Live
Connect with a Google Cloud service account with read-only IAM permissions. ConfigTrace monitors the security and network configuration of your GCP resources.
Monitors
  • IAM policy bindings and service account permissions
  • VPC firewall rules and network posture
  • Cloud Storage bucket IAM and public access settings
  • Project-level security and API configuration
KB
Kubernetes
Live
Connect a cluster with a read-only kubeconfig. ConfigTrace monitors workload security, RBAC, network exposure, admission policy, and cluster configuration drift.
Monitors
  • Workload security context and privileged / host-access posture
  • RBAC: Roles, ClusterRoles, bindings, and service accounts
  • Services, Ingress, Gateway API exposure, and NetworkPolicy coverage
  • Admission policy, namespaces, and resource quotas
CF
Cloudflare
Live
Connect a zone with a scoped API token. ConfigTrace monitors every DNS record and WAF rule — any reroute, deletion, or weakened rule is detected and risk-classified.
Monitors
  • A, AAAA, CNAME, MX, TXT, NS records
  • TTL and Cloudflare proxy status per record
  • WAF rules and firewall settings
  • SRV, CAA, and other record types
VC
Vercel
Live
Connect with a Vercel API token. ConfigTrace monitors the project settings and deployment configuration your production builds depend on.
Monitors
  • Environment variable names and targets
  • Deploy hooks and production branch
  • Project settings and framework config
  • Custom domains and deployment protection
Identity & Access
OK
Okta
Live
Connect an Okta org with a read-only API token. ConfigTrace monitors identity lifecycle, administrator privilege, authentication policy, applications, and SSO posture.
Monitors
  • Users, groups, and group membership lifecycle status
  • Applications, app assignments, and SSO configuration (OIDC / SAML)
  • Sign-on policy, MFA, and authenticator configuration
  • Administrator role assignments and privileged group posture
EN
Microsoft Entra ID
Live
Connect a tenant with app-only Microsoft Graph access. ConfigTrace monitors identity lifecycle, privileged access, applications, Conditional Access, authentication methods, and OAuth consent. A separate integration from Azure — this covers identity, not infrastructure.
Monitors
  • Users, groups, applications, and service principals
  • Graph application permissions and OAuth2 delegated grants
  • Conditional Access, authentication strengths, and auth methods
  • Directory roles and privileged identity / group posture
A0
Auth0
Live
Connect an Auth0 tenant. ConfigTrace monitors the authentication settings and application posture that control how your users sign in and what access they receive.
Monitors
  • Application settings and grant types
  • Connection configuration and allowed providers
  • Security policies and attack protection settings
  • Tenant settings and branding posture
CK
Clerk
Live
Connect a Clerk application. ConfigTrace tracks authentication configuration drift and surfaces risky auth posture across sign-in flows, session settings, and OAuth connections.
Monitors
  • Sign-in and sign-up configuration
  • Session settings and multi-factor authentication posture
  • OAuth connection configuration and allowed providers
  • Domain and production instance settings
Developer Platforms
GH
GitHub
Live
Connect a repository with a personal access token or GitHub App. ConfigTrace monitors settings that are invisible to Git — not code, but the rules that govern your repo.
Monitors
  • Branch protection rules and required checks
  • Environment protection rules and reviewers
  • Webhooks, secret names, and variables
  • Deploy keys and Actions permissions
GL
GitLab
Live
Connect a GitLab group or project. ConfigTrace tracks branch protection, webhook posture, CI/CD variable configuration, and deploy key visibility — the settings that govern your code and delivery pipeline.
Monitors
  • Branch protection and merge request approval posture
  • Webhooks and CI/CD variable posture (presence, not values)
  • Deploy keys, runners, and project/group visibility
  • Cross-cloud security posture and activity signals
TF
Terraform Cloud
Live
Connect a Terraform Cloud organization. ConfigTrace monitors workspace and policy configuration, variable set posture, and run trigger settings. Does not read variable values or state files.
Monitors
  • Workspace settings, team access, and run trigger configuration
  • Variable sets and policy set posture (names, not values)
  • Notification configuration and state-version metadata
  • Organization-level settings and team access summaries
JR
Jira
Live
Connect a Jira Cloud site. ConfigTrace tracks project configuration, workflow changes, and webhook posture — the settings your delivery pipeline and integrations depend on.
Monitors
  • Project settings and workflow configuration
  • Issue type and screen scheme posture
  • Webhook and automation endpoint configuration
  • Site-level settings and user access posture
LN
Linear
Live
Connect a Linear workspace. ConfigTrace monitors the workflow and team configuration that governs how your engineering organization tracks and routes work.
Monitors
  • Team settings and workflow state configuration
  • Webhook and integration endpoint posture
  • Label and priority configuration
  • Workspace settings and member access posture
Data & Backend
FB
Firebase
Live
Connect a Firebase project with a service account. ConfigTrace tracks the security rules and project settings that control who can read and write your data.
Monitors
  • Firestore security rules
  • Firebase Storage rules
  • Realtime Database rules
  • Project settings and OAuth providers
SB
Supabase
Live
Connect with your Supabase management API key. ConfigTrace tracks the policies that control database access and authentication behavior.
Monitors
  • Row-level security (RLS) policies per table
  • Auth configuration and JWT settings
  • API settings and CORS configuration
  • Project access and database settings
SH
Shopify
Live
Connect with a Shopify API access token. ConfigTrace monitors the webhook configuration and shop settings your order and payment flows depend on.
Monitors
  • Webhook endpoints and subscribed topics
  • Checkout and shop settings
  • Payment gateway configuration metadata
ST
Stripe
Live
Connect with a restricted API key. ConfigTrace monitors the webhook endpoints and product settings your payment flow depends on.
Monitors
  • Webhook endpoint URLs, status, and events
  • Product and price configuration
  • API key metadata (presence, not values)
  • Account and branding settings
Observability & Incident Response
DD
Datadog
Live
Connect a Datadog organization. ConfigTrace monitors monitor configuration, notification integrations, and organization settings — the posture that determines when and how your team is alerted.
Monitors
  • Monitor settings and alert thresholds
  • Webhook and notification integrations
  • API key metadata (presence, not values)
  • Organization settings and user access posture
PD
PagerDuty
Live
Connect a PagerDuty account. ConfigTrace tracks escalation policy and service configuration drift — so a removed escalation step or silenced service doesn't go undetected.
Monitors
  • Service configuration and escalation policies
  • Webhook and integration endpoint posture
  • On-call schedule and routing settings
  • Account-level settings and user access posture
Business & Communications
TW
Twilio
Live
Connect a Twilio account. ConfigTrace monitors the phone number and messaging configuration that controls your communications delivery and routing.
Monitors
  • Phone number configuration and capabilities
  • Messaging service settings and webhook endpoints
  • API key metadata (presence, not values)
  • Account and subaccount settings
SG
SendGrid
Live
Connect a SendGrid account. ConfigTrace monitors sender identity, domain authentication, and API configuration — the settings your email delivery depends on.
Monitors
  • Sender identity and domain authentication posture
  • API key metadata (presence, not values)
  • IP pool and dedicated IP settings
  • Inbound parse webhook configuration
Public demo · no signup

Try the public demo risk timeline.

A synthetic timeline showing risky drift across cloud, SaaS, identity, and developer infrastructure providers — exactly as it appears inside ConfigTrace. Field-level diffs, risk classification, and a clear next step.

23 providers · synthetic data · no account required

Get the change in the room where decisions happen.

ConfigTrace routes risky drift to the channels your team already uses — Slack, email, webhooks, and browser push — with the context needed to triage and review. Buttons trigger review actions, not provider mutations.

# infra-alerts
CT
ConfigTrace APP
09:43 UTC · Sync #184
⚠ Critical · AWS · SecurityGroup sg-prod-web
resource ingress 22/tcp
− ip_ranges: ["10.0.0.0/8"] + ip_ranges: ["0.0.0.0/0"] blast radius every EC2 instance attached to this group
Open change Acknowledge Snooze 24h View remediation

Slack buttons drive review actions inside ConfigTrace — open change, acknowledge, snooze, view remediation. They do not mutate provider resources or apply infrastructure changes.

SL
Slack App
Install the ConfigTrace Slack App. High and critical drift posts with field-level context and interactive buttons for Open Change, Acknowledge, Snooze 24h, and View Remediation.
EM
Email digests
A per-sync digest of high and critical changes lands in the inbox of every workspace member — with links to the timeline and Needs Review queue.
WH
Webhooks
Subscribe a generic webhook to receive signed JSON payloads for every detected change. Forward into your own runbooks, ticketing systems, or SIEM.
PN
Browser / PWA push
Opt-in browser push notifications via the ConfigTrace PWA — for on-call engineers who want a fast desktop signal alongside Slack and email.

From risky drift to reviewed fix.

Every risky change comes with a remediation path — guidance, a fix plan, a dry-run preview, and where Terraform mappings exist, a draft GitHub pull request. Every mutation is review-first and admin-gated.

01
Suggested remediation

Each high or critical change ships with plain-English guidance on how to bring it back to a safe state — written for the on-call engineer, not just the cloud expert.

02
Fix plan preview

A structured plan of the exact steps that would restore the previous configuration — shown before anything runs, so a reviewer can sanity-check the intent.

03
Dry-run remediation preview

A read-only preview of what the fix would change, formatted as a diff against the current live state — no API mutations, no writes against provider resources.

04
Terraform fix suggestion preview

Where ConfigTrace can map a drifted resource to your IaC repo, you'll see the proposed HCL diff inline — surfaced as a suggestion, not an applied change.

05
Guarded GitHub draft PR

An admin can open a GitHub draft PR with the fix proposal as a patch file — explicit confirmation required, admin-gated, low- confidence mappings blocked, review-first by design.

PREVIEW aws/security_groups.tf · suggested fix
 resource "aws_security_group_rule" "ssh" {
   type = "ingress"
   from_port = 22
   to_port = 22
   protocol = "tcp"
  cidr_blocks = ["0.0.0.0/0"]
+  cidr_blocks = ["10.0.0.0/8"]
 }
ConfigTrace never runs Terraform and never mutates provider resources. Draft PRs are opened only when an admin explicitly confirms, the IaC mapping is high-confidence, and the change is review-first by design.
Open GitHub draft PR · admin-gated · review-first requires explicit confirmation

Turn noisy drift into governed review.

Drift detection alone isn't a workflow. ConfigTrace adds the structure around it — policies, windows, scoring, digests, and change rooms — so security work doesn't drown in alert fatigue.

Policy engine

Define rules for what counts as risky in your workspace — by provider, resource type, or field. Treat the same change differently in staging versus production.

Expected change windows

Mark planned maintenance windows so expected drift during a deploy or migration is suppressed from the alert path while still being recorded in the timeline.

Drift Control Score

A single workspace-level score that tracks how much risky drift goes unreviewed and how fast critical changes get triaged. A signal you can show leadership and customers.

Weekly security digest

A per-workspace weekly summary of drift, reviewed changes, outstanding critical items, and Drift Control Score trend — for the whole team and for security stakeholders.

Incident-style change rooms

For high-impact drift, ConfigTrace opens a change room — a dedicated page with the diff, blast radius, remediation path, notes, and full activity log for the whole team.

Needs Review queue

High and critical changes land in a single Needs Review queue with acknowledge, snooze, and escalate actions — and an audit trail of who reviewed what, when.

Missing data never becomes a fake deletion.

APIs fail. Permissions vary. Pagination truncates. Providers rate-limit mid-sync. A denied endpoint or a partial response shouldn't make hundreds of resources look deleted. ConfigTrace tracks how completely each sync actually collected data and suppresses false-removal noise when a provider family can't be fully read.

Family-level completeness

Each resource family (RBAC, networking, applications, and so on) is tracked separately for how completely it was collected on a given sync.

Per-resource collection status

ConfigTrace knows the difference between "this resource is gone" and "this sync couldn't confirm it" — and treats them differently.

Bounded retry & rate-limit handling

Transient failures and rate limits are retried within bounds rather than silently treated as authoritative results.

False-removal suppression

When a sync only partially succeeds, ConfigTrace suppresses "removed" findings for the affected family instead of reporting a wave of fake deletions.

Stable resource identities

Resources are matched across syncs by stable identifiers, not positional order — so a reordered API response doesn't look like drift.

Metadata-only collection

Smaller, narrower payloads by design — configuration and posture fields only, which keeps every sync faster and less exposed to partial-failure modes.

Not all changes are equal.

ConfigTrace weighs each detected change by its potential blast radius so your team can triage at a glance — not after the incident is already in progress.

Low
Domain verification TXT added
Vercel preview variable added
Stripe product description updated
Hardening, ownership proof, or non-sensitive addition. No routing or security impact expected.
Medium
New subdomain CNAME created
IAM policy attached to role
Firebase auth provider enabled
Expanded access surface or altered routing. Worth a closer look before it causes issues.
High
Stripe webhook endpoint changed
Supabase RLS policy modified
GitHub environment protection weakened
Production traffic, data access, or release controls may be affected. Needs prompt review.
Critical
AWS security group opened to 0.0.0.0/0
Firestore rules allow all reads
Root DNS record deleted
Infrastructure may be exposed, data potentially public, or the site may be offline. Act immediately.

What teams catch with ConfigTrace.

Concrete configuration changes ConfigTrace is built to detect and classify — not hypothetical incidents.

Entra ID

A Global Administrator role is assigned to an identity outside the normal access-request process.

Okta

A sign-on policy stops requiring MFA, weakening authentication for everyone it applies to.

Kubernetes

A workload's security context changes to privileged, or gains host networking access.

AWS

A security group opens SSH or a database port to 0.0.0.0/0.

GitHub

A production environment's required-reviewers protection is removed.

Entra ID

A high-risk Microsoft Graph application permission is granted to a service principal.

Cloudflare

A WAF rule protecting a production zone is disabled.

Auth0 / Clerk

An application's allowed OAuth redirect URIs change to include an unexpected wildcard.

Built for security review.

ConfigTrace is designed to support security review — both internal and with your customers. Configuration metadata in. No customer data, secret values, source code, payment details, or database rows out.

ConfigTrace never reads
  • × Customer data of any kind
  • × Secret values (only their names / presence)
  • × CI/CD variable values
  • × Terraform state files or variable values
  • × Source code or commit contents
  • × Payment details, charges, or transactions
  • × Database rows or query results
  • × Webhook URLs or shared secrets
  • × Logs, traces, or runtime telemetry
  • × File contents in object storage
  • × Passwords, MFA/OTP secrets, or session tokens
  • × Kubernetes Secret or ConfigMap contents
Encrypted credentials

ConfigTrace stores the minimum encrypted connector credentials needed to read provider configuration — never shown again after creation. That's a necessary part of running a read-only integration; what it does not do is ingest or snapshot secret values, session tokens, or MFA/OTP seeds from the monitored provider itself. Read-only or least-privilege scopes are recommended for every integration.

Revoke anytime

Disconnect a provider from inside ConfigTrace in one click, or rotate / revoke the credential from the provider side. ConfigTrace stops reading immediately.

Provider Trust Center

A per-workspace Trust Center page lists every connected provider, the exact scopes used, what ConfigTrace reads, and what it never reads — built to show to a reviewer.

Security packet export

Export a security packet describing data access boundaries, encryption posture, and audit history. Use it for internal review or customer trust conversations.

Workspace audit log

Every team action — invites, role changes, integrations, acknowledgements, draft PR creation — is recorded with actor, timestamp, and target.

What ConfigTrace is — and isn't.

Production drift sits in a gap between existing tools. ConfigTrace fills that gap — without trying to replace the systems your team already uses.

vs. Cloud provider logs
CloudTrail, Cloudflare Audit Logs, GitHub audit logs — each shows events within one provider, in vendor-specific schemas, with no cross-tool view.
ConfigTrace unifies drift, posture, and identity/access risk across 23 providers — cloud, SaaS, identity, and developer infrastructure — in one risk-classified timeline.
vs. Git
Git tracks the code in your repository. It has no idea who flipped a Stripe webhook, removed an RLS policy, or opened an AWS security group in a console.
ConfigTrace tracks the risky settings that live outside Git, with the same review discipline pull requests give to code.
vs. Uptime & APM monitoring
Uptime checks and APM tools tell you something is broken or slow. They don't tell you what changed in your configuration that caused it.
ConfigTrace explains why production may have broken — which setting moved, when, by whom-shaped events, and what the blast radius looks like.
vs. CSPM tools
Cloud security posture management focuses on cloud infrastructure posture. It typically doesn't cover SaaS tools like Stripe, GitHub, Vercel, or Shopify.
ConfigTrace covers configuration drift across cloud, SaaS, and developer infrastructure — including GitHub, GitLab, Terraform Cloud, Jira, Datadog, and more — in the workflow surfaces engineers actually use.
vs. IAM / IGA platforms
Identity governance tools manage who should have access. They typically don't tell you when a Conditional Access policy, sign-on rule, or Graph app permission actually changed.
ConfigTrace tracks identity and authentication configuration drift across Entra ID and Okta alongside your cloud and SaaS providers — one timeline, not a separate identity console.

The moment ConfigTrace pays for itself.

It is not when everything is working. It is when production breaks and your team needs the answer to one question: what changed?

Without ConfigTrace

Three consoles. Three engineers. Zero answers.

On-call digs through AWS, Cloudflare, Stripe, GitHub, Vercel, and Slack — trying to reconstruct whether it was a security group, a DNS reroute, a deleted webhook, or a weakened Firestore rule. The clock keeps running.

With ConfigTrace

A timestamped record. Already in Slack.

The exact change — record, old value, new value, risk label — arrives in Slack and email within minutes of the next sync.

The result

Less guessing. Cleaner reviews.

Faster root cause. A clear record for the next incident review. A trail your customers and security reviewers can see.

  • Root cause in seconds, not hours
  • Clear answer for the incident timeline
  • History for the next time it happens

Why I'm building ConfigTrace.

A note from the founder.

Builder's note

"I'm building ConfigTrace because production systems now depend on dozens of dashboards, not just code. GitHub tells you what changed in the repo. It does not tell you who changed a DNS record, webhook URL, branch protection rule, OAuth callback, RLS policy, or cloud permission.

Your code has Git history. Your production settings do not. ConfigTrace is my attempt to give those settings the same discipline code gets from Git — a security timeline with diffs, risk classification, a review workflow, and a remediation path that stays review-first."

RS
Rohan Shah
UMass Amherst Computer Science student and founder of ConfigTrace

Configuration changes whether you review them or not.

Give production settings a history. View the public demo to see ConfigTrace in action with synthetic data, or connect your first provider and capture a baseline before the next risky change happens.

23 providers · metadata-only monitoring · admin-gated remediation