AWS security group may expose SSH to the internet
0.0.0.0/0 on port 22.
Production does not only break because code changes. It breaks because settings drift outside Git — and nobody notices until an incident is already in progress. Explore a realistic ConfigTrace security timeline across all 7 providers. No login required.
Demo data only. No customer data is shown.
8 realistic examples of configuration drift across all 7 providers. Each finding includes a field-level diff, a risk classification, and a clear recommended next step.
0.0.0.0/0 on port 22.
allow write: if true.
request.auth != null for sensitive paths and redeploy the previous ruleset if this was accidental.
enabled to disabled on table public.orders.
2 to 0 on branch main.
/api/stripe/webhook to /api/webhook-test.
checkout.example.com was deleted from the zone.
app.example.com to preview.example.com.
apigateway to sts.
Three steps from a configuration change to a clear, actionable finding.
ConfigTrace connects using read-only credentials and snapshots your configuration at regular intervals — security groups, DNS records, Firestore rules, webhook endpoints, branch protections, RLS policies, and more.
Every sync compares current state against your last snapshot. Field-level diffs surface exactly what changed — not just that something changed, but which field, from what value, to what value.
Each change is classified as Critical, High, Medium, or Low, with a human-readable explanation of why it matters and what the owner should review next.
ConfigTrace monitors configuration metadata and security posture. It does not read Firestore documents, Supabase table rows, Storage files, Auth users, secret values, S3 object contents, or log event contents.
View full data access policy →Connect any combination of supported providers. Changes surface in a single shared risk timeline, regardless of which stack you use.
Connect any of 7 supported providers, run your first sync, and get a timestamped record of every risky configuration change from that moment forward.
7 providers live · Reads configuration metadata only · Free plan available