Your code has Git history. Your production configuration does not. ConfigTrace continuously snapshots cloud, SaaS, identity, and developer infrastructure, detects configuration drift, and surfaces risky current posture — from exposed cloud resources to weakened MFA, privileged identities, dangerous OAuth grants, and policy changes. 23 providers, including AWS, Kubernetes, Okta, Microsoft Entra ID, GitHub, and more.
Metadata-only monitoring. No customer data, source code, secret values, payment details, or database rows.
See how ConfigTrace tracks configuration drift, surfaces security posture findings, and connects risk to related activity across cloud, SaaS, and developer infrastructure.
Production-critical settings need a history of changes, a view of risky current states, and a way to connect risk to related activity evidence. ConfigTrace gives you all three, from the same connected providers.
Track production-critical setting changes across cloud, SaaS, and developer infrastructure. See what changed, when, and why it matters.
Find risky current states from provider configuration metadata before they become operational or security review problems.
ConfigTrace evaluates provider configuration metadata and activity event records. It does not inspect payloads, secret values, variable values, state files, or customer data, and it does not confirm breach, compromise, or data exposure. Activity signals and correlations are risk indicators that may require review — not proof of unauthorized access.
Production does not only break because code changes. It breaks because someone changed a setting outside Git — in a cloud console, a vendor dashboard, a CLI, or a misconfigured Terraform run. Code reviews don't see it. CI/CD doesn't catch it. Logs only show the symptom.
ConfigTrace gives those changes a timeline, a risk engine, a review workflow, and a remediation path — the same discipline Git gives source code.
Not just cloud infrastructure. The controls that decide who gets in, what they can reach, and whether production stays safe live across cloud, identity, application, and delivery-pipeline configuration — outside Git, outside code review.
Security groups, firewall rules, storage public access, DNS records, IAM policy bindings, and network posture across AWS, Azure, Google Cloud, and Cloudflare.
Global Administrators, privileged groups, directory roles, service principals, OAuth consent, and admin-role assignments across Entra ID, Okta, and Auth0.
MFA requirements, Conditional Access policies, authentication strengths, sign-on policy, and authenticator configuration across Entra ID, Okta, Auth0, and Clerk.
Redirect URIs, enterprise app assignments, Graph application permissions, OAuth grants, and Kubernetes workload privilege, RBAC, and network exposure.
Branch protection, deployment protection rules, CI/CD variable posture, webhook configuration, and production-branch settings across GitHub, GitLab, and Terraform Cloud.
Alert routing, escalation policies, webhook delivery configuration, monitor notification settings, and run-trigger posture across PagerDuty, Datadog, and Terraform Cloud.
Kubernetes, Okta, and Microsoft Entra ID materially changed what ConfigTrace watches. Identity is now a first-class configuration surface, not an afterthought — because the fastest way into a system is rarely a code vulnerability. It's a Global Administrator role that got assigned quietly, a sign-on policy that stopped requiring MFA, or an OAuth grant nobody reviewed.
ConfigTrace tracks configuration-level changes to privilege and authentication posture — configuration evidence, not breach detection. It tells you what changed and what is currently exposed, not that an account was compromised.
ConfigTrace is a closed loop across the lifecycle of a risky configuration change — from the moment it happens, to the moment it's reviewed, fixed, and explained back to your team and customers.
Without a security timeline, a production incident starts with a question nobody can answer. With one, the answer is already there.
"Prod is degraded. Did code ship? Did DNS change? Did someone touch Cloudflare or Stripe? Was a webhook moved? Who has access? When did it happen?"
ConfigTrace tracks both, because they answer different questions. A Change gives you chronology — exactly what was modified, when. A Security Finding gives you current posture — what configuration state exists right now that needs review, regardless of when it happened.
MFA requirement changed from required to not required on the Okta sign-on policy "Default".
A second example: a Change records that a Global Administrator role was assigned to an identity. The corresponding Security Finding is that this identity currently holds Global Administrator privilege — and stays open until the role is removed, independent of how long ago it was granted. Both matter: one gives you the timeline, the other gives you today's exposure.
Every sync is diffed field-by-field against the last known state — so you see exactly what changed, not just that something did. ConfigTrace reads configuration metadata only. No secret values, no variable values, no state files, no database rows.
A synthetic timeline showing risky drift across cloud, SaaS, identity, and developer infrastructure providers — exactly as it appears inside ConfigTrace. Field-level diffs, risk classification, and a clear next step.
ConfigTrace routes risky drift to the channels your team already uses — Slack, email, webhooks, and browser push — with the context needed to triage and review. Buttons trigger review actions, not provider mutations.
Slack buttons drive review actions inside ConfigTrace — open change, acknowledge, snooze, view remediation. They do not mutate provider resources or apply infrastructure changes.
Every risky change comes with a remediation path — guidance, a fix plan, a dry-run preview, and where Terraform mappings exist, a draft GitHub pull request. Every mutation is review-first and admin-gated.
Each high or critical change ships with plain-English guidance on how to bring it back to a safe state — written for the on-call engineer, not just the cloud expert.
A structured plan of the exact steps that would restore the previous configuration — shown before anything runs, so a reviewer can sanity-check the intent.
A read-only preview of what the fix would change, formatted as a diff against the current live state — no API mutations, no writes against provider resources.
Where ConfigTrace can map a drifted resource to your IaC repo, you'll see the proposed HCL diff inline — surfaced as a suggestion, not an applied change.
An admin can open a GitHub draft PR with the fix proposal as a patch file — explicit confirmation required, admin-gated, low- confidence mappings blocked, review-first by design.
Drift detection alone isn't a workflow. ConfigTrace adds the structure around it — policies, windows, scoring, digests, and change rooms — so security work doesn't drown in alert fatigue.
Define rules for what counts as risky in your workspace — by provider, resource type, or field. Treat the same change differently in staging versus production.
Mark planned maintenance windows so expected drift during a deploy or migration is suppressed from the alert path while still being recorded in the timeline.
A single workspace-level score that tracks how much risky drift goes unreviewed and how fast critical changes get triaged. A signal you can show leadership and customers.
A per-workspace weekly summary of drift, reviewed changes, outstanding critical items, and Drift Control Score trend — for the whole team and for security stakeholders.
For high-impact drift, ConfigTrace opens a change room — a dedicated page with the diff, blast radius, remediation path, notes, and full activity log for the whole team.
High and critical changes land in a single Needs Review queue with acknowledge, snooze, and escalate actions — and an audit trail of who reviewed what, when.
APIs fail. Permissions vary. Pagination truncates. Providers rate-limit mid-sync. A denied endpoint or a partial response shouldn't make hundreds of resources look deleted. ConfigTrace tracks how completely each sync actually collected data and suppresses false-removal noise when a provider family can't be fully read.
Each resource family (RBAC, networking, applications, and so on) is tracked separately for how completely it was collected on a given sync.
ConfigTrace knows the difference between "this resource is gone" and "this sync couldn't confirm it" — and treats them differently.
Transient failures and rate limits are retried within bounds rather than silently treated as authoritative results.
When a sync only partially succeeds, ConfigTrace suppresses "removed" findings for the affected family instead of reporting a wave of fake deletions.
Resources are matched across syncs by stable identifiers, not positional order — so a reordered API response doesn't look like drift.
Smaller, narrower payloads by design — configuration and posture fields only, which keeps every sync faster and less exposed to partial-failure modes.
ConfigTrace weighs each detected change by its potential blast radius so your team can triage at a glance — not after the incident is already in progress.
Concrete configuration changes ConfigTrace is built to detect and classify — not hypothetical incidents.
A Global Administrator role is assigned to an identity outside the normal access-request process.
A sign-on policy stops requiring MFA, weakening authentication for everyone it applies to.
A workload's security context changes to privileged, or gains host networking access.
A security group opens SSH or a database port to 0.0.0.0/0.
A production environment's required-reviewers protection is removed.
A high-risk Microsoft Graph application permission is granted to a service principal.
A WAF rule protecting a production zone is disabled.
An application's allowed OAuth redirect URIs change to include an unexpected wildcard.
ConfigTrace is designed to support security review — both internal and with your customers. Configuration metadata in. No customer data, secret values, source code, payment details, or database rows out.
ConfigTrace stores the minimum encrypted connector credentials needed to read provider configuration — never shown again after creation. That's a necessary part of running a read-only integration; what it does not do is ingest or snapshot secret values, session tokens, or MFA/OTP seeds from the monitored provider itself. Read-only or least-privilege scopes are recommended for every integration.
Disconnect a provider from inside ConfigTrace in one click, or rotate / revoke the credential from the provider side. ConfigTrace stops reading immediately.
A per-workspace Trust Center page lists every connected provider, the exact scopes used, what ConfigTrace reads, and what it never reads — built to show to a reviewer.
Export a security packet describing data access boundaries, encryption posture, and audit history. Use it for internal review or customer trust conversations.
Every team action — invites, role changes, integrations, acknowledgements, draft PR creation — is recorded with actor, timestamp, and target.
Production drift sits in a gap between existing tools. ConfigTrace fills that gap — without trying to replace the systems your team already uses.
It is not when everything is working. It is when production breaks and your team needs the answer to one question: what changed?
On-call digs through AWS, Cloudflare, Stripe, GitHub, Vercel, and Slack — trying to reconstruct whether it was a security group, a DNS reroute, a deleted webhook, or a weakened Firestore rule. The clock keeps running.
The exact change — record, old value, new value, risk label — arrives in Slack and email within minutes of the next sync.
Faster root cause. A clear record for the next incident review. A trail your customers and security reviewers can see.
A note from the founder.
"I'm building ConfigTrace because production systems now depend
on dozens of dashboards, not just code. GitHub tells you what
changed in the repo. It does not tell you who changed a DNS record,
webhook URL, branch protection rule, OAuth callback, RLS policy, or
cloud permission.
Your code has Git history. Your production settings do not.
ConfigTrace is my attempt to give those settings the same discipline
code gets from Git — a security timeline with diffs, risk
classification, a review workflow, and a remediation path that stays
review-first."
Give production settings a history. View the public demo to see ConfigTrace in action with synthetic data, or connect your first provider and capture a baseline before the next risky change happens.
23 providers · metadata-only monitoring · admin-gated remediation