Skip to main content
Overview
How it works

The mechanics, end to end.

How qrie deploys into a dedicated account, evaluates configuration as events arrive, and keeps every finding inside your trust boundary — for the reviewer who needs the details.

The architecture

Runs in your account.
Not a vendor's.

qrie runs entirely inside a dedicated AWS account you control — the QOP account. CloudTrail events flow through EventBridge in real time. Your resource data, findings, and policy evaluations never leave your trust boundary.

No SaaS exfil. No cross-account roles to vendors. No breach risk from someone else's customer.

YOUR AWS ORG · SINGLE TRUST BOUNDARYMonitored accountsPRprod-primary4-digit-acctPRprod-analytics4-digit-acctSTstaging4-digit-acctDEdev-platform4-digit-acctAWS EVENTBRIDGECloudTrail eventsforwarded in real-timeQOP · QRIE ON-PREMISESYOUR ACCTDetection enginepolicy evaluatorsFindings storePostgres · your VPCDashboardweb consolelive
qrie
Typical SaaS
Where your findings live
Your AWS account · your VPC
Vendor multi-tenant DB
Detection cadence
Event-driven · evaluated as changes arrive
Scheduled re-scans
Cross-account role to vendor
None
ReadOnlyAccess required
Breach blast radius
Your account only
All customers affected
Data residency
Whichever AWS region you pick
Vendor's region(s)
Policy transparency
Source visible · editable
Black box
Real-time detection

As events arrive.
Not on a scan schedule.

Scheduled scanners only notice drift on their next sweep. qrie is event-driven — it evaluates each configuration change as CloudTrail delivers it, so nothing waits on a daily cron.

Event-driven
evaluated as events arrive
0
scanners in your VPCs
Live
findings stay in your account
live · findings stream
connecting…
Listening on EventBridge…
evaluated as events arriveno daily scan window
Onboarding

Deploy in fifteen minutes.
Not three quarters.

No vendor cross-account role reaching into your production accounts. The trust boundary is one dedicated account you own and audit. You run the bootstrap; CloudFormation does the rest.

01

We provision your QOP account

15 minutes. One CloudFormation stack in a dedicated AWS account you own. No agents, no sidecars.

02

You run one bootstrap script

Register each AWS account you want monitored. We configure EventBridge forwarding and an assume-role for inventory scans.

03

Findings start streaming

Open the dashboard. Historical inventory lands within the hour; new drift shows up in seconds.

qrie-bootstrap — your-laptop
Contact

Work directly with
the founding team.

We're onboarding a small group of design partners — founder-led, solving your problems personally. Three ways in, whichever fits.

  1. 1
    Request a demo
    Fill the form → we spin up a sandbox in your AWS and walk your own attack paths.
  2. 2
    Talk to the founding team
    Rather talk first? 30 minutes, founder-led — no deck.
    Book a 30-min call
  3. 3
    Something else? Email the team ·

Pricing is collaborative at this stage.

Request a demo
We'll spin up a sandbox in your AWS and walk you through it — reply within a business day.

Your data never leaves your AWS account. We'll never sell it.