The mechanics, end to end.
How qrie deploys into a dedicated account, evaluates configuration as events arrive, and keeps every finding inside your trust boundary — for the reviewer who needs the details.
Runs in your account.
Not a vendor's.
qrie runs entirely inside a dedicated AWS account you control — the QOP account. CloudTrail events flow through EventBridge in real time. Your resource data, findings, and policy evaluations never leave your trust boundary.
No SaaS exfil. No cross-account roles to vendors. No breach risk from someone else's customer.
As events arrive.
Not on a scan schedule.
Scheduled scanners only notice drift on their next sweep. qrie is event-driven — it evaluates each configuration change as CloudTrail delivers it, so nothing waits on a daily cron.
Deploy in fifteen minutes.
Not three quarters.
No vendor cross-account role reaching into your production accounts. The trust boundary is one dedicated account you own and audit. You run the bootstrap; CloudFormation does the rest.
We provision your QOP account
15 minutes. One CloudFormation stack in a dedicated AWS account you own. No agents, no sidecars.
You run one bootstrap script
Register each AWS account you want monitored. We configure EventBridge forwarding and an assume-role for inventory scans.
Findings start streaming
Open the dashboard. Historical inventory lands within the hour; new drift shows up in seconds.
Work directly with
the founding team.
We're onboarding a small group of design partners — founder-led, solving your problems personally. Three ways in, whichever fits.
- 1Request a demoFill the form → we spin up a sandbox in your AWS and walk your own attack paths.
- 2
- 3
Pricing is collaborative at this stage.