SOC 2 Type II · ISO 27001 · 1,400 security teams
SOC 2 Type II · ISO 27001 · 1,400 security teams
Palisade
Palisade
Risk score82/100open
Next page/
Home
Docs
Connect your first source.
Quick starts, guides and the API reference.
SOC 2 Type II · ISO 27001 · 1,400 security teams
Live findings0 / 4 closed
- 09:41Stale admin accountIdentityHigh
- 09:43Leaked API keySecretCritical
- 09:45Contractor · MFA offIdentityHigh
- 09:47Laptop · 41 days unpatchedEndpointMedium
Sample findings, demo data
Docs
Connect your first source.
Quick starts, guides and the API reference.
SOC 2 Type II · ISO 27001 · 1,400 security teams
Live findings0 / 4 closed
- 09:41Stale admin accountIdentityHigh
- 09:43Leaked API keySecretCritical
- 09:45Contractor · MFA offIdentityHigh
- 09:47Laptop · 41 days unpatchedEndpointMedium
Sample findings, demo data
Docs
Connect your first source.
Quick starts, guides and the API reference.
SOC 2 Type II · ISO 27001 · 1,400 security teams
Live findings0 / 3 closed
- 09:41Stale admin accountIdentityHigh
- 09:43Leaked API keySecretCritical
- 09:45Contractor · MFA offIdentityHigh
Sample findings, demo data
- 016 guidesGet startedConnect a first source read-only and run a sweep.Open
- 0212 guidesSourcesIdentity providers, device managers, cloud accounts and code hosts.Open
- 039 guidesFindingsHow a finding is ranked, who owns it and what closes it.Open
- 047 guidesPlaybooksClose a class of finding with one approved step.Open
- 0541 endpointsAPI referenceEvery finding, asset and owner over REST and webhooks.Open
- 065 guidesSecurity and complianceHow we store your data and what our reports cover.Open
Quick start
From nothing to a ranked list in four steps.
- 1
Create a read-only token
In your identity provider, add Palisade as an app with read scopes only.
- 2
Connect the source
Paste the token under Sources. Nothing is changed in your tenant.
- 3
Run the first sweep
It takes about four minutes for 500 identities.
- 4
Assign the top five
Each finding names its owner. Send them from the list.
API
Your findings, in your own tools.
Pull open findings into a ticket queue, a chat channel or a board. Everything in the product is in the API.
curl https://api.palisade.example/v1/findings \
-H "Authorization: Bearer psk_sample_3f9a..." \
-G -d status=open -d severity=critical -d limit=2{
"total": 7,
"findings": [
{ "id": "fnd_8Q2", "asset": "Leaked API key", "kind": "secret",
"severity": "critical", "owner": "t.whitlock", "open_for": "3h 12m" },
{ "id": "fnd_8Q7", "asset": "Open RDP port", "kind": "network",
"severity": "critical", "owner": "it-ops", "open_for": "41m" }
]
}Sample data. The key above is not a real key.
- 016 guidesGet startedConnect a first source read-only and run a sweep.Open
- 0212 guidesSourcesIdentity providers, device managers, cloud accounts and code hosts.Open
- 039 guidesFindingsHow a finding is ranked, who owns it and what closes it.Open
- 047 guidesPlaybooksClose a class of finding with one approved step.Open
- 0541 endpointsAPI referenceEvery finding, asset and owner over REST and webhooks.Open
- 065 guidesSecurity and complianceHow we store your data and what our reports cover.Open
Quick start
From nothing to a ranked list in four steps.
- 1
Create a read-only token
In your identity provider, add Palisade as an app with read scopes only.
- 2
Connect the source
Paste the token under Sources. Nothing is changed in your tenant.
- 3
Run the first sweep
It takes about four minutes for 500 identities.
- 4
Assign the top five
Each finding names its owner. Send them from the list.
API
Your findings, in your own tools.
Pull open findings into a ticket queue, a chat channel or a board. Everything in the product is in the API.
curl https://api.palisade.example/v1/findings \
-H "Authorization: Bearer psk_sample_3f9a..." \
-G -d status=open -d severity=critical -d limit=2{
"total": 7,
"findings": [
{ "id": "fnd_8Q2", "asset": "Leaked API key", "kind": "secret",
"severity": "critical", "owner": "t.whitlock", "open_for": "3h 12m" },
{ "id": "fnd_8Q7", "asset": "Open RDP port", "kind": "network",
"severity": "critical", "owner": "it-ops", "open_for": "41m" }
]
}Sample data. The key above is not a real key.
- 016 guidesGet startedConnect a first source read-only and run a sweep.Open
- 0212 guidesSourcesIdentity providers, device managers, cloud accounts and code hosts.Open
- 039 guidesFindingsHow a finding is ranked, who owns it and what closes it.Open
- 047 guidesPlaybooksClose a class of finding with one approved step.Open
- 0541 endpointsAPI referenceEvery finding, asset and owner over REST and webhooks.Open
- 065 guidesSecurity and complianceHow we store your data and what our reports cover.Open
Quick start
From nothing to a ranked list in four steps.
- 1
Create a read-only token
In your identity provider, add Palisade as an app with read scopes only.
- 2
Connect the source
Paste the token under Sources. Nothing is changed in your tenant.
- 3
Run the first sweep
It takes about four minutes for 500 identities.
- 4
Assign the top five
Each finding names its owner. Send them from the list.
API
Your findings, in your own tools.
Pull open findings into a ticket queue, a chat channel or a board. Everything in the product is in the API.
curl https://api.palisade.example/v1/findings \
-H "Authorization: Bearer psk_sample_3f9a..." \
-G -d status=open -d severity=critical -d limit=2{
"total": 7,
"findings": [
{ "id": "fnd_8Q2", "asset": "Leaked API key", "kind": "secret",
"severity": "critical", "owner": "t.whitlock", "open_for": "3h 12m" },
{ "id": "fnd_8Q7", "asset": "Open RDP port", "kind": "network",
"severity": "critical", "owner": "it-ops", "open_for": "41m" }
]
}Sample data. The key above is not a real key.
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected