Real-time score.
Full attack surface.

Vimy continuously measures your security posture across identity, perimeter, cloud, and endpoints — scoring your environment in real time and alerting when it drifts. Not a quarterly assessment. Not a point-in-time snapshot. A live score that reflects reality right now.

Real-time scoring Drift detection CIS & NIST benchmarks
Vimy posture monitoring dashboard
The Problem

You can't secure what you can't measure.

01

Point-in-time assessments

Annual penetration tests and quarterly vulnerability scans give you a snapshot — but your environment changes daily. Configurations drift, new services spin up, permissions creep. The snapshot is stale before the report is printed.

02

No unified score

Your EDR has a health score. Your cloud provider has a security score. Your identity provider has a risk score. None of them talk to each other. You have five numbers and no answer to "are we secure?"

03

Reactive, not proactive

Most security tools wait for something bad to happen. Posture monitoring catches the conditions that lead to something bad — misconfigurations, weak settings, exposed services, stale credentials — before they're exploited.

Posture Score

One number. Every layer.

Vimy calculates a unified posture score from 0 to 100 by aggregating security health across every connected layer. The score updates in real time as your environment changes — configurations, permissions, policies, and compliance controls all feed into a single, actionable number.

Posture Score
Identity Posture
MFA adoption, password policies, OAuth app permissions, stale accounts, admin sprawl
78/100
Perimeter Posture
WAF configuration, SSL/TLS settings, DNS security, origin protection, bot management
91/100
Cloud Security
Firewall rules, storage permissions, API key hygiene, resource configuration, backup status
74/100
Hardening
OS configuration, service exposure, patch status, encryption settings, logging coverage
85/100

Scores shown are illustrative. Your posture score is calculated from your actual environment.

Posture Domains

Every angle of your attack surface. Measured.

Identity Posture

Monitors how well your identity infrastructure is configured and maintained. Tracks MFA enforcement rates, password policy strength, OAuth app permissions, inactive accounts, admin privilege sprawl, and session management settings.

Key Checks
  • MFA enforcement across all users
  • OAuth apps with excessive permissions
  • Stale accounts not accessed in 90+ days
  • Admin accounts without MFA
  • Password policy strength
Source: Google Workspace, Okta, Entra ID...

Perimeter Posture

Monitors the security configuration of your edge — the boundary between the internet and your infrastructure. Tracks WAF ruleset coverage, SSL/TLS configuration, DNS security settings, origin IP protection, and bot management effectiveness.

Key Checks
  • WAF managed rulesets enabled and updated
  • TLS 1.2+ enforced, TLS 1.3 preferred
  • DNSSEC enabled
  • Origin IP not exposed
  • Bot Fight Mode active
Source: Cloudflare, Akamai...

Cloud Security

Monitors the security configuration of your cloud infrastructure. Tracks firewall rules, storage bucket permissions, API key rotation, resource tagging compliance, backup configuration, and network segmentation.

Key Checks
  • Firewall rules reviewed and minimal
  • No public storage buckets
  • API keys rotated within policy
  • Backups configured and verified
  • Logging enabled on all resources
Source: Canadian cloud infrastructure, AWS, Azure

Hardening

Monitors the configuration of individual servers and endpoints against security baselines. Tracks OS hardening, unnecessary service exposure, patch status, encryption settings, and logging coverage.

Key Checks
  • SSH key-only authentication
  • Unnecessary ports closed
  • Automatic security updates enabled
  • Disk encryption active
  • Audit logging configured
Source: Vimy Agent
Drift Detection

Catch changes before they become vulnerabilities.

Security posture degrades over time. Configurations get changed during debugging and never reverted. New team members get admin access "temporarily." Firewall rules accumulate exceptions. Vimy detects these drifts automatically and alerts before they become exploitable.

Drift detection runs continuously — not on a schedule. The moment a configuration changes in a way that weakens your posture, Vimy flags it.

MFA disabled for admin account
HIGH
Identity posture dropped from 82 → 71. [email protected] MFA was disabled 14 minutes ago.
WAF managed ruleset disabled
CRITICAL
Perimeter posture dropped from 91 → 64. Cloudflare OWASP Core Ruleset was turned off.
SSH password authentication re-enabled
MEDIUM
Hardening score dropped from 85 → 78. Server web-01 now accepts password authentication.
Benchmarks

Industry benchmarks. Continuously tested.

Vimy runs your environment against industry-standard benchmarks — CIS Controls v8 and NIST CSF 2.0 — continuously. Not a one-time scan, not an annual audit. Every benchmark check runs against your live configuration and updates your benchmark score in real time.

CIS Controls v8
CIS Controls v8

18 Critical Security Controls across three Implementation Groups (IG1, IG2, IG3). Vimy tracks your implementation level for each control and collects evidence continuously.

controls mapped
Automated technical checks via connected batteries and agent
NIST CSF 2.0
NIST CSF 2.0

Six core functions — Identify, Protect, Detect, Respond, Recover, Govern. Vimy maps security operations to each function and provides a function-level maturity score.

controls mapped
Continuously assessed against live security data

Benchmark results feed into your compliance posture. CIS and NIST evidence automatically satisfies overlapping controls in SOC 2, ISO 27001, and other frameworks.

Posture Reporting

Trends your leadership can track.

Vimy generates posture reports automatically — weekly summaries, monthly trends, and on-demand snapshots. See your score over time, identify recurring drift patterns, and demonstrate continuous improvement to leadership, auditors, and cyber insurers.

Weekly posture summary
Monthly trend report
Domain-level deep dives (identity, perimeter, cloud, hardening)
Board-ready executive summaries
Cyber insurance evidence reports
Vimy posture reports dashboard

See your posture score in 30 minutes.

We'll connect to your environment and calculate your real-time posture score — across identity, perimeter, cloud, and hardening — live on the call.

Real-time scoring Drift detection 100% Canadian infrastructure