# Hororus

*/Startups/Hororus*

## Startup Overview

This platform directly eliminates non-human identity sprawl by monitoring, mapping, and revoking dormant service accounts. It continuously scans cloud and on-premise infrastructure to identify machine identities that no longer execute active workloads. Once a stale account is mapped and verified against production dependencies, the system automatically terminates its access credentials.

Cloud engineering and security teams operate in environments where service accounts vastly outnumber human users, leaving behind orphaned access whenever applications are decommissioned or updated. These unmonitored credentials accumulate rapidly, creating permanent backdoors for lateral movement and violating core access policies. Tracking down the owners of these headless accounts typically forces engineers into endless log analysis and manual cross-departmental investigation.

Instead of relying on manual access reviews or heavy legacy governance suites like CyberArk Privilege Cloud and SailPoint IdentityIQ, the platform executes the entire discovery and remediation lifecycle automatically. The dependency mapping engine ensures access is safely torn down without breaking active production workloads. Utilizing a strictly outcome-based commercial model, the system bills exclusively for successful revocations, guaranteeing organizations only pay for removed vulnerabilities.

## Startup Founding Hypothesis

**Approach**: that monitors, maps, and revokes dormant service accounts
**Competitors**:
- [Manual Access Reviews](/Competitors/Manual_Access_Reviews)
- [CyberArk Privilege Cloud](/Competitors/CyberArk_Privilege_Cloud)
- [SailPoint IdentityIQ](/Competitors/SailPoint_IdentityIQ)
**Differentiator2x2**: fully automated in execution and billed strictly on successful revocations

## Startup Solution Coordinate

**Solution**: [Service Account Sweeper](/Services/Service_Account_Sweeper)

## Startup Position2x2

```mermaid
quadrantChart
    x-axis "Manual Execution" --> "Fully Automated Execution"
    y-axis "Fixed Subscription" --> "Performance-Based Billing"
    "Manual Access Reviews": [0.15, 0.15]
    "CyberArk Privilege Cloud": [0.75, 0.10]
    "SailPoint IdentityIQ": [0.65, 0.15]
    "Hororus": [0.90, 0.90]
```

## Startup Brand

**Voice**: Clinical cybersecurity register defined by absolute precision and blunt directness
**Tagline**: Eliminate dormant service accounts and pay only for successful revocations
**Icon Concept**: badge
**Palette Intent**: institutional-cool
**Visual Identity**: Deep midnight blues and stark white typography project an institutional-cool authority, accented by sharp, sterile lines resembling access control matrices.
**Archetype Reference**: the-ruler

## Startup Customer Journey

```mermaid
flowchart LR; A[AWS Marketplace] --> B[Read-Only Audit Script]; B --> C[Dormant Account Map]; C --> D[Account Revocation API]; D --> E[Enterprise Identity Environment]; E --> F[SOC Orchestration Registry];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 30-day read-only environment scan to map API dependencies and identify at least 50 safely revokable dormant accounts without executing terminations.
- 60-day active revocation pilot in a staging environment to demonstrate zero false positives on active services and validate the automated SLA-backed rollback functionality.
**Target Metrics**:
- Target: 0 production downtime events caused by non-human credential cleanup
- Aim: 100 percent of orphaned service accounts identified within 48 hours of initial scan
- Target: over 80 percent reduction in unused service account sprawl within the first 60 days
- Aim: under 60 second automated rollback time for any mistakenly flagged credential termination
**Target Case Studies**:
- Mid-market SaaS engineering team successfully automating the removal of dormant service accounts while avoiding disruption to annual batch jobs.
- Enterprise financial services cloud operations team mapping multi-cloud non-human identities and implementing RBAC workflows to eliminate legacy application credential risk.
**Testimonial Targets**:
- VP of Engineering emphasizing how the dependency mapping engine accurately preserved long-cycle access patterns and cron schedules.
- Cloud Security Director expressing confidence in the automated rollback guarantee that enables aggressive credential cleanup without production fear.
- DevSecOps Lead highlighting that the usage-based pricing per revoked account directly aligns vendor cost with actual security debt reduction.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Automated revocation disables a critical production workload by misidentifying an active but infrequently used service account. · Mitigation Status: unmitigated
- Severity: high · Description: Enterprise InfoSec teams refuse to grant the required write and delete IAM permissions necessary for automated execution. · Mitigation Status: in-progress
- Severity: high · Description: Revenue drops drastically after the initial cleanup phase because billing is tied strictly to the volume of successful revocations. · Mitigation Status: unmitigated
- Severity: moderate · Description: Cloud providers alter or rate-limit the identity APIs required to map cross-account service dependencies. · Mitigation Status: in-progress

## Startup Competitors

- [Manual Access Reviews](/Competitors/Manual_Access_Reviews) — Status Quo
- [CyberArk Privilege Cloud](/Competitors/CyberArk_Privilege_Cloud) — Incumbent
- [SailPoint IdentityIQ](/Competitors/SailPoint_IdentityIQ) — Incumbent
- [Oasis Security](/Competitors/Oasis_Security) — Startup
- [Astrix Security](/Competitors/Astrix_Security) — Startup

## Startup Story Brand

**Hero**:
- **Need**: to secure the cloud perimeter without breaking critical undocumented background processes
- **Want**: to eliminate the security risks of dormant, unrotated machine credentials
- **Identity**: the security engineer at a growth-stage fintech company
**Plan**:
- Step: Identify · Detail: Scan cloud environments to inventory all machine identities and flag orphaned accounts for review at no cost.
- Step: Approve · Detail: Verify the dependency maps generated by the 14-day simulation and authorize the cleanup of dormant accounts.
- Step: Revoke · Detail: Execute automated removals and pay only for successful revocations that shrink your attack surface.
**Guide**:
- **Empathy**: You shouldn't still be hunting orphans in IAM logs. SailPoint IdentityIQ wasn't built to map machine-to-machine dependencies.
**Problem**:
- **Villain**: identity sprawl
- **External**: orphaned service accounts sit dormant across AWS and GCP, bypassing SailPoint's human-centric identity governance
- **Internal**: you feel like you are sitting on a ticking time bomb of unmanaged keys
- **Philosophical**: Cybersecurity expertise belongs in proactive defense, not in manual access review spreadsheets.
**Success**: The cloud attack surface is permanently reduced with zero production downtime and zero unmanaged service accounts.
**One Liner**: What if you only paid for the security risks you actually removed? Hororus monitors, maps, and revokes dormant service accounts with zero production downtime.
**Positioning**:
- **So That**: eliminate dormant credentials without breaking production processes
- **Unlike**: Manual Access Reviews
- **For Whom**: security engineers at growth-stage fintech companies
- **Category**: Automated Machine Identity Governance
**Call To Action**:
- **Direct**: Execute a revocation
- **Transitional**: View dormant account inventory
**Failure Stakes**:
- Compromised unrotated credentials
- Failed SOC2 compliance audits
- Production downtime from manual cleanup
**Transformation**:
- **To**: the architect who automates the entire machine identity lifecycle
- **From**: the engineer digging through AWS IAM logs
**Controlling Idea**: Machine identity cleanup should be automated and billed only on successful outcomes.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: What if your orphaned service accounts were revoked automatically without breaking production? Hororus maps dependencies and terminates dormant credentials, billing you only for successful removals.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: aac054b5ba353bc1

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Non-human Identity Management for cloud engineering and security teams. Unlike SailPoint IdentityIQ — safely terminate dormant service accounts without breaking production.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: 267b7abbb7fc28d0

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Orphaned credentials accumulate in CyberArk and SailPoint because tracking down headless owners requires endless manual log analysis.
Solution: What if your orphaned service accounts were revoked automatically without breaking production? Hororus maps dependencies and terminates dormant credentials, billing you only for successful removals.
Customer: cloud engineering and security teams
Unlike: SailPoint IdentityIQ
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: d137e5a1268a588d

## Startup Token M E D D P I C C

**Pain**: Orphaned credentials accumulate in CyberArk and SailPoint because tracking down headless owners requires endless manual log analysis.
**Metrics**: Target: Your non-human identity footprint is strictly limited to active workloads, with every orphaned credential safely terminated.
**Rendered**: Pain: Orphaned credentials accumulate in CyberArk and SailPoint because tracking down headless owners requires endless manual log analysis.
Economic buyer: IAM Security Engineer
Metrics: Target: Your non-human identity footprint is strictly limited to active workloads, with every orphaned credential safely terminated.
Competition: SailPoint IdentityIQ
**Mechanism**: spine-derived-v1
**Competition**: SailPoint IdentityIQ
**Economic Buyer**: IAM Security Engineer
**Vocab Fingerprint**: 25f4bde0cf5994b6

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Non-human Identity Management for cloud engineering and security teams

cloud engineering and security teams — Orphaned credentials accumulate in CyberArk and SailPoint because tracking down headless owners requires endless manual log analysis. What if your orphaned service accounts were revoked automatically without breaking production? Hororus maps dependencies and terminates dormant credentials, billing you only for successful removals.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 3d32327fe0155e74

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Non-human Identity Management. What if your orphaned service accounts were revoked automatically without breaking production? Hororus maps dependencies and terminates dormant credentials, billing you only for successful removals. Serves cloud engineering and security teams.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 35da8f5f21990733

## Neighborhood

### Entrant startups

- [AI Bookkeeping For Accounting Firms](/Opportunities/AI_Bookkeeping_For_Accounting_Firms) — is entrant in · Opportunities

### Competitors

- [Oasis Security](/Competitors/Oasis_Security) — competes with · Competitors
- [SailPoint IdentityIQ](/Competitors/SailPoint_IdentityIQ) — competes with · Competitors
- [CyberArk Privilege Cloud](/Competitors/CyberArk_Privilege_Cloud) — competes with · Competitors
- [Manual Access Reviews](/Competitors/Manual_Access_Reviews) — competes with · Competitors
- [Astrix Security](/Competitors/Astrix_Security) — competes with · Competitors
- [Offshore BPOs](/Competitors/Offshore_BPOs) — competes with · Competitors
- [QuickBooks Online Accountant](/Competitors/QuickBooks_Online_Accountant) — competes with · Competitors
- [Vic.ai](/Competitors/Vic.ai) — competes with · Competitors
- [Dext Prepare](/Competitors/Dext_Prepare) — competes with · Competitors
- [Botkeeper](/Competitors/Botkeeper) — competes with · Competitors
- [Pilot Bookkeeping](/Competitors/Pilot_Bookkeeping) — competes with · Competitors
- [Offshore BPO Firms](/Competitors/Offshore_BPO_Firms) — competes with · Competitors
- [Botkeeper Partner Platform](/Competitors/Botkeeper_Partner_Platform) — competes with · Competitors
- [QuickBooks Native Rules](/Competitors/QuickBooks_Native_Rules) — competes with · Competitors
- [Offshore Bookkeeping Labor](/Competitors/Offshore_Bookkeeping_Labor) — competes with · Competitors

### Embodies

- [Service-as-Software](/Theses/Service-as-Software) — embodies · Theses
- [Agent](/Theses/Agent) — embodies · Theses

### What it offers

- [Service Account Sweeper](/Services/Service_Account_Sweeper) — offers · Services
- [Hororus AutoClose](/Services/Hororus_AutoClose) — offers · Services
- [Ledger Mapping Agent](/Agents/Ledger_Mapping_Agent) — offers · Agents

### Composed of

- [AutoClose Ledger Pipeline](/Agents/AutoClose_Ledger_Pipeline) — composes · Agents
- [Ledger Triage Agent](/Agents/Ledger_Triage_Agent) — composes · Agents
- [Historical Context Agent](/Agents/Historical_Context_Agent) — composes · Agents
- [Bank Feed Sync API](/Agents/Bank_Feed_Sync_API) — composes · Agents
- [Ledger Writeback API](/Agents/Ledger_Writeback_API) — composes · Agents

### What it addresses

- [Categorize Client Transactions](/Problems/Categorize_Client_Transactions) — addresses · Problems

### Who it serves

- [Accounting Firm](/CompanyTypes/Accounting_Firm) — serves · CompanyTypes

### Similar Startups

- [Acceam](/Startups/Acceam) — similar · Startups
- [Permoster](/Startups/Permoster) — similar · Startups
- [Corelamp](/Startups/Corelamp) — similar · Startups
- [Acaspoint](/Startups/Acaspoint) — similar · Startups
- [Autincipal](/Startups/Autincipal) — similar · Startups
- [Novia](/Startups/Novia) — similar · Startups
- [Venturenexus](/Startups/Venturenexus) — similar · Startups
- [Symon](/Startups/Symon) — similar · Startups
- [Spaceintractable](/Startups/Spaceintractable) — similar · Startups
- [Accaze](/Startups/Accaze) — similar · Startups
- [Direridian](/Startups/Direridian) — similar · Startups
- [Verow](/Startups/Verow) — similar · Startups
- [Atomnon](/Startups/Atomnon) — similar · Startups
- [Prilum](/Startups/Prilum) — similar · Startups
- [Accirm](/Startups/Accirm) — similar · Startups
- [Coordinatorfield](/Startups/Coordinatorfield) — similar · Startups
- [Atonyx](/Startups/Atonyx) — similar · Startups
- [Posept](/Startups/Posept) — similar · Startups
- [Bleed](/Startups/Bleed) — similar · Startups
- [Turnift](/Startups/Turnift) — similar · Startups
