# Porosityscaffold

*/Startups/Porosityscaffold*

## Startup Overview

This platform continuously maps and automatically remediates hidden ingress paths across enterprise cloud environments. It traces complex network configurations, identity permissions, and exposed endpoints to pinpoint exactly how external attackers reach internal assets.

Cloud security and infrastructure teams struggle with shadow ingress created by overlapping security groups, misconfigured API gateways, and dangling DNS records. These hidden vectors bypass standard perimeter defenses and remain completely invisible to conventional vulnerability scanners.

Legacy tools like Prisma Cloud and Tenable ASM rely on snapshot-based assessments that generate isolated alerts without structural context. By remaining topologically aware, this system analyzes the continuous network graph to verify functional reachability and automatically deploys configuration fixes to close exposures, eliminating the reliance on periodic penetration testing.

## Startup Founding Hypothesis

**Approach**: that maps and remediates hidden cloud ingress paths
**Competitors**:
- [Prisma Cloud](/Competitors/Prisma_Cloud)
- [Tenable ASM](/Competitors/Tenable_ASM)
- [periodic penetration testing](/Competitors/periodic_penetration_testing)
**Differentiator2x2**: topologically aware and auto-remediating rather than snapshot-based and alert-only

## Startup Solution Coordinate

**Solution**: [Ingress Mapping Engine](/Software/Ingress_Mapping_Engine)

## Startup Position2x2

```mermaid
quadrantChart\n    title Attack Surface Mapping & Remediation\n    x-axis Snapshot-based --> Topologically Aware\n    y-axis Alert-only --> Auto-remediating\n    quadrant-1 Continuous Resolution\n    quadrant-2 Point-in-time Fixes\n    quadrant-3 Legacy Audits\n    quadrant-4 Contextual Alerting\n    Periodic Penetration Testing: [0.15, 0.15]\n    Tenable ASM: [0.35, 0.25]\n    Prisma Cloud: [0.70, 0.45]\n    Porosityscaffold: [0.85, 0.85]
```

## Startup Offer

**Proof**:
- Aiming to reduce external attack surface exposure time to under five minutes for scaling SaaS providers.
- Targeting zero undetected shadow ingress paths for mid-market financial institutions adopting multi-cloud architectures.
- Designed to eliminate manual network remediation tickets entirely for lean cloud engineering teams.
**Tiers**:
- Name: Single Environment · Price: ~$800–$1,500/mo · Inclusions: Continuous topological mapping and auto-remediation for one primary cloud provider environment, covering up to 5,000 active compute and network resources.
- Name: Multi-Cloud Portfolio · Price: ~$2,500–$4,500/mo · Inclusions: Unified cross-cloud ingress mapping, custom remediation playbooks, and API-driven deployment covering up to 25,000 multi-cloud resources.
**Guarantee**: If a manual third-party penetration test successfully exploits a structural ingress path that the topological engine failed to map or flag for remediation, the buyer receives a full refund for that operating quarter.
**Business Function**: ProvideService
**Objection Handlers**:
- Objection: Automated network remediation will break legitimate production traffic. Rebuttal: The system is designed to simulate path closures against a topological twin before execution, providing exact blast-radius calculations and requiring human-in-the-loop approval by default.
- Objection: We already pay for a CSPM that alerts us to open ports. Rebuttal: CSPMs rely on static snapshots of isolated configurations; this engine traces multi-hop topological routing to expose chained ingress paths that look secure in isolation.
- Objection: InfoSec will not approve broad write-access to our cloud infrastructure. Rebuttal: The core engine operates on standard read-only cross-account roles, requesting strictly scoped, temporary write execution only when a specific remediation playbook is approved.
**Pricing Architecture**: Tiered
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Clinical and authoritative, prioritizing architectural precision over alarmism.
**Tagline**: Expose and seal hidden ingress paths across your cloud topology.
**Icon Concept**: hatch
**Palette Intent**: electric-signal
**Visual Identity**: The visual identity pairs deep blueprint blue with sharp neon magenta highlights to evoke structural topology maps under ultraviolet inspection, anchored by precise monospaced typography.
**Archetype Reference**: the-sage

## Startup Buyer Chain

**Chain**: Porosityscaffold → Cloud Security Architect → Enterprise Infrastructure
**Gtm Motion**: Acquires users by offering a free, read-only topology scan of a single AWS or GCP account to expose immediate vulnerabilities. Expands revenue by upselling automated remediation write-access and continuous cross-cloud organizational monitoring.
**Agent Channel**: Intends to register the topology-mapping API as a tool in the LangChain integrations catalog and OpenAI structured capability registries, allowing autonomous security-auditing agents to query live ingress paths during automated posture reviews.
**Primary Channel**: AWS Marketplace and GitHub Security integration directories, capturing DevSecOps engineers searching for external attack surface management tools after a failed compliance audit or penetration test.

## Startup Customer Journey

```mermaid
flowchart LR A[AWS Marketplace] --> B[Topology Scanner] --> C[Ingress Map] --> D[Single Cloud Subscription] --> E[Remediation Engine] --> F[Cross-Cloud Monitor] --> G[GitHub Security Directory]
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 30-day single-environment deployment: Connect the engine via standard read-only cross-account roles to identify at least one multi-hop ingress path that the buyer's existing CSPM fails to detect.
- 60-day multi-cloud pilot across up to 25,000 resources: Execute strictly scoped, human-in-the-loop remediation playbooks to close identified shadow ingress paths, proving zero disruption to baseline production traffic.
**Target Metrics**:
- Target: Under 5 minutes of external attack surface exposure time following a new cloud deployment.
- Aim: 0 undetected shadow ingress paths exploitable during manual third-party penetration tests.
- Target: 100% reduction in manual network remediation tickets for lean cloud engineering teams.
- Aim: 100% accuracy in pre-execution blast-radius calculations against the topological twin.
**Target Case Studies**:
- Mid-market SaaS provider (VP of Engineering): Transition from quarterly manual penetration testing to continuous topological mapping, demonstrating the total elimination of undetected shadow ingress paths.
- Fintech scale-up (Lead DevOps Engineer): Shift from manual network configuration reviews to automated remediation playbooks, proving a reduction in manual network remediation tickets to zero.
- Enterprise healthcare software vendor (CISO): Move from reactive, isolated CSPM alerts to continuous blast-radius simulations, proving zero disruption to legitimate production traffic during automated ingress closures.
**Testimonial Targets**:
- Cloud Security Architect: Validates that the engine exposes multi-hop chained ingress paths that their existing static CSPM entirely missed.
- VP of Infrastructure: Expresses high confidence in the automated remediation process because the topological twin accurately simulates the exact blast radius before executing path closures.
- Chief Information Security Officer: Affirms trust in the platform's mapping completeness after a rigorous third-party penetration test fails to exploit any unmapped structural ingress paths.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Auto-remediation engine inadvertently severs a critical undocumented production ingress path and causes an enterprise-wide outage. · Mitigation Status: in-progress
- Severity: high · Description: Enterprise security and DevOps teams refuse to grant the extensive write permissions required to execute automated network remediation. · Mitigation Status: unmitigated
- Severity: moderate · Description: Cloud infrastructure providers restrict or heavily throttle the network configuration APIs required for continuous topological mapping. · Mitigation Status: unmitigated
- Severity: moderate · Description: Incumbents like Prisma Cloud replicate the continuous topological graph feature before the auto-remediation engine reaches maturity. · Mitigation Status: in-progress

## Startup Competitors

- [Prisma Cloud](/Competitors/Prisma_Cloud) — Incumbent CSPM
- [Tenable ASM](/Competitors/Tenable_ASM) — Incumbent ASM
- [Periodic Penetration Testing](/Competitors/Periodic_Penetration_Testing) — Status Quo
- [Wiz](/Competitors/Wiz) — Snapshot CSPM
- [Orca Security](/Competitors/Orca_Security) — Agentless Scanner

## Startup Solution Stack

- [Cloud Remediation Service](/Services/Cloud_Remediation_Service) — Service-as-Software
- [Topology Discovery Agent](/Agents/Topology_Discovery_Agent) — Agent
- [Ingress Remediation Worker](/Agents/Ingress_Remediation_Worker) — Agent
- [Ingress Mapping Engine](/Software/Ingress_Mapping_Engine) — Software
- [Network Policy SDK](/Software/Network_Policy_SDK) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the architect of an impenetrable perimeter, not a firefighter chasing alerts
- **Want**: to eliminate every hidden entry point into their cloud infrastructure
- **Identity**: the cloud security lead at a scaling SaaS provider
**Plan**:
- Step: Map · Detail: Trace every multi-hop routing path across AWS and Azure to reveal hidden ingress points.
- Step: Review · Detail: Inspect the simulated blast-radius on a topological twin to ensure remediation won't break production traffic.
- Step: Seal · Detail: Authorize the platform to execute scoped network changes that permanently close the exposure.
**Guide**:
- **Empathy**: Zero-day windows are won in minutes — but security teams are stuck waiting on manual Jira tickets to close known holes.
**Problem**:
- **Villain**: chained misconfigurations
- **External**: Prisma Cloud and native CSPMs generate static alerts for isolated ports but miss multi-hop ingress paths hidden in complex routing tables.
- **Internal**: You feel blind to the real attack surface while drowning in a sea of low-priority security notifications.
- **Philosophical**: Every security engineer deserves structural certainty — not a guessing game of snapshot alerts.
**Success**: The external attack surface exposure time drops below five minutes with zero undetected shadow ingress paths left in the environment.
**One Liner**: Instead of chasing fragmented alerts in a CSPM, Porosityscaffold maps and auto-remediates hidden topological ingress paths — ensuring a zero-exposure cloud perimeter.
**Positioning**:
- **So That**: hidden multi-hop attack paths are automatically mapped and sealed
- **Unlike**: snapshot-based CSPMs like Prisma Cloud
- **For Whom**: cloud security leads at scaling SaaS providers
- **Category**: Topological Cloud Ingress Remediation
**Call To Action**:
- **Direct**: Secure an environment
- **Transitional**: View topological twin sample
**Failure Stakes**:
- Exploitation of undetected shadow ingress
- Compliance failure during penetration tests
- Engineering burnout from manual remediation
**Transformation**:
- **To**: free to design resilient cloud architectures, no longer stuck closing manual network tickets
- **From**: a security analyst reacting to Tenable ASM snapshots
**Controlling Idea**: Cloud security should be a matter of topology, not a pile of alerts.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Instead of chasing fragmented alerts in a CSPM, Porosityscaffold maps and auto-remediates hidden topological ingress paths — ensuring a zero-exposure cloud perimeter.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: b2a817a6526954fc

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Topological Cloud Ingress Remediation for cloud security leads at scaling SaaS providers. Unlike snapshot-based CSPMs like Prisma Cloud — hidden multi-hop attack paths are automatically mapped and sealed.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: ce2cfe28a1b0f19a

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Prisma Cloud and native CSPMs generate static alerts for isolated ports but miss multi-hop ingress paths hidden in complex routing tables.
Solution: Instead of chasing fragmented alerts in a CSPM, Porosityscaffold maps and auto-remediates hidden topological ingress paths — ensuring a zero-exposure cloud perimeter.
Customer: cloud security leads at scaling SaaS providers
Unlike: snapshot-based CSPMs like Prisma Cloud
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 4db737770300df8f

## Startup Token M E D D P I C C

**Pain**: Prisma Cloud and native CSPMs generate static alerts for isolated ports but miss multi-hop ingress paths hidden in complex routing tables.
**Metrics**: Target: The external attack surface exposure time drops below five minutes with zero undetected shadow ingress paths left in the environment.
**Rendered**: Pain: Prisma Cloud and native CSPMs generate static alerts for isolated ports but miss multi-hop ingress paths hidden in complex routing tables.
Economic buyer: Cloud Security Architect
Metrics: Target: The external attack surface exposure time drops below five minutes with zero undetected shadow ingress paths left in the environment.
Competition: snapshot-based CSPMs like Prisma Cloud
**Mechanism**: spine-derived-v1
**Competition**: snapshot-based CSPMs like Prisma Cloud
**Economic Buyer**: Cloud Security Architect
**Vocab Fingerprint**: 9dc5db50374c3968

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Topological Cloud Ingress Remediation for cloud security leads at scaling SaaS providers

cloud security leads at scaling SaaS providers — Prisma Cloud and native CSPMs generate static alerts for isolated ports but miss multi-hop ingress paths hidden in complex routing tables. Instead of chasing fragmented alerts in a CSPM, Porosityscaffold maps and auto-remediates hidden topological ingress paths — ensuring a zero-exposure cloud perimeter.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 55e8c750c701a06b

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Topological Cloud Ingress Remediation. Instead of chasing fragmented alerts in a CSPM, Porosityscaffold maps and auto-remediates hidden topological ingress paths — ensuring a zero-exposure cloud perimeter. Serves cloud security leads at scaling SaaS providers.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: a78fc51150ec0120

## Neighborhood

### Candidate solutions

- [Procure Specialty Foam Materials](/Problems/Procure_Specialty_Foam_Materials) — candidate solution for · Problems

### What it offers

- [Ingress Mapping Engine](/Software/Ingress_Mapping_Engine) — offers · Software

### Composed of

- [Topology Discovery Agent](/Agents/Topology_Discovery_Agent) — composes · Agents
- [Cloud Remediation Service](/Services/Cloud_Remediation_Service) — composes · Services
- [Ingress Remediation Worker](/Agents/Ingress_Remediation_Worker) — composes · Agents
- [Network Policy SDK](/Software/Network_Policy_SDK) — composes · Software

### Embodies

- [Software](/Theses/Software) — embodies · Theses

### Competitors

- [Tenable ASM](/Competitors/Tenable_ASM) — competes with · Competitors
- [Wiz](/Competitors/Wiz) — competes with · Competitors
- [Orca Security](/Competitors/Orca_Security) — competes with · Competitors
- [Prisma Cloud](/Competitors/Prisma_Cloud) — competes with · Competitors
- [Periodic Penetration Testing](/Competitors/Periodic_Penetration_Testing) — competes with · Competitors

### Similar Startups

- [Accirm](/Startups/Accirm) — similar · Startups
- [Cloudint](/Startups/Cloudint) — similar · Startups
- [Mythenith](/Startups/Mythenith) — similar · Startups
- [Dalatigue](/Startups/Dalatigue) — similar · Startups
- [Incisive Software](/Startups/Incisive_Software) — similar · Startups
- [Wavoblem](/Startups/Wavoblem) — similar · Startups
- [Aspenmere](/Startups/Aspenmere) — similar · Startups
- [Awarestack](/Startups/Awarestack) — similar · Startups
- [Mapleshape](/Startups/Mapleshape) — similar · Startups
- [Weldedrock](/Startups/Weldedrock) — similar · Startups
- [Triquint](/Startups/Triquint) — similar · Startups
- [Weborb](/Startups/Weborb) — similar · Startups
- [Atonyx](/Startups/Atonyx) — similar · Startups
- [Shadowyard](/Startups/Shadowyard) — similar · Startups
- [Zenithember](/Startups/Zenithember) — similar · Startups
- [Forgouble](/Startups/Forgouble) — similar · Startups
- [Aurossom](/Startups/Aurossom) — similar · Startups
- [Verow](/Startups/Verow) — similar · Startups
- [Zerodaycrest](/Startups/Zerodaycrest) — similar · Startups
- [Shielduffer](/Startups/Shielduffer) — similar · Startups
