METRIGRAPH PLATFORM PREVIEW

THE METRIGRAPH PLATFORM

Turn raw security findings into clear, prioritized decisions your team can act on.

READY TO BUILD SOMETHING GREAT?
Let's build your next digital product.
Start a project →
ABOUT US PREVIEW

ABOUT ARKAIC

We are a studio dedicated to building high-performance, secure software that lasts.

READY TO BUILD SOMETHING GREAT?
Let's build your next digital product.
Start a project →
CONTACT PREVIEW

LET'S TALK

Ready to secure your cloud or build your next platform? We'd love to hear from you.

READY TO BUILD SOMETHING GREAT?
Let's build your next digital product.
Start a project →
Flagship Product • Coming Soon

Know exactly what a
misconfiguration can
reach.

MetriGraph maps your cloud resources as a dependency graph and scores every finding by real-world reachability — not just severity on paper.


Blast Radius Scoring

Misconfiguration chaining shows you the path an attacker would actually take. We filter out the noise so you can focus on the critical intersections of your infrastructure while we finalize our engine.

0–100
Score Range
20+
Curated Checks
scan 2026-06-30.json73
S3 → IAM role
88
EC2 → RDS
61
Lambda → S3
74
VPC peering
34

How MetriGraph Works

Three-step analysis pipeline that turns raw cloud config data into actionable blast-radius intelligence.

01 — INGEST

Cloud Config Ingestion

Upload a snapshot JSON or connect your cloud account via read-only IAM role. MetriGraph snapshots your resource state in seconds.

02 — MAP

Dependency Graph Build

Every resource becomes a node. Trust relationships, network paths, and data flows become directed edges — revealing hidden attack surfaces.

03 — SCORE

Blast Radius Scoring

Each misconfiguration is scored 0–100 based on reachable blast radius — how many critical resources are compromisable downstream.


Curated Checks

Hand-engineered rules that surface real risk paths across AWS services — not just compliance noise.

S3

Public bucket with IAM role trust chained to sensitive data store

Critical

EC2

Overpermissive instance profile granting unscoped S3 write access

High

Lambda

Environment variable exposing credentials readable via public invoke

Critical

VPC

Unrestricted peering with cross-account data path to production RDS

High

IAM

Wildcard resource permissions on assume-role without MFA condition

Critical

RDS

Publicly accessible database with weak subnet group isolation

High

CloudTrail

Logging disabled in region containing sensitive workloads

Medium

STS

Long-lived credentials in use with no rotation policy enforced

Medium

Early Access

Be first to see your blast radius.

MetriGraph is in closed beta. Join the waitlist and we'll reach out when your spot opens — no commitments, full access.

Explore Our Services