Solutions · CyberSec · Prove

Know what you cannot see.

Coverage Assurance measures what your security tools and telemetry actually observe across your estate, and treats every blind spot as a finding with a cause, an effect and the action that closes it.

More of your estate observed, and every blind spot on a list.

  • More of each domain observed. Measured by VCR, Visibility Coverage Rate.
  • Fewer open coverage gaps. Measured by open coverage gaps.
  • Fewer unobserved segments on paths to your crown jewels. Measured by UNKNOWN segments on crown-jewel paths.
VCR · Visibility Coverage Rateagent-install countsup against your baseline · every gap a finding

Supporting KPIs

Coverage per domain ↑

Share of each domain observed, against a denominator the twin discovered

coverage map

Open coverage gaps ↓

Blind spots with no closing action taken

coverage map

UNKNOWN segments on crown-jewel paths ↓

Unobserved segments on a path to a crown jewel

twin

Unowned and unclassified assets ↓

Assets with no owner or no business classification

twin

Answers refused for staleness ↓

Questions refused because their oldest fact exceeded its budget

twin history

Baselines are set in the 30-day diagnostic. Targets are committed in the 90-day scorecard. A KPI we cannot measure is reported as UNMEASURED.

No observed traffic is not no traffic.

When a log source is switched off, most tools show that environment as quiet. Quiet reads as safe, and nobody is told the difference.

Read why

Coverage is usually reported as the share of assets with an agent installed. That denominator counts only what someone already knew about. The asset nobody listed is covered by definition.

Every answer a security programme gives is only as good as what it could see, and almost none of them say so.

What it costs

  • Blind spots presented as safe environments.
  • Coverage figures that look complete because the denominator was incomplete.
  • Decisions made on answers that never stated their limits.

Three environments. One of them is not quiet. It is unobserved.

  • vpc-hl-prod · flow logs: present
  • vpc-hl-dev · flow logs: partial
  • vpc-hl-staging · flow logs: off · observed traffic: no data · UNKNOWN

Answers about staging say UNKNOWN. Never "no traffic, therefore safe".

illustrative · Harbourline Financial is the worked example used across this site

Coverage as a measured number, and every gap as work.

Coverage Assurance is the first thing SecSemantic's twin produces, and it keeps measuring for as long as the twin runs.

Within 30 minutes of connecting a cloud, a coverage report: here is what we can and cannot see.

What you get

  • A coverage report per domain and environment, with an evidence-derived denominator
  • A gap register: every blind spot with its cause, effect and closing action
  • A normalised, deduplicated view of your existing tools' findings on real assets
  • An ownership and classification backlog
  • A coverage trend over time

Industry lens

Evidence of what is and is not monitored, for the auditor's first question.

What it is not

Not an asset inventory or a CMDB replacement. It measures what your estate reveals and what your tools can see.

FAQ

What exactly does the coverage report measure?

What the twin observes in each domain and environment, against a denominator it discovered from your estate, with every gap listed alongside its cause and the action that closes it.

How is this different from an agent-coverage dashboard?

Two ways. The denominator comes from evidence rather than from a list someone maintains, and a gap is a finding you can act on rather than a missing row.

What does UNKNOWN mean?

That part of the estate is not observed. It is treated as possibly open, never as safe, and any answer that depends on it says so.

Do we need to install anything?

No agents. Read-only credentials to your clouds, and the outputs your existing tools already produce.

How soon do we get the first report?

Within 30 minutes of connecting a cloud.

Does it replace our CMDB or asset inventory?

No. It measures what your estate reveals and what your tools see, and can show where they disagree.

Why start here?

Every other solution's answers are limited by what the twin can see. Coverage Assurance makes those limits visible first, so every later result can be believed.

How Coverage Assurance is delivered

A capability, the people who run it with you, and numbers you can check.

  • Diagnostic · days 0 to 30, at no cost.

    The twin is launched and the first coverage report arrives within 30 minutes. Your existing tools' findings and telemetry are connected, the gap register is ranked by what each gap stops you from answering, and every KPI baseline is measured.

  • Outcome · days 30 to 90.

    Gaps are closed with your teams in order of consequence, and ownership and classification backlogs are worked down.

  • The Semantic Loop · from day 90.

    Every new account, environment and log source is measured as it appears.

The pod

two senior engineers and a fractional CISO advisor

  • Forward-deployed security engineer.

    Deploys the twin, connects your sources, runs the gap register with your teams and owns the KPI baseline with you.

  • Exposure analyst.

    Ranks every gap by what it stops you from answering and tracks each one to its closing action.

  • Fractional CISO advisor.

    Owns the 90-day scorecard with your leadership and chairs the day-90 review.

What runs underneath

SecSemantic's Sentinel: the context graph, entity resolution, business context and crown jewels, findings and coverage, and trust and correctness. Insights presents posture and coverage, read-only.

Start with what you cannot see.

Connect one cloud, read-only. Within 30 minutes you have a report of what the twin can and cannot see, and every gap comes with the action that closes it.

  • SOC 2Type 2
  • HIPAACompliant
  • GDPRCompliant
  • ISO 270012013
  • ISO 90012015
  • ISO 200002018
  • ISO 134852016