Configuration drift and security posture monitoring, in one place.
ConfigTrace monitors your cloud infrastructure and SaaS tools for configuration drift and security posture risk. It snapshots configuration on a schedule, detects what changed, classifies the risk, and gives your team a single timeline to diagnose incidents and catch risky changes before they become outages.
Read-only by design
Every provider connection uses read-only, scoped credentials. ConfigTrace only ever reads configuration state to build snapshots, detect changes, and evaluate security posture — it never modifies resources in a connected cloud or SaaS account.
What ConfigTrace does
Continuous configuration snapshots
ConfigTrace connects to your cloud and SaaS providers on a schedule and takes point-in-time snapshots of their configuration — no agents to install.
Change detection & diffing
Every new snapshot is diffed against the last one. Additions, removals, and modifications are captured as structured, resource-level changes.
Risk classification
Detected changes are classified by risk — from routine to critical — so the ones that matter surface first instead of getting lost in noise.
Unified change timeline
A single timeline correlates changes across every connected provider, making it easier to diagnose incidents caused by configuration drift.
Security posture & findings
Beyond drift, ConfigTrace evaluates provider-specific configuration against a rules engine to surface exposed resources, weak policies, and privilege risks.
Broad provider coverage
Cloud infrastructure (AWS, Azure, Google Cloud, Kubernetes, Cloudflare, Terraform Cloud), identity (Okta, Microsoft Entra ID, Auth0), and SaaS tools (GitHub, GitLab, Stripe, Snowflake, Sentry, Datadog, PagerDuty, Linear, Jira, and more).
Questions? Reach us at support@configtrace.org