Welcome to Retrievy
Retrievy is the single pane of glass for your security posture across cloud accounts, identity providers, and on-prem infrastructure. You connect your environments, Retrievy ingests findings, and you triage and remediate from one place. One score, one Kanban, one set of compliance reports.
This Getting Started flow takes you from a fresh sign-up to a workspace with your first scan landed, your team invited, and an idea of where you sit. About 30 to 45 minutes end-to-end, most of which is wait time on the first scan.
Who Retrievy is for
| Role | What you'll do in Retrievy |
|---|---|
| Security Operations | Live in the Hardening Kanban. Triage findings as they come in. Resolve, escalate, or accept risk. |
| Compliance Officer | Live in the Compliance Hub. Map findings to CIS, NIST, ISO, SOC 2, PCI, HIPAA, MITRE ATT&CK, and the rest of the catalog. Export evidence for auditors. |
| CISO / Security Lead | Live in the Command Center. Watch the Retrievy Index trend. Pull executive reports for the board. |
| Workspace Admin | Manage seats, plans, integrations, and roles. The first three pages of this guide are written for you. |
You don't have to be all four. A two-person security team can use Retrievy fine; a hundred-person SOC can also use Retrievy fine. The product scales sideways across roles, not just headcount.
What Retrievy actually does
- Connects to data sources. AWS, Azure, GCP, Cloudflare, OCI, Microsoft 365, FortiGate firewalls, Windows servers with Active Directory.
- Runs scans. A managed scanner for cloud, a self-hosted Retrievy Agent for on-prem.
- Ingests findings. Each finding gets a severity (Critical / High / Medium / Low / Informational) and a state (Open, Pending Verification, Resolved, Risk Accepted, etc.).
- Computes a single score. The Retrievy Index is one number from 0 to 100 that captures your overall posture. Per-module sub-scores let you drill down.
- Surfaces work. The Hardening Kanban shows what needs attention. Remediation Projects group related work into trackable initiatives. Security Exceptions formalise risk acceptance.
- Maps to frameworks. The Compliance Hub shows your findings through the lens of CIS Benchmarks, NIST CSF, and MITRE ATT&CK.
- Exports for leadership and auditors. Executive PDF for the board, Technical PDF for the engineers, per-project PDF for the auditor.
That's the whole product. Everything else is configuration around those building blocks.
What you'll do in this section
Four pages, in order:
- Create your workspace — sign up at retrievy.com, verify your email, pick a plan, land on your Command Center.
- Run your first scan — connect one data source (cloud account or agent), watch the first scan complete, see findings flow into the Kanban.
- Invite your team — bring in teammates with the right roles, set up SSO if your plan includes it, require 2FA.
- (You're back to the day-to-day product after that.) The Features section covers every module in depth, and the Concepts section covers the model behind the scoring.
You can skip ahead at any point. The pages are designed to stand alone, with a Before you start block at the top of each.
A note on the Retrievy Index
You'll see the Retrievy Index number across most pages, and it's worth two sentences here. It's a 0 to 100 score (with a letter grade A through F) computed from the weighted count of your unresolved findings divided by the total checks the scanner ran. The math is in How the Retrievy Index is calculated; the gist is that more findings drop your score, more checks raise the ceiling, and severity matters more than count.
If your first scan lands and the number is lower than you hoped, that's normal. The Index is calibrated for honesty, not vanity. A first-day score of 60 is a baseline, not a verdict.
Related
- Retrievy Index overview
- Command Center (where you'll spend most of your time after onboarding)
- Hardening Kanban (where the team will spend most of their time)
- Plans and pricing (so you can pick a tier before signing up)