Policies
Codify your organization's standards as policies — across asset configuration, live state, and the people with access. Outpost evaluates every asset continuously and tells you the moment one drifts out of line.
The rule builder
Pick a subject — an asset type or a person — then a condition over its configuration, its state, or its access, an operator, and the value you expect. No query language to learn, no scripts to maintain.
Outpost applies the rule across every matching asset the moment you save it — and keeps applying it as your stack changes.
Policy rule
Subject
Every Domain
Condition
Response header · Content-Security-Policy
Operator
must exist
Expected
Required
Evaluated against 144 domains continuously
One policy engine, three surfaces
Configuration, live state, and the people with access — all in the same builder, all evaluated against the inventory you've already connected.
The settings an asset ships with. Write rules against any field Outpost syncs from the source.
Content-Security-Policy header present
TLS 1.2 or higher
Repository visibility is private
The live posture of an asset, evaluated continuously — not just how it was configured once.
Certificate not expiring within 14 days
No DNS record drift
No port open to 0.0.0.0/0
The identities and access attached to your assets, synced from every connected provider.
All members use a corporate email
MFA enforced for every account
No standing admin outside the owners group
Example policies
Each policy reads in plain English and reports live compliance across every asset it covers.
Every site must ship a Content-Security-Policy.
142 / 144 compliant
2 drifted
All members must use a corporate email address.
218 / 221 compliant
3 drifted
All repos must be private — except approved open source.
96 / 97 compliant
1 drifted
Every account must have MFA enforced.
219 / 221 compliant
2 drifted
Drift detected
j.rivera@acme.com edited the Cloudflare zone
2:14 PM
Content-Security-Policy header removed
drift detected
Finding raised · routed to #security-alerts
2:14 PM
Drift detection
A setting changes, a header disappears, an account loses MFA — Outpost re-evaluates the affected policies and raises a finding with the full context: what changed, who changed it, and when.
Findings stay open until the asset is back in spec, then resolve themselves automatically. No stale tickets, no manual bookkeeping.
Alert routing
Route violations by severity, policy, or asset group. Page on-call for criticals, drop the rest in Slack, and pipe everything to your own systems through webhooks and message queues. Alerts are deduplicated, so a noisy change is one notification, not fifty.
PagerDuty
SMS
Slack
Microsoft Teams
Webhooks
Amazon SNS
Amazon SQS
Google Pub/Sub
Alert routing
CSP policy violated
PagerDuty
Critical
Slack · #security
High
Email digest
Info
Join the waitlist for early access. Be among the first to know when Outpost launches, and lock in founding-customer pricing.
Built for security teams that can't be everywhere at once.