Outpost
Use casesHow it worksPoliciesAccessAIIntegrationsPricingFAQ

Policies

Define how your stack should look.Outpost keeps it that way.

Codify your organization's standards as policies — across asset configuration, live state, and the people with access. Outpost evaluates every asset continuously and tells you the moment one drifts out of line.

Back to overview

The rule builder

Compose a rule in plain language.

Pick a subject — an asset type or a person — then a condition over its configuration, its state, or its access, an operator, and the value you expect. No query language to learn, no scripts to maintain.

Outpost applies the rule across every matching asset the moment you save it — and keeps applying it as your stack changes.

Policy rule

Draft

Subject

Every Domain

Condition

Response header · Content-Security-Policy

Operator

must exist

Expected

Required

Evaluated against 144 domains continuously

One policy engine, three surfaces

Write policy against anything Outpost sees.

Configuration, live state, and the people with access — all in the same builder, all evaluated against the inventory you've already connected.

Asset configuration

The settings an asset ships with. Write rules against any field Outpost syncs from the source.

Content-Security-Policy header present

TLS 1.2 or higher

Repository visibility is private

Asset state

The live posture of an asset, evaluated continuously — not just how it was configured once.

Certificate not expiring within 14 days

No DNS record drift

No port open to 0.0.0.0/0

People & access

The identities and access attached to your assets, synced from every connected provider.

All members use a corporate email

MFA enforced for every account

No standing admin outside the owners group

Example policies

The standards you've been enforcing by hand.

Each policy reads in plain English and reports live compliance across every asset it covers.

Every site must ship a Content-Security-Policy.

142 / 144 compliant

2 drifted

All members must use a corporate email address.

218 / 221 compliant

3 drifted

All repos must be private — except approved open source.

96 / 97 compliant

1 drifted

Every account must have MFA enforced.

219 / 221 compliant

2 drifted

Drift detected

shop.acme.com

j.rivera@acme.com edited the Cloudflare zone

2:14 PM

Content-Security-Policy header removed

drift detected

Finding raised · routed to #security-alerts

2:14 PM

Drift detection

Know the moment something falls out of policy.

A setting changes, a header disappears, an account loses MFA — Outpost re-evaluates the affected policies and raises a finding with the full context: what changed, who changed it, and when.

Findings stay open until the asset is back in spec, then resolve themselves automatically. No stale tickets, no manual bookkeeping.

Alert routing

Send every alert exactly where it belongs.

Route violations by severity, policy, or asset group. Page on-call for criticals, drop the rest in Slack, and pipe everything to your own systems through webhooks and message queues. Alerts are deduplicated, so a noisy change is one notification, not fifty.

PagerDuty

PagerDuty

SMS

Email

Slack

Slack

Microsoft Teams

Microsoft Teams

Webhooks

Amazon SNS

Amazon SNS

Amazon SQS

Amazon SQS

Google Pub/Sub

Google Pub/Sub

Alert routing

CSP policy violated

PagerDuty

Critical

Slack · #security

High

Email digest

Info

See your full digital landscape.Before someone else does.

Join the waitlist for early access. Be among the first to know when Outpost launches, and lock in founding-customer pricing.

Built for security teams that can't be everywhere at once.