Getting started
8200.dev is an autonomous data-security platform. It continuously maps who — and what — can reach your organization's data across your SaaS and cloud, scores the risk, and explains every finding in plain language. Three engines cover the surface: Posture Guard (misconfiguration and over-exposure), Flow Guard (contextual data-loss prevention), and Agent Guard (governance of AI agents and service identities).
It is built agent-native. As AI assistants, copilots, bots and service principals quietly accumulate access to your most sensitive resources, 8200.dev treats them as first-class identities — inventorying what each one can reach, what it has done, and whether it stays within the access policy you set.
Explainability first
Every finding carries a dated, plain-language reason and the evidence behind it — the exact resource, the exact grant, who or what holds it, and how far it reaches (the blast radius). You never get an opaque score with no way to act on it.
The same principle governs the AI verdict engine: a deterministic rule floor sets the hard decisions, an optional model escalates novel cases, and the engine degrades safely to the rules on any model error. A model can explain or escalate — it can never overrule a hard block.
Quick start
Five steps take you from sign-up to an auditor-ready report:
- 1Sign up with email and create your organization — no credit card, no sales call.
- 2Connect your first source — Google Workspace, Microsoft 365, Slack, Notion, GitHub or AWS IAM.
- 3Run a scan — the connector enumerates resources and identities and normalizes them into one model.
- 4Review findings — sorted by blast radius, each with a plain-language reason, the evidence, and a recommended fix.
- 5Generate a compliance report — SOC 2, ISO 27001 or GDPR access-control evidence, exportable as PDF or JSON.
- 6Optionally turn on prevention — opt in per connector to act on findings (simulate first; live writes are gated).
Explore in mock mode first
Every connector ships with a realistic mock dataset, so you can explore the entire product — scans, findings, compliance reports, even the full remediation loop — before you connect a single real credential. Findings and reports generated this way are clearly labelled as demo data.
When you connect a real source, the identical pipeline runs against live data. Mock mode is never a different product — it is the same engines over fixture data.