Vishcore Inc. vishcore.

how it works

Methodical cloud work, scoped before production changes.

The operating model is simple: inspect first, scope second, remediate with infrastructure code, then hand over evidence and the next queue. A skeptical CTO should grasp the engagement in under sixty seconds.

vishcore [how it works]

client@discovery:~$ vishcore delivery --mode evidence-first

read‑only review before any recommendation

rollout order matched to production risk

auditor-readable handoff after changes land

delivery workflow

Six steps. One engagement, end to end.

Each step shows who owns the decision and what artifact comes out of it.

01 / 06 pressure

Pressure arrives.

SOC 2 deadline, buyer security review, disaster recovery gap, or Terraform drift the team can no longer defend.

owner: client
02 / 06 read‑only

Vishcore starts read‑only.

Client-created cross-account role with External ID, scoped to the scanner allowlist. No writes, no Terraform, no secret values read.

owner: vishcore
03 / 06 report

Scan and report.

Controls evaluated, gaps classified into confirmed fix, owner context, permission-limited, or not observed.

artifact: sample-cloud-control-scan.json
04 / 06 decide

Decision call.

The client confirms what should be fixed, what is intentional, and what stays out of scope. Vishcore does not decide alone.

owner: client + vishcore
05 / 06 remediate

Approved remediation.

Terraform pull requests or scoped manual changes only after written approval. Rollout order matched to production risk.

owner: vishcore
06 / 06 handoff

Evidence packet.

Before/after report, screenshots and API evidence, owner-context worksheet, and the auditor handoff.

artifact: before/after evidence packet

safety boundary

Three rules that hold from first message to handoff.

01

Read‑only by default.

Discovery uses a client-created cross-account role with External ID, scoped to the Vishcore scanner allowlist. No writes, no Terraform, no secret values read, no remediation during discovery.

policy · scanner allowlist + deny guards
02

No secrets in the first message.

Inquiry email and fit-check exchange happen before any AWS access. No portal login, no access request, no secret values, no production credentials.

boundary · fit-check before access
03

Remediation requires written approval.

Every change ships as a reviewable Terraform pull request or scoped manual ticket, after the client confirms rollout order and exclusions. Discovery does not change production.

contract · signed scope · no auto-fix

what discovery produces

A buyer-reviewable report, not a sales pitch.

The discovery scan returns a counts strip, a triage of every gap, a remediation queue sorted by production risk, and an owner-context worksheet for the items where business intent matters more than the control state alone.

The buyer sees the shape of the deliverable before approving paid work.

See the full sample scan

Illustrative example based on the current Vishcore scanner report shape. The example is sanitized, client-safe, and not presented as a client endorsement.

Discovery uses read-only cloud metadata. It does not create, change, delete, remediate, or read secret values.

This is not an audit opinion, compliance certification, or guarantee that an environment will meet SOC 2 requirements.

~ $ vishcore report --input scan-result.json --format html

client@discovery:~$ vishcore report --input scan-result.json --format html

control counts

evaluated controls
147
OK
79
observed gaps
39
blocked or explicit approval
6
not observed
23

remediation queue · first 3

  1. P1 S3 public-access guardrails owner: aws account owner plus application owner
  2. P1 Root and IAM access hygiene owner: aws account owner
  3. P1 Default security group posture owner: network or platform owner

real engagements

Where each step has shown up in actual client work.

Every row links to an approved client story on the work page. Same six steps, four named teams.

Start with context, not a generic audit checklist.

Send the pressure point, cloud provider, audit timeline, and where Terraform is trusted or not trusted. Vishcore replies with focused next-step questions, not a sales pitch.

Start discovery