ethira

Custom Findings

Your rules, on a living graph.

Write free-text evaluators that Ethira turns into checks on the live inventory graph. Findings stay current as the estate changes.

Trusted by

Evaluators

From free text to continuous findings.

Karl Fredriksson

Karl Fredriksson

Founding Engineer

We kept hearing the same thing from security and platform teams: the controls they care about already exist in their heads, in policies and review checklists, but turning them into queries takes a specialist and a sprint. Custom Findings is our answer to that gap.

You describe the control in plain language, and we compile it into the method that fits: SQL over the inventory graph, OpenGrep rules over agent code, or other checks. I care a lot about this compilation step being transparent, so teams can see exactly what will run before it runs.

Because evaluators run against the live graph, findings stay current as the ecosystem changes. A rule you wrote in January still means something in June, because the inventory underneath it is never stale.

Free-text input

Describe what you care about in natural language ("flag any agent that can reach PII in the EU") without writing query syntax.

Generated methods

Ethira produces SQL over the inventory graph, OpenGrep rules over agent code, and other checks matched to the question.

Continuous findings

Evaluators re-run as the graph updates, so findings stay evidence-backed and current, not a snapshot from last quarter.

Standards

Standards that stay enforced

Zsolt Halo

Zsolt Halo

VP of Engineering

I spent a lot of time with teams whose findings tools produced noise: thousands of results, no owners, no reach. On Ethira, a finding is born on the graph, so it already knows which asset it belongs to, who owns it, and what data it can touch.

That context is what makes continuous evaluation practical. When a new vendor, agent, or dataset appears, the evaluators that touch it re-run, and the finding lands with evidence instead of a screenshot from last quarter’s audit.

We built this so security teams can encode their standards once and trust that they stay enforced, without turning every policy change into a query-writing exercise.

Get started

Encode your standards once.

Write the evaluators your security and platform teams already have in their heads, and let them run against the live graph.