For investors, vCSOs & the boards they answer to
Cyber risk, grounded in evidence.
Theodolite deploys a scanner inside the environment you're invited into — a portfolio company, a client — and turns verified cloud evidence into coverage-qualified observed checks, severity-ranked Top Priorities, and an evidence-backed decision view. CIS Controls v8; every finding backed by live cloud evidence.
30-minute call. No slides. Real evidence from a guided walkthrough.
Current evidence sources and references
Assessment evidence sources
Cloud Evidence
Assessment Evidence
Data Discovery
Control Evidence
Theodolite
Illustrative example
Start with the question the evidence can answer
“What did the scan observe — and what could it not observe?”
A different approach to cyber risk.
Traditional
- ✕Siloed scans with no business context
- ✕CVSS scores that mean nothing to the board
- ✕Weeks to compile a risk report
With Theodolite
- ✓Coverage-qualified observed checks and failures
- ✓Evidence-backed risk reporting
- ✓Revenue-band annual-loss benchmark for context
The Story Behind Theodolite
“I built Theodolite because no tool gave me what I needed in that boardroom: a clear line from cloud evidence to the security decisions we had to make.”

Founder, Theodolite & vCSO
15 years CSO, SVB
◆Author, “Cyber War…and Peace” — on translating cyber risk for boards
Cyber Risk Evidence Map
Every finding backed by live cloud evidence.
Access Intelligence
Review provider-observed direct access across Azure, AWS S3, SharePoint, and bounded-beta Box with explicit unknown states. Complete account-wide effective reach, sensitive-data reach, and blast radius remain held where policy coverage or exact-generation evidence is incomplete.
See directly observed accessAssessment Evidence
Work from a 209-question master — 153 CIS Controls v8 and 56 cyber due-diligence questions. One favorable mapping is currently release-enabled when exact, current evidence supports it; the rest require review.
Discuss the guided workflowData Discovery
Scan Azure, AWS, SharePoint, and bounded-beta Box for PII, PHI, and credential indicators. Raw findings and detailed scan output remain stored in the customer-side scanner database, not the control plane.
See what a scan surfacesHow it Works