Launched this week

Retrievy
See and improve your security posture in one place.
3 followers
See and improve your security posture in one place.
3 followers
Retrievy helps security teams understand what is exposed, what matters most, and what to fix next. It brings cloud, identity, Active Directory, Microsoft 365, and FortiGate security into one clear workspace. Teams can find hidden risks, prioritize remediation, assign ownership, track progress, and verify fixes with fresh scans. Instead of scattered tools and static reports, Retrievy turns security posture into an ongoing, practical workflow.








Hey Product Hunt! 👋
I'm Ney. I spent most of the last decade working in cybersecurity consulting, and I kept seeing the same problem from one environment to another. An Active Directory with 15 years of permissions nobody could explain. A firewall ruleset last touched by someone who left years ago. Cloud accounts and configurations quietly drifting in the background.
Different systems. Different tools. Different reports.
And somehow, one person was expected to connect all the dots.
That's why I built Retrievy. Retrievy is designed to give IT teams a clearer view of what's actually happening across their environment. This is my attempt at closing that loop. Three X-Ray engines, each answering a question the native console doesn't.
Identity X-Ray. A list of privileged users tells you who is an admin. It never tells you who can become one. This builds the privilege graph across every Data Source you connect (Entra ID, Active Directory, AWS, Azure, GCP, M365, Google Workspace, GitHub, FortiGate) and draws the real paths to Tier 0, with the chokepoints, shadow admins and MFA gaps along them.
GPO X-Ray. GPMC shows you which GPOs exist, not which setting wins after LSDOU precedence or which machines a change is about to hit. This shows both, plus a blast radius per GPO and a hygiene view for orphaned and shadowed ones.
FortiGate Policy X-Ray. 45 Layer 7 checks across SSL, AV, IPS, AppControl, WebFilter, DNS and DLP. My favourite is the Domino Effect: miss deep inspection on one policy and every downstream control on that HTTPS traffic goes blind, so you get one root cause instead of seven unrelated findings.
Compliance falls out as a by-product. Findings auto-map to 20+ frameworks as they land (CIS, NIST CSF 2.0, ISO 27001, PCI DSS 4.0, SOC 2, HIPAA), and when your policy fits none of them, the Framework Builder lets you assemble your own catalog from any of their requirements.
Built solo over about a year of nights and weekends while consulting full time.
I'd love to hear what you think!