The guardian layer for cloud infrastructure.
Heimdall Systems builds the tools that let cloud teams design secure AWS environments — then mathematically prove the guardrails around them actually hold.
Most security tooling tells you an architecture "looks" safe. We'd rather show you. Heimdall Build turns a secure design into policy in minutes; Invariant hands that policy to a theorem prover and proves nothing was silently weakened. Two products, one standard: proven, not assumed.
No account required to start — see how the two products fit together.
-
01
Design
Sketch a secure AWS architecture from templates or from scratch.
Heimdall Build -
02
Validate
Check the design against AWS Security Reference Architecture controls, live.
Heimdall Build -
03
Prove
Hand the resulting SCPs/RCPs to Z3 and prove no guardrail regressed.
Invariant -
04
Operate
Continuous, fleet-wide proof across every account in your org.
Roadmap
From first sketch to proven guardrail
Every stage shares one goal: replace "we think this is safe" with a check you can point to. Two stages ship today; the third is next on the roadmap.
Design & Validate
Heimdall Build is a visual AWS architecture designer that checks every draft against the AWS Security Reference Architecture as you build it — client-side, free, no account required.
Open Heimdall Build →Prove
Invariant hands your Service Control Policies and Resource Control Policies to the Z3 theorem prover and proves whether a guardrail regression exists — with a concrete counterexample when it doesn't hold.
View on GitHub →Operate
A unified view that runs Invariant's proofs continuously across every account in an AWS Organization, so drift is caught the moment it lands — not at the next audit.
Get notified →Two products. One standard for proof.
Use them together as a design-to-proof pipeline, or independently — both are free to start.
Heimdall Build
A visual AWS architecture designer with security compliance built in. Start from a template — Serverless API, 3-Tier Web, ETL Pipeline — or drag together your own VPCs, EC2, and RDS, and get real-time validation against 12 AWS Security Reference Architecture controls as you go.
- Template-based auto-design or manual drag-and-drop
- Live validation against 12 AWS SRA controls, with a documented-justification workflow for accepted risk
- Five client-side exports: Markdown docs, JSON for CI/CD, OPA Rego, editable draw.io diagrams, Terraform scaffolding
- Runs entirely client-side — no account, no data leaves your browser
Invariant
SMT-based guardrail SAST for AWS Service Control Policies and Resource Control Policies. Invariant hands your policies to the Z3 theorem prover and asks one precise question: is there any (action, resource, principal) request that used to be denied, but isn't anymore?
- Baseline scan against bundled AWS Landing Zone Accelerator guardrails — nothing to configure to start
- Regression diff against your own reference policies, with a git-diff-derived manifest
- Concrete
(action, resource, principal)counterexamples, not a fuzzy severity score - CI-native: JSON and SARIF output, configurable exit codes, GitHub Actions & GitLab CI templates included
pip install invariant
Three ways to work with Heimdall
Start with free, open tools. Bring us in when you need the guardrails proven across a whole estate, not just one repo.
Open tools
Heimdall Build and Invariant are free to run today — no sales call, no account, no seat licence. Point Invariant at a repo or open Heimdall Build in a browser and get a result in minutes.
Platform
A hosted view that runs Invariant's proofs continuously across an entire AWS Organization and links every finding back to the design that produced it in Heimdall Build.
Advisory
Embedded engagements to harden an existing Landing Zone Accelerator estate, wire guardrail proofs into CI/CD, and train internal teams to extend the check registry themselves.
Built around one idea
A guardrail is only as good as your ability to prove it still works after the next change.
Prove, don't assume
Every check either produces a proof or a concrete counterexample — not a severity score.
Zero friction to start
No account, no manifest, no config to get a first result out of either product.
Built by practitioners
Shaped by real AWS Landing Zone Accelerator work, not a generic compliance checklist.
Open by default
The design tool and the solving engine are free and open — the platform is what you pay for.