AWS-native Proof-based, not pattern-matched Free to start

The guardian layer for cloud infrastructure.

Heimdall Systems builds the tools that let cloud teams design secure AWS environments — then mathematically prove the guardrails around them actually hold.

Most security tooling tells you an architecture "looks" safe. We'd rather show you. Heimdall Build turns a secure design into policy in minutes; Invariant hands that policy to a theorem prover and proves nothing was silently weakened. Two products, one standard: proven, not assumed.

No account required to start — see how the two products fit together.

// the guardian lifecycle
  • 01

    Design

    Sketch a secure AWS architecture from templates or from scratch.

    Heimdall Build
  • 02

    Validate

    Check the design against AWS Security Reference Architecture controls, live.

    Heimdall Build
  • 03

    Prove

    Hand the resulting SCPs/RCPs to Z3 and prove no guardrail regressed.

    Invariant
  • 04

    Operate

    Continuous, fleet-wide proof across every account in your org.

    Roadmap
Built on Z3 Bundled AWS LZA guardrails SARIF + JSON output OPA Rego · Terraform · draw.io export Apache-2.0 core
The platform

From first sketch to proven guardrail

Every stage shares one goal: replace "we think this is safe" with a check you can point to. Two stages ship today; the third is next on the roadmap.

Stage 01–02 Live

Design & Validate

Heimdall Build is a visual AWS architecture designer that checks every draft against the AWS Security Reference Architecture as you build it — client-side, free, no account required.

Open Heimdall Build →
Stage 03 Live

Prove

Invariant hands your Service Control Policies and Resource Control Policies to the Z3 theorem prover and proves whether a guardrail regression exists — with a concrete counterexample when it doesn't hold.

View on GitHub →
Stage 04 Roadmap

Operate

A unified view that runs Invariant's proofs continuously across every account in an AWS Organization, so drift is caught the moment it lands — not at the next audit.

Get notified →
Products

Two products. One standard for proof.

Use them together as a design-to-proof pipeline, or independently — both are free to start.

DESIGN & VALIDATE

Heimdall Build

A visual AWS architecture designer with security compliance built in. Start from a template — Serverless API, 3-Tier Web, ETL Pipeline — or drag together your own VPCs, EC2, and RDS, and get real-time validation against 12 AWS Security Reference Architecture controls as you go.

  • Template-based auto-design or manual drag-and-drop
  • Live validation against 12 AWS SRA controls, with a documented-justification workflow for accepted risk
  • Five client-side exports: Markdown docs, JSON for CI/CD, OPA Rego, editable draw.io diagrams, Terraform scaffolding
  • Runs entirely client-side — no account, no data leaves your browser
12SRA controls checked live
5export formats
0accounts required
Open Heimdall Build Free forever
PROVE

Invariant

SMT-based guardrail SAST for AWS Service Control Policies and Resource Control Policies. Invariant hands your policies to the Z3 theorem prover and asks one precise question: is there any (action, resource, principal) request that used to be denied, but isn't anymore?

  • Baseline scan against bundled AWS Landing Zone Accelerator guardrails — nothing to configure to start
  • Regression diff against your own reference policies, with a git-diff-derived manifest
  • Concrete (action, resource, principal) counterexamples, not a fuzzy severity score
  • CI-native: JSON and SARIF output, configurable exit codes, GitHub Actions & GitLab CI templates included
Z3SMT solver, not regex
2check modes: scan & regression
0manifest required for a first scan
View on GitHub Apache-2.0 / pip install invariant
How we work

Three ways to work with Heimdall

Start with free, open tools. Bring us in when you need the guardrails proven across a whole estate, not just one repo.

01 · Self-serve

Open tools

Heimdall Build and Invariant are free to run today — no sales call, no account, no seat licence. Point Invariant at a repo or open Heimdall Build in a browser and get a result in minutes.

02 · Coming next

Platform

A hosted view that runs Invariant's proofs continuously across an entire AWS Organization and links every finding back to the design that produced it in Heimdall Build.

03 · Hands-on

Advisory

Embedded engagements to harden an existing Landing Zone Accelerator estate, wire guardrail proofs into CI/CD, and train internal teams to extend the check registry themselves.

Why Heimdall

Built around one idea

A guardrail is only as good as your ability to prove it still works after the next change.

01

Prove, don't assume

Every check either produces a proof or a concrete counterexample — not a severity score.

02

Zero friction to start

No account, no manifest, no config to get a first result out of either product.

03

Built by practitioners

Shaped by real AWS Landing Zone Accelerator work, not a generic compliance checklist.

04

Open by default

The design tool and the solving engine are free and open — the platform is what you pay for.

Get started

Ready to prove your guardrails hold?

Start designing in Heimdall Build, or point Invariant at your existing AWS Organization config.

Questions about the roadmap or an advisory engagement? hello@heimdallsystems.co.uk