| Trust-path explainability | Full chain: identity → privilege → workload → resource, with evidence. | Risk score on a finding; chain is not surfaced. |
|---|
| Rollout safety | Read-only ingest; simulated remediation; staged enforcement built in. | Hardening is a write op handed to a separate tool, with no simulator. |
|---|
| Open-core architecture | Apache 2.0. Full source on GitHub. Self-host the same binary we run. | Closed source. Black-box detection logic. Audit-by-vendor-promise. |
|---|
| Who owns the fix | Identrail names the resource owner and routes the playbook to them. | Findings dropped into a security queue with no automatic owner mapping. |
|---|
| Cost shape | Free self-host. Hosted plan starts at $19/user/mo. No enterprise floor for SAML. | Sales-led pricing. SSO and core controls behind enterprise tier. |
|---|