Features

Everything A1 Cloud Guard does

Grouped by what you are trying to accomplish — scanning your estate, reporting on it, controlling who sees it, and keeping credentials safe.

Scanning

Six platforms, one workflow

AWS, Azure, Google Cloud, Kubernetes, Linux hosts and web applications — 194 services in a single catalog, scanned from one console.

Scheduled and on-demand scans

Run immediately, schedule once, or repeat daily, weekly or monthly. Pick the exact services and regions each run should cover.

Targeted rescans

Re-run a whole report, a single service, or one affected resource, without repeating the entire scan.

Scan profiles

Save per-platform rule sets so every scan applies the same policy, and mark one as the default for that platform.

Severity scoring

Every finding carries a CVSS-style score mapped to Critical, High, Medium, Low and Info, so triage order is unambiguous.

Stalled scan detection

A sweep marks jobs that stop making progress as failed and records why, instead of leaving a report stuck in progress.

Reporting

PDF reports

A formatted assessment with severity summary, per-region breakdown, affected resources, impact and remediation for each finding.

Email delivery

Send any report to a mailbox on demand, or let a scheduled scan deliver it when it finishes.

Findings explorer

Filter by region, service, severity and status. The filters live in the URL, so a filtered view can be shared or bookmarked.

Account history

Drill into a connected account by region and service to see how a finding changed across scans.

Dashboard rollups

Severity distribution, issues per service, and the most affected resources across every account in the organization.

Team & access

Organizations

Group accounts, credentials and reports per organization, and switch between them without signing out.

Roles

Owner, admin and member. Only owners and admins can invite people or change notification routing.

Email invitations

Invite by address with a signed, expiring link that only the invited address can accept.

Two-factor authentication

TOTP with any authenticator app, plus single-use backup codes.

Google sign-in

Optional Google OAuth alongside email and password.

Audit log

Every sign-in, credential change, scan, invitation and role change recorded with actor, IP and timestamp — readable by organization admins.

Credentials

Seven credential types

AWS access key, AWS assumed role, GCP service account, Azure service principal, Kubernetes service account, Linux SSH, and authenticated HTTP endpoint.

Encrypted at rest

Every secret is sealed with AES-256-GCM. Values are never sent back to the browser once saved.

Validated on save

A1 Cloud Guard proves a credential works before storing it, so a scan never fails on a typo hours later.

Suspend without deleting

Pause a credential to stop it being scanned while keeping its history intact.

Domain verification

A web target must be proven under your control before it can be scanned.

See it against your own account

Connect one read-only credential and run a scan — the free plan shows the complete report.