How it works
From credential to report
Four stages, no agents to deploy and no write access to grant.
- 1
Connect a read-only credential
Add an AWS access key or cross-account role, an Azure service principal, a Google Cloud service account, a Kubernetes service account token, an SSH login, or a verified URL. A1 Cloud Guard calls the provider to confirm the credential works before it is stored, so a broken credential is caught immediately rather than hours later mid-scan. Every secret is encrypted with AES-256-GCM and never sent back to the browser.
- 2
Choose scope and schedule
Select the services and regions a scan should cover. Run it immediately, schedule it for a specific time, or repeat daily, weekly or monthly. Scan profiles let you save a rule set per platform and apply it consistently.
- 3
Scanners do the work
Each platform has its own scanner working from a shared queue. They query provider APIs read-only, or connect over SSH with the host key verified against the fingerprint recorded when the credential was added. If a scan stops making progress, a sweep marks it failed and records why.
- 4
Read, route and record
Findings arrive scored on one severity scale with impact and remediation attached. Filter by region, service, severity or status — filters live in the URL so a view can be shared. Export a PDF, email it, or route alerts to Slack, Teams, PagerDuty, Jira or your own webhook.
Try it on one account
The free plan runs a complete scan and shows the entire report.