How it works

From credential to report

Four stages, no agents to deploy and no write access to grant.

  1. 1

    Connect a read-only credential

    Add an AWS access key or cross-account role, an Azure service principal, a Google Cloud service account, a Kubernetes service account token, an SSH login, or a verified URL. A1 Cloud Guard calls the provider to confirm the credential works before it is stored, so a broken credential is caught immediately rather than hours later mid-scan. Every secret is encrypted with AES-256-GCM and never sent back to the browser.

  2. 2

    Choose scope and schedule

    Select the services and regions a scan should cover. Run it immediately, schedule it for a specific time, or repeat daily, weekly or monthly. Scan profiles let you save a rule set per platform and apply it consistently.

  3. 3

    Scanners do the work

    Each platform has its own scanner working from a shared queue. They query provider APIs read-only, or connect over SSH with the host key verified against the fingerprint recorded when the credential was added. If a scan stops making progress, a sweep marks it failed and records why.

  4. 4

    Read, route and record

    Findings arrive scored on one severity scale with impact and remediation attached. Filter by region, service, severity or status — filters live in the URL so a view can be shared. Export a PDF, email it, or route alerts to Slack, Teams, PagerDuty, Jira or your own webhook.

Try it on one account

The free plan runs a complete scan and shows the entire report.