Cloud posture baseline
AWS, Azure, GCP, and Kubernetes checks cover high-value storage exposure, logging,
monitoring, network exposure, identity, key management, RBAC, and pod security.
Azure, GCP, and Kubernetes support plan mode for non-mutating change preview.
Controlled remediation
AWS apply mode supports selected S3 settings, EBS encryption by default, IAM Access
Analyzer, and VPC Flow Logs when an approved destination is configured. Policy
validation uses JSON Schema for precise error reporting.
Rollback evidence
AWS rollback restores supported manifest-backed changes including S3 public access,
default encryption, EBS encryption-by-default, tool-created Access Analyzers, and
VPC Flow Logs. Irreversible operations are reported as manual.
OS and local scanners
Linux, macOS, Windows, FreeBSD, and Alpine scripts cover host baselines. Docker,
secrets, Terraform plan, and network/TLS scanners add explicit scoped evidence for
local and CI/CD workflows.
Enriched SARIF reporting
SARIF output includes full descriptions, help URIs, NIST CSF / ISO 27001 / CIS
framework tags, security-severity scores, and markdown remediation guidance.
JSON findings are documented with a reusable schema for downstream ingestion.
Container image
A pre-built container image is published to GitHub Container Registry (GHCR) on
every release. Run audits in CI/CD pipelines without installing Python dependencies.
Secure by design
Structured logging with automatic secret redaction, SSRF-protected webhook
notifications, input validation on all CLI data, rate-limited API calls with
exponential backoff retry, and concurrent provider execution with error isolation.