Connect read-only
Use an AWS role and temporary credentials. Choose regions, services, and collection limits before scanning.
AWS configuration APIsUnderstand what runs in AWS, query the configuration, and see how risks connect. Keep your inventory on infrastructure you control.
A CLEARER PICTURE, WITH LESS COLLECTION
Use an AWS role and temporary credentials. Choose regions, services, and collection limits before scanning.
AWS configuration APIsFilter resources by type, region, name, and ownership tags. Inspect the evidence behind each finding.
Query stored metadataModel public configuration and attached security groups. Link repository findings through explicit resource tags.
Candidate exposure, clearly labeledDESIGNED FOR YOUR OWN HARDWARE
Start with one region, 1,000 resources, and 300 logical API calls per scan. Bounds, denied permissions, and incomplete coverage stay visible.
Docker defaults cap the app, worker, and database at 1.5 CPUs and 1,280 MiB combined. Build-time resources and filesystem storage need separate host controls.
Read the collection contract ↗A request-budget estimate, not an AWS bill or performance guarantee.
SDK retries allow up to two HTTP attempts per call. Role setup adds STS requests. Counts are capped; AWS billing is service-specific.
OPEN ENGINE. PRACTICAL SUPPORT.
Free Apache 2.0 engine
Self-hosted inventory, 15 initial posture checks, configuration diagrams, workspace roles, schedules, and optional GitHub alert or SARIF ingestion.
Get the source →Your cloud. Help when you need it.
The commercial direction is setup assistance, supported upgrades, and managed operations. Pricing, billing, and hosted customer signup are not launched.
Meet the developer ↗Try the synthetic demo, read the checks, and help shape what comes next.
Explore the project →See the roadmap ↗