MayoCSPMOpen workspace →
OPEN SOURCE · SELF-HOSTED · EARLY PREVIEW

Your cloud is complex.
Its security shouldn’t
be out of reach.

Understand what runs in AWS, query the configuration, and see how risks connect. Keep your inventory on infrastructure you control.

Apache 2.0No disk snapshotsNo container image downloads
CONFIGURATION MODELIllustration
Internetuntrusted networkSecurity groupunrestricted SSHApplicationEC2 configurationGitHub repositoryoptional SARIF findingsCandidate exposure
Configuration context, with uncertainty made explicit.
Reachability and exploitation are not inferred as fact.
Metadata, not your workloadsSmall collection scopesExplainable risk prioritiesNo license fee for the engine

A CLEARER PICTURE, WITH LESS COLLECTION

Useful context. A deliberate footprint.

01

Connect read-only

Use an AWS role and temporary credentials. Choose regions, services, and collection limits before scanning.

AWS configuration APIs
02

Ask your inventory

Filter resources by type, region, name, and ownership tags. Inspect the evidence behind each finding.

Query stored metadata
03

Follow the relationships

Model public configuration and attached security groups. Link repository findings through explicit resource tags.

Candidate exposure, clearly labeled

DESIGNED FOR YOUR OWN HARDWARE

Set a budget.
Keep it visible.

Start with one region, 1,000 resources, and 300 logical API calls per scan. Bounds, denied permissions, and incomplete coverage stay visible.

Docker defaults cap the app, worker, and database at 1.5 CPUs and 1,280 MiB combined. Build-time resources and filesystem storage need separate host controls.

Read the collection contract ↗

Estimate your collection frequency

A request-budget estimate, not an AWS bill or performance guarantee.

300average budgeted collector calls / day

SDK retries allow up to two HTTP attempts per call. Role setup adds STS requests. Counts are capped; AWS billing is service-specific.

OPEN ENGINE. PRACTICAL SUPPORT.

Start free. Build on your terms.

AVAILABLE · EARLY PREVIEW

MayoCSPM Community

Free Apache 2.0 engine

Self-hosted inventory, 15 initial posture checks, configuration diagrams, workspace roles, schedules, and optional GitHub alert or SARIF ingestion.

Get the source →
COMMERCIAL SERVICES · PLANNED

Mayo CSPM

Your cloud. Help when you need it.

The commercial direction is setup assistance, supported upgrades, and managed operations. Pricing, billing, and hosted customer signup are not launched.

Meet the developer ↗

Cloud security you can inspect.

Try the synthetic demo, read the checks, and help shape what comes next.

Explore the project →See the roadmap ↗