Skip to content
CyberArmorApplication security engineering
São Paulo, Brasil · Infrastructure security

We harden the machines and the cloud your clients run on.

1,501 CIS benchmark rules in an endpoint agent that runs on Windows, Linux and macOS, 183 infrastructure-as-code rules and 100 container rules. Of the IaC rules, 111 are AWS, 16 are Azure and none are Google Cloud — if your clients run on GCP, you should know that before the proposal.

SARIFCYCLONEDXNESSUS XMLCSV

Where the coverage is thin, said out loud

0Google Cloud rules, against 111 for AWS and 16 for AzureMulticloud posture management.
0CVEs from RedHat or RPM packages — dpkg and apk only, from inside a container imageContainer and OS package scanning.
0authenticated web scans, and no certificate, cipher or TLS version inspectionDynamic application security testing.

A security vendor that claims to do everything is selling, not assessing. These are the same numbers we would have to admit in week two.

In your day

What runs without depending on you

  • I want to scan the client environment on a schedule

    Code with 198 rules across 14 languages; dependencies across 8 ecosystems, reading lock files and the transitive tree; secrets with 31 patterns; infrastructure as code with 183 rules; and containers with 100 Dockerfile and compose rules.

  • I need to know what is actually installed on those machines

    The agent keeps a software inventory, flags unauthorised installs, and detects which EDR is present on the machine. It reports what exists; it is not an EDR.

  • I need the hardening to be defensible

    The CIS benchmark is applied in a controlled way, with a trail of what was changed. 1,501 rules, three operating systems, a 30-second check-in interval.

The agent

What the endpoint agent does

Counted in the repository. What is not counted does not appear here.

1.501CIS benchmark rules, in an agent that runs on Windows, Linux and macOSControlled hardening, with a trail of what changed.
30 scheck-in intervalRead on the current public page and not measured in the code by whoever wrote this.
100container rules, plus 183 infrastructure-as-code rules111 AWS, 16 Azure, none for Google Cloud.
Limits

What we do not do

Every limit below was read in the code before it was written here, and it is in writing before the proposal, not after it.

  • RedHat and RPM generate no CVE

    Debian, Ubuntu and Alpine do, and only from inside a container image. The dependency engine reads no operating-system package at all.

  • Cloud coverage is lopsided

    In infrastructure as code: 111 AWS rules, 16 Azure rules, none for Google Cloud. If your clients are on GCP, this module does not serve them today.

  • The web scanner sees the anonymous surface

    It does not log in to your client system, and it does not inspect certificate, cipher or TLS version. When it confirms a flaw it stops there: no privilege escalation, no command execution, no data extraction.

  • What we claim about the agent is what was counted

    1,501 CIS rules, three operating systems, a 30-second check-in. Real-time process blocking is not in that count, and it will not become a headline before it is.

  • The platform is not live yet

    Infrastructure is being rebuilt. There is no signup, no trial and no billing, and you pay for nothing before it exists.

Next step

Tell us which operating systems and which cloud your clients run on.

If the answer is Google Cloud, we will say so in the conversation and not in week two.

Talk to the engineer