Platform · features

One platform to find, rank & fix risk

CSPM.io discovers every resource you run, validates it against 578+ security checks, and uses AI to turn thousands of findings into the handful that matter — with remediation code ready to apply.

Read-only access No agents First scan in <10 min
Discovery

Continuous discovery & inventory

You can't secure what you can't see. CSPM.io keeps a live map of your cloud — every region, every account, every relationship.

  • Live multi-region, multi-account inventory. Every resource is discovered and refreshed continuously across all your regions and linked accounts.
  • Dependency & relationship mapping. Understand how resources connect — networks, roles, data stores — so context travels with every finding.
  • Drift detection. Spot configuration changes the moment they happen and trace what moved away from a known-good state.
  • Normalized model. AWS, GCP and Azure resources share one schema, so a single query works across every cloud you run.

Always current

Inventory updates continuously — no stale snapshots, no nightly batch gaps.

Connected graph

Relationships are first-class, powering blast-radius and attack-path analysis.

Every region

Parallel scanning across all enabled regions in a single run.

Drift alerts

Know the instant a resource diverges from its expected configuration.

Security graph & inventory

See your entire cloud as a living graph

Every resource, every relationship, every exposure path — mapped. Click a node to trace how an attacker could reach your crown jewels, and what the blast radius would be.

Security Graph

Resource relationships, exposure & risk across your cloud estate

Critical High Medium Low Attack path

Visual inventory

A complete, always-current map of every asset across accounts, regions and clouds — no spreadsheets, no blind spots.

Resource relationships

Follow the edges between IAM roles, networks, compute and data to understand how everything actually connects.

Internet exposure

Instantly spot which assets are publicly reachable and trace the exact path traffic takes to get there.

Attack paths & blast radius

See multi-step chains from the internet to your crown jewels, and the full blast radius if one node is compromised.

Checks

578+ security checks, mapped to the frameworks you report on

Deep coverage across 82 AWS services, each check mapped to CIS Benchmarks, PCI DSS and AWS Well-Architected — and continuously validated.

43 checks

IAM & identity

Root usage, MFA, over-privileged roles, stale keys, and risky trust policies.

24 checks

S3 & storage

Public buckets, encryption, access logging, versioning, and lifecycle policy gaps.

70 checks

EC2 & compute

Open security groups, IMDSv2, public IPs, unpatched AMIs, and EBS encryption.

34 checks

RDS & databases

Encryption at rest, public accessibility, backups, deletion protection, and TLS.

KMS & secrets

Encryption & KMS

Key rotation, policy scope, unused keys, and secrets exposed in configuration.

Networking

VPC & networking

Flow logs, default VPCs, exposed ingress, NACL gaps, and peering exposure.

AI prioritization

From 1,000s of findings to a handful that matter

Severity labels treat every issue the same. CSPM.io scores risk in the context of your environment — so your team works the threats that are actually exploitable.

Live

Exposure-aware

Public IPs, internet-facing security groups, and open paths push real risk to the top — internal-only issues drop down.

Live

Data sensitivity

Findings on resources holding sensitive or regulated data are weighed higher, reflecting true business impact.

Beta

Attack-path potential

Weaknesses that chain into a real, multi-step path are surfaced first — fix what breaks the chain.

Live

0–100 risk score

One clear, explainable score per finding — see exactly why something ranked where it did.

Live

Ask in plain English

“Show internet-facing databases without encryption.” Skip the query language and just ask.

Live

80% less noise

Teams cut through alert fatigue and reach the critical findings far faster.

Remediation

Automated remediation — fix code you can review and apply

Don't just find the problem. CSPM.io generates the fix in the format your team already uses, with safety built in.

  • Multi-format output. Generate Terraform, CloudFormation or AWS CLI fixes — matched to how you ship infrastructure.
  • Impact preview. See exactly what a change touches before anything runs, with warnings for production-affecting edits.
  • Safe rollback. Every fix ships with rollback instructions so you can reverse cleanly if needed.
  • Full audit trail. Who generated what, when, and what changed — captured automatically for compliance.
remediation.tf — S3 public access
# Block all public access on prod-exports
resource "aws_s3_bucket_public_access_block" "fix" {
  bucket                  = aws_s3_bucket.prod_exports.id
  block_public_acls       = true
  block_public_policy     = true
  ignore_public_acls      = true
  restrict_public_buckets = true
}
# Rollback: terraform destroy -target=...public_access_block.fix
Compliance

Audit-ready compliance & reporting

Continuous monitoring against the frameworks that matter, with the evidence already collected when audit season arrives.

Continuous evidence

Control status is captured automatically over time — no scramble to assemble screenshots before an audit.

Gap analysis

See exactly which controls are failing, on which resources, mapped to CIS, PCI DSS and Well-Architected.

Audit-ready reports

Export framework-aligned reports your auditors and leadership can read at a glance.

Governance

Exceptions & governance, without the spreadsheet

Real environments have accepted risks. CSPM.io makes exceptions disciplined — time-limited, justified, and approval-gated.

Time-limited

Every exception carries an expiration, so accepted risk is revisited instead of forgotten.

Justified & documented

Capture the rationale and compensating controls, with AI-drafted justifications to speed it up.

Approval-gated

Exceptions route through approval and stay traceable — clear ownership, clean audit history.

At a glance

Platform capabilities

Everything in one place — built for modern cloud teams, not enterprise complexity.

Discovery & inventory Live, continuous, multi-region and multi-account All regions
Security checks Across 82 AWS services, mapped to CIS / PCI DSS / Well-Architected 578+ checks
AI risk prioritization Context-aware scoring across exposure, sensitivity and attack paths 80% less noise
Automated remediation Terraform, CloudFormation and AWS CLI with rollback & audit trail 3 formats
Compliance & reporting Continuous evidence, gap analysis and audit-ready exports Audit-ready
Onboarding Read-only cross-account role with a unique external ID — no agents <10 min

See the platform on your own cloud

Connect an account read-only and get your first prioritized findings in minutes.