Skip to content
Beta NimbusGuard is currently in testing. Want to be part of it? Email us at info@nimbusguard.io
NimbusGuard

The product

One platform for cloud security

Posture, workloads, exposure, threats and infrastructure-as-code — built to work together, correlated instead of siloed. Here's how each piece fits.

Cloud Security Posture

The CSPM core

Continuous inventory, evaluation, findings and custom controls — the foundation every other module builds on.

Discovery & inventory

NimbusGuard connects to your AWS and Azure accounts and normalizes every resource into a consistent shape. Collectors span roughly 85 resource types — EC2, security groups, S3, IAM, RDS, KMS, CloudTrail on AWS; Storage, AKS, Key Vault, App Service, SQL and more on Azure — agentless, with no keys stored.

  • AWS: AssumeRole + external ID (no keys stored)
  • Azure: app registration, secret encrypted at rest
  • ~85 normalized, queryable resource types

Independent evaluation engine

A stateless, isolated evaluation service compares each resource against your controls and returns a structured result. It's kept separate from the rest of the platform so that updating a control never means touching your data or your account.

  • Stateless by design
  • Results with evidence
  • PASS · FAIL · NOT_APPLICABLE · NOT_EVALUATED · ERROR

Built-in controls

A curated catalog of 270+ high-value controls, each with severity, category, remediation and a mapping to compliance frameworks. Informed by industry best practices — not a generic checklist.

  • 177 AWS controls across 44 services
  • 97 Azure controls across 23 services
  • CIS · NIST 800-53 · PCI DSS mapping

Custom controls in Rego

Write your own policies in Rego and run them through Open Policy Agent, safely sandboxed. Arbitrary code never runs — only declarative policies in an isolated environment. Version, test and publish your controls straight from the UI, or draft them with AI.

  • Open Policy Agent (OPA)
  • Draft → validated → active
  • AI-assisted authoring

Findings & lifecycle

Every FAIL becomes a finding with severity, evidence and remediation, with a clear open-to-resolved lifecycle and structural deduplication — one finding per resource and control, no duplicates. Tame noise with an exceptions system (false positive, risk accepted, compensating control) that requires an owner, a note and an expiry.

  • Open → resolved, deduplicated
  • Exceptions with mandatory expiry
  • Per-organization severity overrides

Dashboards, reporting & prioritization

Dashboards that summarize your posture: connected accounts, resources by type, open findings by severity, and your posture score. Filter, sort and group any view, then export it as evidence in one click.

  • Posture summary & posture score
  • Filter, sort and group by
  • Export to CSV / JSON / XLSX / HTML

Beyond posture

The rest of the platform

Workloads, external exposure, attack paths and shift-left — all sharing the same inventory, findings and control catalog.

Workload Protection (CWPP)

Go past configuration into the workloads themselves. Scan container images for CVEs, generate an SBOM, and flag end-of-life packages; inventory protected workloads across ECS, EKS, AKS and Docker hosts; browse packages org-wide and scan disk artifacts.

  • Image scanning: CVEs, SBOM, EOL detection
  • Workload inventory across ECS/EKS/AKS/Docker
  • Agentless by default · optional sensors for depth

Exposure Validation (EASM)

See yourself the way an attacker does. Discover your external attack surface, diff it against your inventory to catch shadow IT, and run real vulnerability scanning. Controlled exploitation happens only after a signed engagement and an explicit human sign-off — the human brake other tools skip.

  • External attack surface + shadow-IT diff
  • Real vulnerability scanning (Nuclei)
  • Signed engagement → human approval → controlled exploit
  • Generated pentest reports

Threat Modeling

Turn a pile of findings into a story. Visualize attack paths and the single “cut point” — the one change that breaks a compromise chain — and declare your crown-jewel assets and business context so priority reflects real impact.

  • Attack-path visualization with a named cut point
  • Assignable Threat Scenarios lifecycle
  • Crown-jewel & business-context tagging

IaC Scanning

Shift left and catch misconfigurations before they ship. Gate Terraform, CloudFormation and Bicep in your CI pipeline against the same 270+ control catalog you use in runtime — with tracked findings, auto-resolve and org-level suppression governance.

  • CI gate-check: Terraform / CloudFormation / Bicep
  • Same 270+ controls, pre-deploy
  • Tracked findings + suppression governance

Exposure Validation and advanced Threat Modeling are available on request — contact us for access and pricing.

AI-native

AI woven through, not bolted on

Every AI feature reads your real data, cites its sources, and — where it suggests a fix — validates it against the evaluation engine before you see it.

Copilot

A chat assistant that answers with cited tool calls against your real posture.

Correlate

Cross-resource investigation that hypothesizes and traces an attack path.

Executive Summary

Board-language posture reports generated from your findings.

Explained findings

Every finding explained in plain language, with the reasoning behind it.

Remediation drafts

Fix snippets dry-run validated against the real evaluation engine.

AI-authored controls

Draft a custom control with AI, then test and publish it.

Metered by credits with a cost ceiling — degraded answers are labeled, and nothing runs a runaway bill.

Built for security teams

Multi-tenant, with granular access control and the enterprise controls your organization needs — on every plan.

Multi-tenancy
Fully isolated organizations, end to end
Access control
RBAC with built-in and custom roles per organization
Authentication
TOTP MFA + SAML SSO + SCIM on every plan + service accounts with API keys
Audit & compliance
Login audit log + posture score by framework (CIS, NIST 800-53, PCI DSS)
Scan cadence
Manual, daily or weekly, per cloud account
Cloud support
AWS and Azure supported · GCP on the roadmap

Why NimbusGuard

Coverage you can trust

Most tools show a high score over a catalog that may have failed silently. NimbusGuard doesn't. When a control can't be evaluated — a missing field, a permission gap, a resource type we didn't reach — we say so explicitly, with the reason. A NOT_EVALUATED or ERROR result never counts as a pass. You always know what was checked, what wasn't, and why.

A separated, secure design

Evaluation runs in a service that's independent from the rest of the platform. That service has no access to your database, never calls any cloud, and knows nothing about your users: it only receives an already-normalized configuration and returns a result. It's a deliberate security boundary — and the reason your custom Rego controls always run fully isolated.

AWS / Azure → Inventory → Evaluation engine → Finding → Dashboard

Ready to see it in action?