The product
One CSPM platform, end to end
NimbusGuard brings discovery, evaluation, findings and remediation into a single continuous flow. Here's how each piece fits together.
Discovery & inventory
NimbusGuard connects to your AWS account with a read-only role and normalizes every resource into a consistent shape. Collectors cover EC2, security groups, S3, IAM, RDS, KMS, CloudTrail, ELB, ECS/EKS and more — no agents to install and no credentials to store.
- AssumeRole + external ID
- No access keys stored
- Normalized, queryable resources
Independent evaluation engine
A stateless, isolated evaluation service compares each resource against your controls and returns a structured result. It's kept separate from the rest of the platform so that updating a control never means touching your data or your account.
- Stateless by design
- Results with evidence
- PASS · FAIL · NOT_APPLICABLE · NOT_EVALUATED · ERROR
Built-in controls
A curated catalog of 70+ high-value controls for AWS and Azure, each with severity, category, remediation and a mapping to compliance frameworks. Informed by industry best practices — not a generic checklist.
- 52 AWS + 18 Azure controls
- Severity & remediation per control
- CIS · NIST 800-53 · PCI DSS mapping
Custom controls in Rego
Write your own policies in Rego and run them through Open Policy Agent, safely sandboxed. Arbitrary code never runs — only declarative policies in an isolated environment. Version, test and publish your controls straight from the UI.
- Open Policy Agent (OPA)
- Draft → validated → active
- Test against sample data before publishing
Findings & lifecycle
Every FAIL becomes a finding with severity, evidence and remediation, with a clear open-to-resolved lifecycle. One finding per resource and control — no duplicates and none of the noise typical of other tools.
- Open → resolved lifecycle
- One finding per resource × control
- Per-organization severity overrides
Dashboards & prioritization
Dashboards that summarize your posture: connected accounts, resources by type, open findings by severity, and your posture score. Filter inventory and findings, sort by what matters, and act.
- Posture summary
- Filterable inventory
- Per-control posture score
Built for security teams
Multi-tenant, with granular access control and the integrations your organization needs.
A separated, secure design
Evaluation runs in a service that's independent from the rest of the platform. That service has no access to your database, never calls AWS, and knows nothing about your users: it only receives an already-normalized configuration and returns a result. It's a deliberate security boundary — and the reason your custom Rego controls always run fully isolated.