Skip to content
NimbusGuard

The product

One CSPM platform, end to end

NimbusGuard brings discovery, evaluation, findings and remediation into a single continuous flow. Here's how each piece fits together.

Discovery & inventory

NimbusGuard connects to your AWS account with a read-only role and normalizes every resource into a consistent shape. Collectors cover EC2, security groups, S3, IAM, RDS, KMS, CloudTrail, ELB, ECS/EKS and more — no agents to install and no credentials to store.

  • AssumeRole + external ID
  • No access keys stored
  • Normalized, queryable resources

Independent evaluation engine

A stateless, isolated evaluation service compares each resource against your controls and returns a structured result. It's kept separate from the rest of the platform so that updating a control never means touching your data or your account.

  • Stateless by design
  • Results with evidence
  • PASS · FAIL · NOT_APPLICABLE · NOT_EVALUATED · ERROR

Built-in controls

A curated catalog of 70+ high-value controls for AWS and Azure, each with severity, category, remediation and a mapping to compliance frameworks. Informed by industry best practices — not a generic checklist.

  • 52 AWS + 18 Azure controls
  • Severity & remediation per control
  • CIS · NIST 800-53 · PCI DSS mapping

Custom controls in Rego

Write your own policies in Rego and run them through Open Policy Agent, safely sandboxed. Arbitrary code never runs — only declarative policies in an isolated environment. Version, test and publish your controls straight from the UI.

  • Open Policy Agent (OPA)
  • Draft → validated → active
  • Test against sample data before publishing

Findings & lifecycle

Every FAIL becomes a finding with severity, evidence and remediation, with a clear open-to-resolved lifecycle. One finding per resource and control — no duplicates and none of the noise typical of other tools.

  • Open → resolved lifecycle
  • One finding per resource × control
  • Per-organization severity overrides

Dashboards & prioritization

Dashboards that summarize your posture: connected accounts, resources by type, open findings by severity, and your posture score. Filter inventory and findings, sort by what matters, and act.

  • Posture summary
  • Filterable inventory
  • Per-control posture score

Built for security teams

Multi-tenant, with granular access control and the integrations your organization needs.

Multi-tenancy
Fully isolated organizations, end to end
Access control
RBAC with roles: Admin, Security Engineer, DevOps, Auditor and more
Authentication
SAML 2.0 SSO per organization + service accounts with API keys
Scan cadence
Manual, daily or weekly, per cloud account
Cloud support
AWS in production · Azure in the catalog · more to come

A separated, secure design

Evaluation runs in a service that's independent from the rest of the platform. That service has no access to your database, never calls AWS, and knows nothing about your users: it only receives an already-normalized configuration and returns a result. It's a deliberate security boundary — and the reason your custom Rego controls always run fully isolated.

AWS Inventory Evaluation engine Finding Dashboard

Ready to see it in action?