Cloud Posture

642 checks across three clouds, finished before your coffee

Agentless posture checks for AWS, Azure and GCP that run pre-deploy and post-deploy in the same pipeline, then correlate what they find with your app and API findings.

Read-only role. Full sweep in under ten minutes.

osprey / cloud posture

Workspace

Accounts

Checks

Drift

Policies

Evidence

Connect an account

View drift

last run 4m ago

642

Checks per sweep

3

Clouds connected

8m

Full sweep

Severity · Finding

Critical

S3 bucket is world-readable

High

IAM role is over-privileged

Medium

KMS key rotation disabled

Low

Flow logs off in eu-west-1

Low

Unused security group left open

A misconfiguration is only boring until it is reachable

Without Osprey

A posture tool that never talks to your app scanner

Drift discovered at the quarterly review

Alerts on every public bucket, reachable or not

Three consoles and three different severity scales

With Osprey

Cloud findings correlated with app and API findings

Checks that run before and after every deployment

Reachability decides severity, not the check name

One inventory and one scale across all three clouds

Read-only role in, full sweep out

01

Connect an account

One read-only role per cloud account. No agent, no daemon set, and nothing that can change your infrastructure.

02

Get a baseline

The first sweep finishes in under ten minutes and gives you a ranked list, not 4,000 undifferentiated alerts.

03

Watch for drift

Every deployment triggers a delta sweep, so a permissive role added on a Friday is on your board before Monday.

Posture that knows what the rest of your stack looks like

642 checks, three clouds

AWS, Azure and GCP under one inventory and one severity scale, so you stop translating between three consoles.

IAM drift detection

Catches the role that quietly gained a wildcard, the key that never rotated, and the bucket that lost its block-public setting.

Pre and post deploy

The same checks run against your plan before apply and against reality after, so drift shows up as a diff rather than a surprise.

Correlated findings

A public bucket is noise. A public bucket holding the backup your leaked API key points at is an attack path, and it gets ranked that way.

Evidence on demand

Exports mapped to SOC 2, ISO 27001, HIPAA and PCI DSS controls, with the raw check output attached to each one.

Sweeps that finish

A full three-cloud sweep completes in under ten minutes. Delta sweeps after a deploy finish in under sixty seconds.

Correlation is the whole point

Every posture tool can tell you a bucket is public. Very few can tell you that the key to it is sitting in a JavaScript bundle you shipped last Tuesday.

Cloud, app and API findings share one inventory

Attack paths assembled across all three surfaces

Reachability from the public internet is computed, not assumed

Severity reflects the whole path, not the single check

One ticket per path instead of three per symptom

Attack path OSP-P-311

Leaked key to public bucket to backup

Surfaces involved

App Scanner, API Surface and Cloud Posture

Ranked

Critical, reachable without authentication

Questions infrastructure teams ask first

What permissions do you need?

A read-only role per cloud account. Osprey never holds write access, never provisions anything, and cannot change your infrastructure even by mistake.

Is there an agent to install?

No. Everything runs against the cloud provider APIs with the read-only role you grant, so there is nothing to deploy and nothing to keep patched.

How long does a sweep take?

A full sweep of three connected clouds completes in under ten minutes. Delta sweeps, triggered after each deployment, finish in under sixty seconds.

Can it run in our pipeline?

Yes. The same checks run against a Terraform plan before apply and against live state after, so you see drift as a diff instead of a quarterly surprise.

Do you support multiple accounts?

Yes. Connect as many accounts, subscriptions and projects as you run. They share one inventory and one severity scale, which is usually the reason teams switch.

What if we only use one cloud?

That is fine and most teams start there. The correlation with App Scanner and API Surface is where the value shows up, not in the number of clouds connected.

Find the path, not just the misconfiguration

Connect one read-only role and see your first correlated attack path in ten minutes.

Find the path, not just the misconfiguration

Connect one read-only role and see your first correlated attack path in ten minutes.

Create a free website with Framer, the website builder loved by startups, designers and agencies.