Cloud Posture
642 checks across three clouds, finished before your coffee
Agentless posture checks for AWS, Azure and GCP that run pre-deploy and post-deploy in the same pipeline, then correlate what they find with your app and API findings.
Read-only role. Full sweep in under ten minutes.
osprey / cloud posture
Workspace
Accounts
Checks
Drift
Policies
Evidence
Connect an account
View drift
last run 4m ago
642
Checks per sweep
3
Clouds connected
8m
Full sweep
Severity · Finding
Critical
S3 bucket is world-readable
High
IAM role is over-privileged
Medium
KMS key rotation disabled
Low
Flow logs off in eu-west-1
Low
Unused security group left open
A misconfiguration is only boring until it is reachable
Without Osprey
A posture tool that never talks to your app scanner
Drift discovered at the quarterly review
Alerts on every public bucket, reachable or not
Three consoles and three different severity scales
With Osprey
Cloud findings correlated with app and API findings
Checks that run before and after every deployment
Reachability decides severity, not the check name
One inventory and one scale across all three clouds
Read-only role in, full sweep out
01
Connect an account
One read-only role per cloud account. No agent, no daemon set, and nothing that can change your infrastructure.
02
Get a baseline
The first sweep finishes in under ten minutes and gives you a ranked list, not 4,000 undifferentiated alerts.
03
Watch for drift
Every deployment triggers a delta sweep, so a permissive role added on a Friday is on your board before Monday.
Posture that knows what the rest of your stack looks like
642 checks, three clouds
AWS, Azure and GCP under one inventory and one severity scale, so you stop translating between three consoles.
IAM drift detection
Catches the role that quietly gained a wildcard, the key that never rotated, and the bucket that lost its block-public setting.
Pre and post deploy
The same checks run against your plan before apply and against reality after, so drift shows up as a diff rather than a surprise.
Correlated findings
A public bucket is noise. A public bucket holding the backup your leaked API key points at is an attack path, and it gets ranked that way.
Evidence on demand
Exports mapped to SOC 2, ISO 27001, HIPAA and PCI DSS controls, with the raw check output attached to each one.
Sweeps that finish
A full three-cloud sweep completes in under ten minutes. Delta sweeps after a deploy finish in under sixty seconds.
Correlation is the whole point
Every posture tool can tell you a bucket is public. Very few can tell you that the key to it is sitting in a JavaScript bundle you shipped last Tuesday.
Cloud, app and API findings share one inventory
Attack paths assembled across all three surfaces
Reachability from the public internet is computed, not assumed
Severity reflects the whole path, not the single check
One ticket per path instead of three per symptom
Attack path OSP-P-311
Leaked key to public bucket to backup
Surfaces involved
App Scanner, API Surface and Cloud Posture
Ranked
Critical, reachable without authentication
Questions infrastructure teams ask first
What permissions do you need?
A read-only role per cloud account. Osprey never holds write access, never provisions anything, and cannot change your infrastructure even by mistake.
Is there an agent to install?
No. Everything runs against the cloud provider APIs with the read-only role you grant, so there is nothing to deploy and nothing to keep patched.
How long does a sweep take?
A full sweep of three connected clouds completes in under ten minutes. Delta sweeps, triggered after each deployment, finish in under sixty seconds.
Can it run in our pipeline?
Yes. The same checks run against a Terraform plan before apply and against live state after, so you see drift as a diff instead of a quarterly surprise.
Do you support multiple accounts?
Yes. Connect as many accounts, subscriptions and projects as you run. They share one inventory and one severity scale, which is usually the reason teams switch.
What if we only use one cloud?
That is fine and most teams start there. The correlation with App Scanner and API Surface is where the value shows up, not in the number of clouds connected.