Cloud-native application protection

Secure every workload, from the pull request to the running container

Guardian Sentinel unifies posture management, entitlement analysis, workload runtime protection, Kubernetes security and infrastructure-as-code scanning into one CNAPP. The same finding is traceable from the Terraform line that created it to the process that exploited it — because both live in the same data layer.

4min From connecting an account to a complete agentless asset inventory
1,940 Managed cloud services with posture and configuration coverage
3.1s Median time to detect and kill a container escape at runtime
86% Of critical findings resolved before merge once IaC scanning is on
0 Snapshots copied out of your account during agentless scanning

CNAPP

One control plane across the whole application lifecycle

CSPM told you the bucket was public. CWPP told you a process was suspicious. CIEM told you the role was over-permissioned. None of them told you they were the same incident. Sentinel treats the lifecycle as one continuum with one risk model.

CODE BUILD DEPLOY RUNTIME Terraform, Helm, CDK images, packages, SBOM accounts, IAM, clusters VMs, pods, functions Infrastructure-as-code scanning Image, package, SBOM and secret scanning Posture management — CSPM and KSPM Entitlement analysis — CIEM Workload runtime — CWPP Unified detection, correlation and autonomous response blocks the merge blocks the promotion continuous drift detection effective, not declared, permissions kills the process one graph, one incident, one action Every band writes into the same fabric, so a runtime alert carries the commit, the image digest and the IAM role that allowed it.

Scroll horizontally to see the full chart on a small screen.

Multi-cloud coverage

Same depth on every provider you actually use

Coverage claims are easy; parity is not. This is what Sentinel does natively on each platform, including how workloads are inspected without you installing anything.

Coverage as of the 2026.7 release. Agentless scanning uses provider-native snapshot APIs and never copies volumes outside your account or region.
Provider Services with posture rules Agentless workload scan Runtime protection Entitlement analysis Managed Kubernetes
Amazon Web Services 812 EBS snapshot scanning, Lambda layers EC2, ECS, EKS, Fargate, Lambda IAM, SCP, permission boundaries, Identity Center EKS, EKS Anywhere
Microsoft Azure 604 Managed disk snapshots, Functions VMs, AKS, Container Apps, Functions Entra ID, RBAC, PIM, managed identities AKS, Azure Arc clusters
Google Cloud 418 Persistent disk snapshots, Cloud Run Compute Engine, GKE, Cloud Run IAM, org policy, service accounts, Workload Identity GKE, GKE on-prem
Oracle Cloud Infrastructure 76 Block volume snapshots Compute, OKE IAM policies and compartments OKE
Self-managed Kubernetes 30 CIS benchmarks Via node agent Any CNCF-conformant distribution RBAC, service accounts, admission policy OpenShift, Rancher, Talos, kubeadm
Private cloud & virtualisation 42 Via node agent VMware vSphere, Nutanix, Proxmox, KVM Not applicable Any conformant cluster

Scroll the table horizontally to see every column.

Onboard in four minutes

Connect an organisation, management group or folder with a read-only role and Sentinel enumerates every account beneath it, including the ones nobody told the security team about.

Effective permissions, not declared ones

CIEM resolves the full chain — role, policy, boundary, SCP, group, trust relationship — to answer the only question that matters: what can this principal actually do today?

Agentless first, agent where it pays

Snapshot scanning gives vulnerability and secret coverage on day one with nothing installed. Add the runtime sensor only where you need behavioural detection and blocking.

Containers & Kubernetes

Admission control at the gate, eBPF detection on every node

Kubernetes fails in two places: what you let in, and what happens after. Sentinel covers both with a validating admission webhook that can block a deployment, and a node-level eBPF sensor that watches every syscall a container makes.

KUBERNETES CLUSTER Registry & CI signed images SBOM attached Guardian admission webhook image provenance · privilege · policy ADMIT DENY 1,204 admitted today 38 denied — privileged or unsigned node-01 node-02 node-03 podpodpod podpodpod podpodpod eBPF sensor (DaemonSet) eBPF sensor (DaemonSet) eBPF sensor (DaemonSet) Normalised events → Sentinel Data Fabric — joined with endpoint, network and identity telemetry No sidecars. No privileged containers.

Scroll horizontally to see the full diagram on a small screen.

Container escape detection

Namespace and cgroup manipulation, /proc abuse, kernel module loading and privileged socket creation, caught at the syscall boundary in a median of 3.1 seconds.

Drift detection

Containers should be immutable. Any binary that appears in a running container but not in its image is flagged within five seconds and optionally killed on sight.

Supply-chain provenance

Admission verifies image signatures, SLSA provenance and SBOM presence, and refuses anything built outside your approved pipelines.

Service-to-service map

Observed pod-to-pod communication becomes a proposed network policy you can simulate against real traffic before enforcing.

Shift left

Fix it in the pull request, not in the postmortem

Sentinel scans Terraform, OpenTofu, CloudFormation, Bicep, Pulumi, Helm charts and raw Kubernetes manifests in the pipeline, and comments on the exact line that will create the exposure. Once teams see the finding at review time, 86% of criticals never reach an account.

  • Native checks in GitHub, GitLab, Bitbucket, Azure DevOps and Jenkins
  • Secret detection across 340 credential formats, with automatic revocation hooks
  • Suggested fixes proposed as a commit the developer can accept in one click
  • Runtime findings trace back to the commit, author and module that introduced them
  • Policy-as-code exceptions with expiry dates, so temporary never means permanent
See pipeline integrations
Critical GDN-AWS-S3-004

Public access block disabled on a bucket receiving billing exports

resource "aws_s3_bucket" "billing_exports" {
  bucket = "acme-billing-exports"
}

resource "aws_s3_bucket_public_access_block" "exports" {
  bucket                  = aws_s3_bucket.billing_exports.id
  block_public_acls       = false   # ← finding
  ignore_public_acls      = false   # ← finding
  restrict_public_buckets = false   # ← finding
}

Why this matters here: Sentinel resolved the downstream data classification for this bucket from the fabric — it receives cost and usage reports containing account identifiers, so the finding is rated critical rather than the default high.

infra/billing/main.tf, lines 14–16 Data classification

Shift left is not a substitute for runtime. Roughly 40% of real cloud incidents involve resources that were compliant at deploy time and drifted afterwards, or credentials that were valid and then stolen. Both halves are necessary.

Posture in the console

Risk expressed in a way an executive and an engineer both accept

Findings are ranked by exploitability on the actual asset — its exposure, its identity reach, its data classification and whether anything is currently attacking it — not by a severity label copied from a CVE feed.

Cloud posture — all connected accounts last full scan 4 minutes ago 214 148,207 37 82 connected accounts discovered assets critical findings posture score / 100 Open findings by severity 1,781 open Critical 37 High 128 Medium 402 Low 1,214 Critical findings by provider AWS Azure Google Cloud Oracle Cloud 19 11 5 2 Highest-exploitability findings Public bucket holding classified exports Role with org-wide administrative reach Unencrypted managed database, internet-facing Privileged container admitted pre-policy s3://acme-billing-exports · 2 accounts arn:aws:iam::…:role/ci-deploy-prod rds/orders-eu-west · 1 account ns/payments · 3 clusters CRITICAL CRITICAL HIGH HIGH Posture score, last 12 weeks +21 points wk 1 wk 6 wk 12

Scroll horizontally to see the full dashboard on a small screen.

Representative console view. Figures are illustrative of a 214-account estate after twelve weeks of remediation.

Compliance

Evidence generated continuously, not assembled the week before the audit

Every posture check maps to the control it satisfies across 32 frameworks. Auditors get a live, timestamped evidence trail; engineers get one backlog instead of one per framework.

CIS Benchmarks PCI DSS 4.0 HIPAA SOC 2 ISO 27001 NIST 800-53 NIST CSF 2.0 FedRAMP DORA NIS2 GDPR APRA CPS 234

Continuous control monitoring

Each control shows current pass rate, the assets failing it and the exact remediation, refreshed on every scan rather than at quarter end.

PCI DSS 4.094%
CIS AWS Foundations91%
ISO 27001 Annex A88%
NIST 800-53 moderate96%

Exceptions with an expiry date

Every accepted risk carries an owner, a justification, a compensating control and a date. Sentinel reopens the finding automatically when the date passes, and reports on exception debt by team.


Open exceptions

41Active
6Expiring in 30 days
0Expired and unreviewed

Audit-ready export

Produce a signed evidence pack per framework, per scope and per date range, including the raw check results and the change history for every asset in scope.

  • Immutable, timestamped and hash-chained
  • Scoped to a business unit or account group
  • Delivered to your GRC platform through the API
Compliance advisory services
We had a CSPM tool, a container security tool and an EDR that all disagreed about which workloads existed. Sentinel gave us one asset inventory that engineering actually trusts, and that trust is what finally moved our remediation numbers.
Amara Nwosu Head of Cloud Platform Security, Lumen Retail Group
73% Fewer open critical findings after two quarters
3 Cloud security products retired

Questions cloud teams ask

Does agentless scanning copy our data anywhere?

No. Sentinel creates a snapshot using the provider's own API, mounts and analyses it inside your account and region, then deletes it. Only findings and metadata leave — never volume contents, never a copy of a disk, never cross-region.

What permissions does the connector need?

Read-only by default: the provider's security-audit role plus snapshot creation for agentless scanning. Write permissions are optional and scoped per action — you choose whether Sentinel may quarantine an instance, revoke a key or update a security group, and each is separately grantable and separately audited.

How does this handle ephemeral workloads?

Assets are identified by workload identity rather than by instance ID, so a pod that lives for 40 seconds still produces a complete, attributable record. Findings persist against the deployment, image and owning team even after the individual instance is gone.

Will the runtime sensor slow our nodes down?

The eBPF sensor is measured at under 1% of node CPU and roughly 110 MB of memory per node under production load. It runs unprivileged with a scoped capability set, never as a privileged container, and it fails open — a sensor fault degrades to logging, never to a blocked workload.

Can we use this without adopting the rest of the platform?

Yes — cloud security is licensable on its own and integrates with an existing SIEM or ticketing workflow. It gets substantially better alongside identity protection and endpoint security, because that is what turns a posture finding into a confirmed attack path.

What about serverless and platform-as-a-service?

Lambda, Azure Functions and Cloud Run are covered for posture, package vulnerabilities, secret exposure and invocation-level anomaly detection. Managed platform services such as RDS, Cosmos DB and BigQuery are covered by posture, entitlement and data-plane access analysis rather than runtime instrumentation.

Connect one account and see what is really there

A read-only connector produces a full inventory, posture score and prioritised finding list in under an hour. Keep the report whether or not you go further.