Skip to content

Know Your Posture Across Every Cloud You Run.

SinonPosture is a self-hosted CSPM/SSPM platform that connects to 30 kinds of target (cloud, SaaS, identity, network appliances, virtualisation and databases), evaluates 1,121 built-in checks, and maps every finding to 20 compliance frameworks. Your configuration and findings never leave your infrastructure.

Self-host or SinonTech-hosted. Attack-path graph. Air-gap capable.

Request Access See the Coverage

Platform at a Glance

30

Provider Integrations

Cloud, SaaS, identity, network appliances, virtualisation, and databases: each with a real collector, not a roadmap entry.

1121

Built-In Checks

YAML-defined security checks in a hot-reloadable registry, plus tenant-authored custom checks with a draft-to-published lifecycle.

20

Compliance Frameworks

SOC 2, PCI DSS 4.0, HIPAA, GDPR, ISO 27001, NIST 800-53, CMMC, FedRAMP, MITRE ATT&CK, and CIS benchmarks.

28

API Modules

REST API across orgs, tenants, providers, checks, findings, frameworks, scans, evidence and remediation.

6

Deployment Modes

Bare metal, Docker, Kubernetes, cloud VMs, virtual environments, and fully air-gapped.

One Platform, Not One Cloud

Most posture tools cover the big three clouds and stop. SinonPosture treats your whole estate as one surface: the SaaS you depend on, the identity providers that gate it, the firewalls at the edge, the hypervisors underneath, and the databases holding the data.

Cloud & Kubernetes

AWS, Azure, GCP, Oracle Cloud, Alibaba Cloud, DigitalOcean and Kubernetes. AWS alone ships 26 service collectors.

🔐

SaaS & Identity

Microsoft 365, Google Workspace, GitHub, Okta and Active Directory — the accounts and tenants attackers actually target.

🖥

Virtualisation

VMware vSphere, Proxmox, Nutanix and OpenStack, so the layer beneath your workloads is in scope too.

🛡

Network Appliances

Palo Alto PAN-OS, FortiGate, Cisco ASA, pfSense, OPNsense, and Cisco/Aruba switches, posture for the edge, not just the cloud.

🗄

Databases

PostgreSQL, MySQL, MSSQL, Oracle, MongoDB, Redis and Elasticsearch, checked for the misconfigurations that leak data.

💻

Host Agent

A host agent extends posture to individual machines: 200 host-level checks for the boxes that never make it into a cloud console.

From Finding to Fixed

A list of misconfigurations is where most tools stop. SinonPosture connects them into attack paths, tracks how they change, and helps close them.

🕸

Attack-Path Graph

Findings are joined across providers into a graph that shows how a low-severity misconfiguration in one system chains into a real path to your data — not just a flat severity list.

📈

Drift Detection

Every scan is compared to the last, so a config that was compliant yesterday and isn't today surfaces as a drift event rather than getting lost in the noise.

🔧

Guided Remediation

Remediation logic for AWS, Azure, GCP, GitHub and Kubernetes issues real provider API calls to fix findings. An optional AI assistant (bring your own Anthropic key) drafts summaries and remediation steps.

Evidence You Can Hand an Auditor

A hash-chained, HMAC-signed audit log and exportable evidence bundles turn "we think we're compliant" into a record you can prove and a chain that detects tampering.

📝

Custom Checks

Write your own checks in YAML with a draft → review → published lifecycle, so your organisation's policy is enforced alongside the 1,121 built in.

📤

Dispatch Anywhere

Route findings to SinonAlert, your SIEM, Slack, Jira, email or a webhook, so posture results land where your team already works.

Technical Specifications

Providers30 integrations: AWS, Azure, GCP, OCI, Alibaba, DigitalOcean, Kubernetes, M365, Google Workspace, GitHub, Okta, Active Directory, vSphere, Proxmox, Nutanix, OpenStack, PAN-OS, FortiGate, Cisco ASA, pfSense, OPNsense, Cisco/Aruba switches, 7 databases, and a host agent
Checks1,121 built-in YAML checks in a hot-reloadable registry, plus custom checks
Frameworks20: SOC 2, PCI DSS 4.0, HIPAA, GDPR, ISO 27001:2022, NIST 800-53 r5, NIST CSF 2.0, CMMC L2, FedRAMP High/Moderate, MITRE ATT&CK, and CIS benchmarks (AWS, Azure, GCP, OCI, Alibaba, Kubernetes, Linux, Windows, Windows Server)
AnalysisCross-provider attack-path graph, drift detection between scans, security posture scoring
RemediationReal provider-API remediation for AWS, Azure, GCP, GitHub and Kubernetes; optional AI assistance (bring-your-own Anthropic key)
Audit & evidenceHash-chained, HMAC-signed audit log; exportable evidence bundles; encrypted credential storage at rest
IntegrationsDispatch to SinonAlert, SIEM, Slack, Jira, email and webhooks
DatabasesPostgreSQL 16, Redis 7
API28 route modules, 129 endpoints
Multi-tenancyOrganisation → tenant → sub-tenant with role-based access; application-enforced isolation
Backend stackPython 3.11+, FastAPI, SQLAlchemy 2 async, asyncpg, OpenTelemetry; workers for scheduling, scanning, graph and agents
Frontend stackReact 18 with TypeScript, Vite, Redux Toolkit, Tailwind CSS, Monaco editor
Operations17-probe preflight doctor, backup/restore, air-gap bundle packager
DeploymentBare metal (systemd), Docker Compose, Kubernetes (Helm), cloud VMs, virtual environments, air-gapped

Frequently Asked Questions

What is SinonPosture?

A self-hosted cloud and SaaS security posture management (CSPM/SSPM) platform. It connects to 30 kinds of target (cloud accounts, SaaS tenants, identity providers, network appliances, hypervisors and databases), runs 1,121 built-in checks against them, maps results to 20 compliance frameworks, and produces findings, attack-path graphs, drift events and evidence bundles. It runs on PostgreSQL and Redis on your own infrastructure.

How is this different from a cloud provider's own posture tool?

Native tools cover their own cloud. SinonPosture covers 30 kinds of target across every cloud plus the SaaS, identity, network, virtualisation and database layers around them, in one place, on your infrastructure, with findings that never leave it. The attack-path graph then joins findings across those providers, which a single-cloud tool structurally cannot do.

Where do our cloud credentials and findings live?

On your infrastructure. Provider credentials are stored encrypted at rest, and scan results and findings never leave the platform you host. There is no vendor cloud in the path — that is the point of self-hosting a posture tool rather than granting a SaaS vendor read access to your entire estate.

Can we write our own checks?

Yes. Checks are YAML with a query, severity, category and remediation, loaded from a hot-reloadable registry. You can author your own with a draft → review → published lifecycle, so your organisation's specific policy runs alongside the 1,121 built-in checks.

Does the AI remediation send our data to a third party?

Only if you enable it and supply your own Anthropic API key. It is optional and off unless configured. The core platform, all 1,121 checks, the attack-path graph, drift detection and evidence bundles work with no AI and no external calls, which is what makes air-gapped deployment possible. Provider-API remediation for AWS, Azure, GCP, GitHub and Kubernetes is independent of the AI assistant.

Can it run air-gapped?

Yes. There is an offline bundle packager and air-gap installer, and the platform scans targets reachable on your own network with no route to the internet. Scanning an internet-only SaaS provider naturally needs a route to that provider, but the platform itself has no cloud dependency.

What stage is SinonPosture at?

Closed beta. It is a substantial platform: 30 provider collectors, 1,121 checks, 20 frameworks, covered by 470 backend tests. Request access and we will walk you through coverage for your estate, the deployment options, and onboarding before you commit anything.

See Your Real Posture

SinonPosture is in closed beta. Request access for a coverage assessment against your estate, deployment documentation, and an architecture walkthrough.

Own Your Security Posture

Talk to an engineer about posture management on infrastructure you own — or let us host it for you and still own every byte.

0141 536 0433  ·  info@sinontech.co.uk

Contact Us