| Providers | 30 integrations: AWS, Azure, GCP, OCI, Alibaba, DigitalOcean, Kubernetes, M365, Google Workspace, GitHub, Okta, Active Directory, vSphere, Proxmox, Nutanix, OpenStack, PAN-OS, FortiGate, Cisco ASA, pfSense, OPNsense, Cisco/Aruba switches, 7 databases, and a host agent |
| Checks | 1,121 built-in YAML checks in a hot-reloadable registry, plus custom checks |
| Frameworks | 20: SOC 2, PCI DSS 4.0, HIPAA, GDPR, ISO 27001:2022, NIST 800-53 r5, NIST CSF 2.0, CMMC L2, FedRAMP High/Moderate, MITRE ATT&CK, and CIS benchmarks (AWS, Azure, GCP, OCI, Alibaba, Kubernetes, Linux, Windows, Windows Server) |
| Analysis | Cross-provider attack-path graph, drift detection between scans, security posture scoring |
| Remediation | Real provider-API remediation for AWS, Azure, GCP, GitHub and Kubernetes; optional AI assistance (bring-your-own Anthropic key) |
| Audit & evidence | Hash-chained, HMAC-signed audit log; exportable evidence bundles; encrypted credential storage at rest |
| Integrations | Dispatch to SinonAlert, SIEM, Slack, Jira, email and webhooks |
| Databases | PostgreSQL 16, Redis 7 |
| API | 28 route modules, 129 endpoints |
| Multi-tenancy | Organisation → tenant → sub-tenant with role-based access; application-enforced isolation |
| Backend stack | Python 3.11+, FastAPI, SQLAlchemy 2 async, asyncpg, OpenTelemetry; workers for scheduling, scanning, graph and agents |
| Frontend stack | React 18 with TypeScript, Vite, Redux Toolkit, Tailwind CSS, Monaco editor |
| Operations | 17-probe preflight doctor, backup/restore, air-gap bundle packager |
| Deployment | Bare metal (systemd), Docker Compose, Kubernetes (Helm), cloud VMs, virtual environments, air-gapped |