CNAPP · code → cloud → runtime

Secure everything —
code, cloud and runtime.

As AI agents take on more autonomy across your cloud estate, fragmented posture, workload and identity tools can't keep pace. OnDuty unifies CSPM, CWPP, CIEM and runtime defense into a single live graph — surfacing only the toxic combinations that lead to a real breach.

Agentless onboarding · multi-cloud in <15 min

Why point tools miss it

An attacker doesn't stay
in one tool's lane.

A real breach chains a misconfiguration, an over-permissioned identity, a vulnerable workload and an exposed data store. Each point tool sees exactly one link — and none of them see the path. A CNAPP puts every layer on one graph, so a chain that four scanners report as four unrelated alerts becomes a single, rankable attack path.

Public storage bucket

CSPM sees a misconfig

Over-privileged role

CIEM sees excess access

Vulnerable workload

CWPP sees a CVE

Customer-data store

DSPM sees sensitive data

OnDuty connects all four into one attack path to your customer data.

Ranked #1 of 41,204 findings

How a CNAPP actually works

Four things point
tools can't do.

One data model

Every layer on one graph — not four consoles.

A CNAPP is only as good as what it can connect. OnDuty ingests posture, workloads, identities, data and code into a single graph, so a policy written once applies everywhere and a risk in one layer is understood in the context of every other — no exporting from four tools to reconstruct what an attacker sees in a single move.

One policy, every cloudCross-layer contextLive workload sensor
CSPM
CWPP
CIEM
Code

Unified data model

One live graph

Attack-path analysis

Rank by the path to a crown jewel, not by CVSS.

Severity alone buries the findings that matter. Because every finding sits on the graph, OnDuty scores it by the attack paths it opens, its proximity to sensitive data and its real blast radius — surfacing the handful of toxic combinations that actually reach a crown-jewel asset, and muting the thousands that lead nowhere.

Toxic-combination detectionCrown-jewel proximityBlast-radius ranking

Ranked by dynamic risk score

crown jewel at risk
Crown-jewel proximity92
Attack path severity81
Assets affected64
Exposure surface47

3 hops from internet to customer-data DB

Top of 1,842 open findings

Root-cause remediation

One root cause, not a thousand tickets.

The graph knows which findings share a cause. OnDuty clusters them into a single remediation Mission with an owner and a deadline — so fixing one Terraform module can close hundreds of findings at once, and teams spend their time on the changes with the highest return instead of triaging alert queues.

Auto-grouped by root causeOwner & deadline built inHighest-ROI fixes first
Mission · Public S3 exposure247 findings

Root cause: one Terraform module (modules/storage/main.tf) sets public-read on every bucket it provisions.

94 of 247 resolvedowner: platform-eng · due in 5 days

1 PR

Fix once

247 alerts

Resolves

+6 pts

Compliance lift

Code to cloud to runtime

Trace every runtime risk back to a line of code.

OnDuty links running workloads to the infrastructure and the repo that produced them. Policies are enforced in the pull request, and every production finding traces straight back to the commit that introduced it — so security and engineering finally work from one picture instead of arguing across two.

Policy gates in CI/CDIaC & image scanningRuntime findings traced to source

main.tf

PR #482 · public-read: true

IaC scan

Blocked in CI · policy violation

prod-storage

Deployed resource

Runtime finding

Publicly exposed bucket

Consolidate the stack

Retire the point tools.
Keep the coverage.

Every scanner you add is another console, another alert queue and another seam an attacker can hide in. OnDuty folds the whole cloud-security stack into one platform — the same coverage, on one graph, in one queue.

Before · tool sprawl

CSPMCWPPCIEMKSPMDSPMIaC scannerRuntime EDR

7 consoles · 7 alert queues · findings that never meet

After · one platform

OnDuty CNAPP

one graph · one risk queue

  • Every layer correlated, not stitched
  • One policy engine across all clouds
  • A single, ranked list of what to fix

7 → 1

Consoles to manage

One platform, one login

~90%

Fewer alerts to triage

Correlated, not duplicated

1

Policy engine

Written once, enforced everywhere

The CNAPP lifecycle

From onboarding
to ownership.

Phase / 01

Connect

Agentless onboarding to every cloud, cluster and code repo in minutes — no sensors to roll out.

Phase / 02

Correlate

Fuse posture, workloads, identities, data and code into one live graph of how everything connects.

Phase / 03

Prioritize

Rank every risk by the attack paths it opens and the blast radius it carries — not by raw severity.

Phase / 04

Remediate

Group findings by root cause into owner-aware Missions with one-click fixes from code to runtime.

Replace the stack with one graph

See the 12 paths,
not the 40,000 alerts.

See your real attack paths, prioritized cloud risks and identity blast radius in a 30-min guided demo with our team.

  • One graph of workloads, identities, data, secrets and paths
  • Attack-path analysis that ranks the 12 risks that matter
  • Root-cause Missions — fix once, resolve hundreds
  • Code-to-cloud tracing from pull request to runtime and back
  • One platform replacing CSPM, CWPP, CIEM, KSPM & more