CSPM · multi-cloud · continuous

Every breach
starts as a misconfig.

A single public bucket, an over-permissive security group, a forgotten admin role — that's how cloud breaches start. OnDuty CSPM continuously inspects every resource in every account, then ranks issues by real-world exposure, not generic severity.

Posture, by the numbers

Less noise.
More signal.

Traditional CSPMs flag every drift as urgent. OnDuty knows which misconfig is actually exposed, who owns it and what compliance control it breaks — so your team fixes the right thing first.

6

Major cloud providers covered

AWS · Azure · GCP · OCI, DigitalOcean, Supabase

1,500+

Built-in policies

CIS · PCI · SOC 2 · HIPAA · ISO

97%

Auto-suppressed noise

Risk-graph aware findings

12 min

Median onboarding

Agentless · read-only role

Six capabilities, one platform

CSPM, graded by
real exposure.

Capability / 01

Multi-cloud asset inventory

Agentless, read-only discovery of every account, region, resource and tag — across AWS, Azure, GCP and OCI — refreshed continuously.

  • Org-wide auto-onboarding
  • Tag & owner enrichment
  • Resource lineage
Capability / 02

Continuous misconfig detection

1,500+ built-in policies plus custom OPA / Rego rules — evaluated continuously against live cloud state, not nightly snapshots.

  • Drift detection
  • Custom Rego policies
  • Suppression workflow
Capability / 03

Compliance & frameworks

Map controls to CIS, PCI DSS, SOC 2, ISO 27001, HIPAA, NIST 800-53 and EU regulations — with audit-ready evidence on demand.

  • 20+ frameworks
  • Custom control packs
  • Continuous evidence
Capability / 04

Exposure-based prioritization

We grade every finding by reachability, blast radius and data sensitivity — not a static severity table — so noise disappears.

  • Reachability scoring
  • Data sensitivity tags
  • Toxic combinations
Capability / 05

Shift-left to IaC

Catch posture issues in Terraform, CloudFormation, Helm and Bicep before they hit production — directly in pull requests.

  • PR checks
  • IaC → cloud diffing
  • Policy as code
Capability / 06

Owner-aware remediation

Tickets route to the team that actually owns the resource, with code-level fixes for IaC and click-to-fix actions for runtime.

  • Jira & ServiceNow
  • Auto-routing by tag
  • One-click fixes

The Posture Graph

One score. Every framework.

Every misconfig is tied to the workloads, identities and data it affects — and the compliance controls it breaks. Posture stops being a quarterly audit and becomes a continuous signal.

Explore compliance
Posture graph · org-root · all clouds LIVE
Resource
Control
Framework
Exposure

S3 bucket public + sensitive data tag

s3://prod-exports · public read · contains PII (DSPM) · CIS 2.1.5

Security group 0.0.0.0/0 on port 22

sg-0c91 · attached to 4 prod EC2 · CIS 5.2

Encryption disabled on RDS instance

rds://prod-billing · AES-256 off · PCI DSS 3.4

Resource missing owner tag

lambda://invoice-renderer · drift since 2024-11-02

The CSPM lifecycle

From inventory
to audit-ready.

Phase / 01

Inventory

Agentless discovery of every account, resource, tag and owner across all clouds.

Phase / 02

Evaluate

Run 1,500+ built-in and custom policies continuously against live cloud state.

Phase / 03

Prioritize

Grade findings by reachability, blast radius and compliance impact — not generic CVSS.

Phase / 04

Remediate

Auto-route tickets, generate IaC fixes and prove compliance with audit-ready evidence.

FAQ

Frequently asked questions.

CSPM (Cloud Security Posture Management) continuously inspects your cloud accounts for misconfigurations, compliance drift and risky resource settings. Instead of a nightly snapshot, OnDuty evaluates live cloud state against 1,500+ policies and maps each finding to the resources, identities and data it actually affects.

Tighten posture without the noise

Fix the misconfig
that's actually exposed.

See your real misconfig backlog, compliance scorecards and top exposures in a 30-min guided demo with our team.

  • Agentless inventory of every account, resource, tag & owner
  • 1,500+ built-in policies plus custom OPA / Rego rules
  • Findings graded by reachability, blast radius & data sensitivity
  • Shift-left IaC checks for Terraform, CloudFormation, Helm & Bicep
  • CIS · PCI DSS · SOC 2 · ISO 27001 · HIPAA — audit-ready evidence