Skip to main content10ETLabsRequest demo

Code security

Agentless code-to-cloud security

Stop the misconfiguration in the template — then prove it is gone in the account.

10ETLabs is agentless. Ten built-in pattern rules — including four for AI infrastructure — flag the most common risky settings in infrastructure-as-code: paste a template in the console, or run the same rules on every pull request with the 10et CLI in GitHub Actions, GitLab CI, Azure Pipelines, or Bitbucket Pipelines. PR checks run offline in your pipeline; an optional upload sends findings metadata, never file contents. After you connect a read-only cloud role, names are matched to live inventory. These are line-level pattern rules, not a full policy engine: no module or variable resolution, and provider defaults are not inferred. No agents. No write-back.

Close-up of infrastructure-as-code on a developer screen

Code security

Catch common public, open, and wildcard patterns in a pasted template — then check the account.

See it work

Flag it in the template, then on the live resource

The same risk class fires on a pasted template and on the deployed resource, and the two findings link.

Code to cloud · same risk, both sides

01Paste the template

Paste Terraform, CloudFormation, ARM, or Kubernetes YAML in the console — no repo access needed. The same rules also run on pull requests in CI.

Ten built-in pattern rules, in the console or on every pull request — line-level checks, not a full IaC policy engine.

What you get

IaC in the browser or the pipeline

Paste Terraform (HCL or plan JSON), CloudFormation, ARM (including compiled Bicep), or Kubernetes YAML in the browser. Line-level pattern rules flag public storage, 0.0.0.0/0 ingress, Action * on Resource *, unencrypted disks, publicly accessible databases, and privileged or hostNetwork pods. Other misconfigurations are not checked.

Pull-request checks in CI

The 10et CLI runs the same rules offline on every pull request: SARIF to GitHub code scanning with a PR comment, GitLab Code Quality / SAST / JUnit reports, Azure Pipelines test results, and Bitbucket Code Insights. Fail on a severity you choose, baseline existing findings, and suppress accepted risks in code with a reason that is always reported.

AI infrastructure before deploy

Rules for public training-data and model buckets, publicly reachable Azure OpenAI / Azure ML / Vertex AI endpoints, SageMaker and Vertex notebooks with internet access, and admin roles attached to AI workloads — the same risks the AI attack paths show on live AWS.

Same finding model as the cloud

IaC issues are findings with 10ET Score, triage, and remediations — not a sidecar “shift-left product.”

Correlate after deploy

When a live asset name appears in the template, the finding links to that inventory row so the team sees code and cloud together.

Agentless multi-cloud

The same tenant connects AWS, Azure, GCP, Kubernetes, and other VPS with reader roles. No runtime agents. Read-only by default: fixes are code you review, or, only if you deploy a separate remediator role, one-click changes you approve.

In this module

  1. Step 1

    Scan the template

    Paste IaC on Code to cloud, or add the 10et check to your pipeline so every pull request is scanned before merge.

  2. Step 2

    Connect read-only

    Deploy the AWS, Azure, GCP, Kubernetes, or VPS onboarding template. Verify and scan the control plane.

  3. Step 3

    Work one queue

    Triage IaC and live CSPM/CIEM findings together. Attack paths come only from live inventory, never from templates.

In this release

  • Ten built-in IaC pattern rules for public, open, wildcard, unencrypted, and privileged settings, including AI training data, AI endpoints, AI notebooks, and admin roles on AI workloads
  • Pull-request checks: offline 10et CLI with a GitHub Action and GitLab, Azure Pipelines, and Bitbucket templates (SARIF, JUnit, GitLab reports, Code Insights)
  • Optional CI upload of findings metadata with write-only CI tokens: CI runs per repository and pull request, new vs fixed
  • Persist and correlate with connected cloud inventory
  • Agentless AWS, Azure, GCP, Kubernetes, and VPS control-plane scans
  • Fix pull requests: a generated Terraform patch committed to a new branch for your review (opt-in write scope on the source-control token)
Request a demo

On the roadmap

  • Broader IaC rule coverage
  • Module and variable resolution
  • Private git apps

Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.

More of the platform

Other modules — not a reprint of this page.