Code security
Agentless code-to-cloud security
Stop the misconfiguration in the template — then prove it is gone in the account.
10ETLabs is agentless. Ten built-in pattern rules — including four for AI infrastructure — flag the most common risky settings in infrastructure-as-code: paste a template in the console, or run the same rules on every pull request with the 10et CLI in GitHub Actions, GitLab CI, Azure Pipelines, or Bitbucket Pipelines. PR checks run offline in your pipeline; an optional upload sends findings metadata, never file contents. After you connect a read-only cloud role, names are matched to live inventory. These are line-level pattern rules, not a full policy engine: no module or variable resolution, and provider defaults are not inferred. No agents. No write-back.

Code security
Catch common public, open, and wildcard patterns in a pasted template — then check the account.
See it work
Flag it in the template, then on the live resource
The same risk class fires on a pasted template and on the deployed resource, and the two findings link.
Code to cloud · same risk, both sides
01Paste the template
Paste Terraform, CloudFormation, ARM, or Kubernetes YAML in the console — no repo access needed. The same rules also run on pull requests in CI.
Ten built-in pattern rules, in the console or on every pull request — line-level checks, not a full IaC policy engine.
What you get
IaC in the browser or the pipeline
Paste Terraform (HCL or plan JSON), CloudFormation, ARM (including compiled Bicep), or Kubernetes YAML in the browser. Line-level pattern rules flag public storage, 0.0.0.0/0 ingress, Action * on Resource *, unencrypted disks, publicly accessible databases, and privileged or hostNetwork pods. Other misconfigurations are not checked.
Pull-request checks in CI
The 10et CLI runs the same rules offline on every pull request: SARIF to GitHub code scanning with a PR comment, GitLab Code Quality / SAST / JUnit reports, Azure Pipelines test results, and Bitbucket Code Insights. Fail on a severity you choose, baseline existing findings, and suppress accepted risks in code with a reason that is always reported.
AI infrastructure before deploy
Rules for public training-data and model buckets, publicly reachable Azure OpenAI / Azure ML / Vertex AI endpoints, SageMaker and Vertex notebooks with internet access, and admin roles attached to AI workloads — the same risks the AI attack paths show on live AWS.
Same finding model as the cloud
IaC issues are findings with 10ET Score, triage, and remediations — not a sidecar “shift-left product.”
Correlate after deploy
When a live asset name appears in the template, the finding links to that inventory row so the team sees code and cloud together.
Agentless multi-cloud
The same tenant connects AWS, Azure, GCP, Kubernetes, and other VPS with reader roles. No runtime agents. Read-only by default: fixes are code you review, or, only if you deploy a separate remediator role, one-click changes you approve.
In this module
Step 1
Scan the template
Paste IaC on Code to cloud, or add the 10et check to your pipeline so every pull request is scanned before merge.
Step 2
Connect read-only
Deploy the AWS, Azure, GCP, Kubernetes, or VPS onboarding template. Verify and scan the control plane.
Step 3
Work one queue
Triage IaC and live CSPM/CIEM findings together. Attack paths come only from live inventory, never from templates.
In this release
- Ten built-in IaC pattern rules for public, open, wildcard, unencrypted, and privileged settings, including AI training data, AI endpoints, AI notebooks, and admin roles on AI workloads
- Pull-request checks: offline 10et CLI with a GitHub Action and GitLab, Azure Pipelines, and Bitbucket templates (SARIF, JUnit, GitLab reports, Code Insights)
- Optional CI upload of findings metadata with write-only CI tokens: CI runs per repository and pull request, new vs fixed
- Persist and correlate with connected cloud inventory
- Agentless AWS, Azure, GCP, Kubernetes, and VPS control-plane scans
- Fix pull requests: a generated Terraform patch committed to a new branch for your review (opt-in write scope on the source-control token)
On the roadmap
- Broader IaC rule coverage
- Module and variable resolution
- Private git apps
Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.
More of the platform
Other modules — not a reprint of this page.
AI security
AI workload security
Trace attack paths to models and agents on SageMaker, Bedrock, Azure AI Foundry and Vertex AI — exposed notebooks, public training data, model weights anyone can swap, retrieval sources fed from public buckets, and workload identities with admin rights.
CSPM
Cloud Security Posture Management
Misconfiguration and identity-risk checks across AWS, Azure, GCP, Kubernetes, and other VPS — AWS-first, re-checked on every scan you run or schedule.
CWPP
Cloud Workload Protection
Inventory VMs, Lambda functions, and hosts from the control plane, and look inside VM disks with opt-in, agentless DeepScan.
CIEM
Cloud Identity & Access
AWS IAM, Azure Entra ID and GCP service accounts: missing MFA, standing admins, and effective Azure permissions that can reach sensitive data.
Containers
Container & Kubernetes Security
EKS, AKS, and any Kubernetes API you connect, ECR scan-on-push, and public services in one queue — agentless by default, with an optional sensor for runtime evidence and deploy-time blocking.
Compliance
Cloud Compliance Monitoring
CIS, SOC 2, PCI DSS, HIPAA, ISO 27001, NIST CSF, FedRAMP, GDPR, DPDP, an AI workload baseline, and your own frameworks — mapped to live findings, with signed evidence packs for auditors.
Vulnerabilities
Cloud Vulnerability Management
ECR scan-on-push gaps from the control plane, plus package CVEs from opt-in DeepScan or the optional host sensor, prioritized by blast radius.