CSPM
Cloud Security Posture Management
See misconfigurations in context — then fix the ones that reach data.
10ETLabs CSPM inventories the control plane on a read-only role, normalizes findings across AWS, Azure, GCP, Kubernetes, and other VPS, and ranks them with 10ET Score using exposure and blast radius. Rule depth is greatest on AWS; other providers have a smaller, named set of checks. Findings refresh when a scan runs — on demand, or on a daily or weekly schedule you configure. One queue, not a stack of vendor consoles.

CSPM
Posture across AWS, Azure, GCP, Kubernetes, and other VPS — deepest on AWS. One finding model, ranked by 10ET Score.
See it work
Every cloud’s findings, one ranked queue
Findings from each provider share one shape, then 10ET Score orders them by exposure and blast radius.
Many clouds · one ranked queue
01Scan each cloud
Posture jobs list each connected provider’s control plane with its reader role or token — AWS deepest, then Azure, GCP, and Kubernetes.
Sample findings using real rule titles. Scores follow the 10ET Score formula.
What you get
Multi-cloud posture
AWS is deepest: S3 public access and encryption, world-open security groups, EBS encryption, public RDS, IAM MFA, root keys and admin wildcards, CloudTrail logging, public EKS endpoints, API Gateway, and Lambda URLs. Azure (from Resource Graph): internet-open NSG rules for SSH, RDP, database ports, or all ports; VMs whose public IP sits behind such an NSG; storage accounts with public blob access, HTTP allowed, TLS below 1.2, shared-key auth, or an open network default; Key Vault purge protection and network exposure; SQL server public network access and TLS; AKS public API without authorized ranges, RBAC off, and local accounts. SQL firewall rules are not read. GCP (from Cloud Asset Inventory): world-open firewall rules for SSH, RDP, database ports, or all ports; external IPs; public buckets and buckets without uniform bucket-level access; Cloud SQL open to 0.0.0.0/0, without required SSL, or without backups; GKE public control planes without authorized networks, legacy ABAC, basic-auth or client certificates, and Shielded Nodes off; service accounts with project Owner/Editor and user-managed keys older than 90 days. Vertex AI and Azure AI Foundry checks are listed under AI workload security. Kubernetes: public services and privileged or hostNetwork pods. Other VPS: public IPs, plus deeper checks where you install the optional host sensor.
Attack-path context
On AWS, a public bucket that feeds a SageMaker or Bedrock model, or an internet-facing workload running as an admin role, becomes an attack path. Other findings are ranked by 10ET Score.
Changes between scans
Each scan you run or schedule refreshes last-seen timestamps and re-evaluates rules. There is no real-time change feed between scans. Open, resolved, and suppressed states stay tenant-scoped so the team works one list.
Ask 10ET on the estate
Ask which CIS failures are internet-exposed. Answers use this tenant’s findings — not a generic playbook.
In this module
Step 1
List the control plane
Posture jobs inventory what each provider’s checks need — on AWS that includes security groups, storage, logging, and encryption — across connected units.
Step 2
Normalize the finding
The same public / open / unencrypted class is one row whether it came from AWS, Azure, GCP, Kubernetes, or VPS.
Step 3
Open CSPM
Filter by unit, suppress sandbox noise, and leave compliance export to the Compliance module.
In this release
- API-based inventory and built-in posture rules
- 10ET Score ranking and Overview widgets
- Tenant isolation and RBAC on mutations
- Fix as code for the top rules (Terraform, CloudFormation, Azure CLI / Bicep, gcloud, Kubernetes patches) built from each finding’s evidence
- Optional one-click fixes through a separate, least-privilege remediator role: preview, Owner/Admin approval, re-read confirmation, audit trail and rollback
On the roadmap
Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.
More of the platform
Other modules — not a reprint of this page.
AI security
AI workload security
Trace attack paths to models and agents on SageMaker, Bedrock, Azure AI Foundry and Vertex AI — exposed notebooks, public training data, model weights anyone can swap, retrieval sources fed from public buckets, and workload identities with admin rights.
Code security
Agentless code-to-cloud security
Check Terraform, CloudFormation, ARM, and Kubernetes YAML against built-in pattern rules — in the console or on every pull request — then see the same risk classes on live AWS, Azure, GCP, Kubernetes, and other VPS.
CWPP
Cloud Workload Protection
Inventory VMs, Lambda functions, and hosts from the control plane, and look inside VM disks with opt-in, agentless DeepScan.
CIEM
Cloud Identity & Access
AWS IAM, Azure Entra ID and GCP service accounts: missing MFA, standing admins, and effective Azure permissions that can reach sensitive data.
Containers
Container & Kubernetes Security
EKS, AKS, and any Kubernetes API you connect, ECR scan-on-push, and public services in one queue — agentless by default, with an optional sensor for runtime evidence and deploy-time blocking.
Compliance
Cloud Compliance Monitoring
CIS, SOC 2, PCI DSS, HIPAA, ISO 27001, NIST CSF, FedRAMP, GDPR, DPDP, an AI workload baseline, and your own frameworks — mapped to live findings, with signed evidence packs for auditors.
Vulnerabilities
Cloud Vulnerability Management
ECR scan-on-push gaps from the control plane, plus package CVEs from opt-in DeepScan or the optional host sensor, prioritized by blast radius.