Skip to main content10ETLabsRequest demo

Cloud access

What the reader can see

Permissions and collection scope only. How Verify and Assess run is on How it works. What we persist is on Trust.

AWS

IAM role: SecurityAudit plus an explicit list of read-only calls, ExternalId-gated

Onboarding
CloudFormation (one-click), Terraform or AWS CLI. You keep the role in your account.
Verify
Assumes the role, then probes each service family (regions, IAM, S3, CloudTrail, SageMaker, Bedrock) and lists what is missing. We never store long-lived AWS user keys.
Listed
Accounts, regions, IAM, S3, EC2, RDS, EKS, Lambda, API Gateway, CloudTrail, EBS, SageMaker, Bedrock.
Never collected
Disk contents, object payloads, VPC traffic, CloudTrail event lakes.

Azure

Reader on each subscription, plus optional read-only Microsoft Graph permissions for Entra ID

Onboarding
Cloud Shell script, portal steps or Terraform: an app registration with Reader on each subscription and, for Entra ID, Directory.Read.All and RoleManagement.Read.Directory (Policy.Read.All and AuditLog.Read.All optional) with admin consent.
Verify
Signs in as the app, lists subscriptions, runs a Resource Graph query and reports which Microsoft Graph permissions are granted (missing ones mean partial Entra ID coverage, with the fix). The AI reads are ARM GETs covered by the same Reader role. Client secret encrypts at rest.
Listed
Subscriptions and an Azure Resource Graph listing of resources. Checks use NSG rules, VMs with their NICs, public IPs and subnets, storage accounts, Key Vaults, SQL servers, AKS clusters, Azure OpenAI / AI Services accounts with their model deployments and content filters, AI Foundry hubs and projects with their connections, Azure ML online endpoints (the model, training job, image and managed-identity roles behind each), compute instances and AI Search index sources. Entra ID users, groups, service principals, managed identities, app registrations (credential expiry dates only), directory roles with PIM, and Conditional Access; Azure role assignments, role definitions and deny assignments to compute effective permissions. SQL firewall rules are not collected.
Never collected
Blob bytes, disk snapshots, activity-log archives, prompts, completions, training files, model weights, keys, connection secrets, and secret or certificate values.

GCP

Cloud Asset Viewer, Browser, Vertex AI Viewer and Notebooks Viewer on the project

Onboarding
Cloud Shell script, console steps or Terraform; a service account JSON key (workload identity federation is not supported yet).
Verify
Signs in with the key, reads the project, lists resources and IAM policies through Cloud Asset Inventory, and checks Vertex AI and Workbench reads. The key is encrypted at rest.
Listed
Project IAM policy, Compute Engine instances and VPC firewall rules, Cloud Storage buckets and their IAM policies, GKE clusters, Cloud SQL instances, and IAM service accounts and user-managed keys via Cloud Asset Inventory; Vertex AI endpoints, models, datasets, training and tuning jobs, Vector Search, feature stores, RAG corpora, Agent Engine and Workbench instances via the Vertex AI and Notebooks APIs (configuration only).
Never collected
Object data, disk images, Cloud Logging stores, dataset items, prompts, predictions and model weights.

Kubernetes

ClusterRole with list only (nodes, pods, services, deployments)

Onboarding
One manifest: ClusterRole, service account and a long-lived token Secret. Paste the token and cluster CA.
Verify
HTTPS to the API server you name, TLS checked against the cluster CA, then a list of each kind. Production refuses skipTls. Private IPs only in on-prem or hybrid.
Listed
Nodes, services, deployments, pods the role can list; public LoadBalancers; privileged / hostNetwork flags.
Never collected
Container filesystems, etcd dumps, exec into pods.

Other VPS

Vendor API token or a host JSON you already maintain

Onboarding
DigitalOcean, Hetzner, Linode, Vultr token, or a static host list. Allowlist this console IP if the vendor requires it. No SSH agent.
Verify
Read-only vendor call or parse of the list you pasted.
Listed
Host identity, region, public IP from the vendor API.
Never collected
Guest packages without a sensor, SSH sessions, disk images.

Host sensor

Optional sensor on each guest host

Onboarding
Save VPS hosts on Connections, then install the host sensor script on each machine.
Verify
Sensor heartbeats to the console; online count appears on the connection card.
Listed
Package vulnerabilities, exposed secrets, and malware indicators from the host filesystem.
Never collected
Live process injection, network taps, disk image export.

Templates ship with the product. Secrets encrypt with AES-256-GCM. Trust

Bring one reader role to the walkthrough

We Verify that identity. Templates are not pasted again here.