Aqua Cloud Security Posture Management (CSPM)

Scan, monitor and remediate configuration issues in public cloud accounts according to best practices and compliance standards, across AWS, Azure, Google Cloud, and Oracle Cloud.

Multi-Cloud visibility
Rapid Remediation
CSPM + Cloud Native Security
Gain visibility into your risk and compliance posture across cloud accounts
Aqua CSPM continually audits your cloud accounts for security risks and misconfigurations across hundreds of configuration settings and compliance best practices, enabling consistent, unified multi-cloud security.
Fix configuration errors before they’re exploited
Aqua provides self-securing capabilities to ensure your cloud accounts don’t drift out of compliance. Get detailed, actionable advice and alerts, or choose automatic remediation of misconfigured services with granular control over chosen fixes.
Implement CSPM to bolster your cloud native security
Apply consistent policies across all your cloud native deployments, combining cloud workload protection for VMs, containers, and serverless, with cloud infrastructure best practices for full-stack security.
Continuous CIS Benchmark Auditing

Get reports mapped to and certified by the Center for Internet Security (CIS) Foundation Benchmark tests for public clouds, to evaluate the security of your cloud accounts and ensure compliance.

Auto-Remediation for Self-Securing Infrastructure

Select configurations to be automatically fixed if they drifted out of policy by granting specific and temporary authenticated access for each selected check.

Infrastructure-as-Code Template Scanning

Check Terraform and AWS CloudFormation templates for security issues before your applications are deployed. Applying “shift left” security reduces your risk and security incidents in production.

Extensive Compliance Reporting

Use ready-made scans and reports for PCI-DSS, HIPAA, Well-Architected Framework, GDPR, and for custom compliance requirements. Your reports can be by region, cloud provider service category (e.g., AWS EC2, AWS S3), severity level, etc. Export as CSV or PDF. You can also build your own customized alerts for specific types of checks and conditions.

Real-Time Control Plane Events Monitoring

Gain visibility into all your cloud control-plane API calls in real time. Analyze events for security-sensitive changes or potentially malicious activity​, based on out-of-the-box rules created by security experts, with no additional configuration required.

Built for Enterprise Scale

Support for multiple users and teams across hundreds of cloud accounts with SSO using SAML 2.0. Aqua CSPM integrates with SIEM and collaboration tools, including Splunk, Slack, OpsGenie, PagerDuty, Microsoft Teams, and more. Fully documented RESTful APIs make it easy for you to create additional integrations and automate workflows.

Extensible Open Source Architecture

At its core, Aqua’s CSPM offering is based on our CloudSploit open source project. Open source provides full transparency into why, what, and how your cloud accounts are tested. With its extendable plugin architecture, you can also develop new or update existing plugins to address any emerging or customer-specific requirements.

Get CloudSploit by Aqua