Cloud asset inventory
Identify accounts, regions, compute, storage, databases, networks, identities and security services with stable provider identity.
Discover cloud resources, evaluate control state, expose configuration drift and prioritize public, privileged and business-critical risk with asset context.
A failed control is evidence of a weak state; context explains whether it is an urgent business exposure.
EnProbe's CSPM architecture continuously discovers cloud resources and evaluates configuration against expected controls across accounts and regions.
The initial collector design is AWS-oriented and uses safe, read-only onboarding patterns. The shared model remains provider-neutral so future adapters do not require separate finding lifecycles or risk queues.
Every capability shares evidence, identity, context, workflow and audit instead of producing another disconnected queue.
Identify accounts, regions, compute, storage, databases, networks, identities and security services with stable provider identity.
Preserve pass, fail, unknown and not-applicable evidence instead of storing only failures.
Identify internet-facing resources, broad network rules and paths that make harm more plausible.
Understand roles, policies, trust relationships, stale credentials and powerful workload identities.
Record first seen, last seen, checksums and previous evidence so teams can understand what changed and when.
Make last success, partial failure, throttling, stale data and retry state visible in the posture view.
Use temporary cross-account credentials, external IDs, least privilege and secret references.
Handle pagination, region and account scope, throttling, retries and deterministic identity.
Persist control evidence and link failed states to the correct resources, applications and owners.
Explain the unsafe state and expected protection without silently changing infrastructure by default.
Not by default. Read-only assessment and guidance are the safer starting point. Automated remediation requires explicit policy, safeguards, approvals, rollback and audit.
No. It is evidence of an unsafe or non-compliant state. Exploitability and business impact require additional exposure and asset context.
The first collector architecture is AWS-oriented. The canonical asset, control and finding model is provider-neutral so Azure and Google Cloud adapters can be introduced later.
Discover what exists. Test what can fail. Understand what matters. Fix it with the right owner. Retest it with evidence. Prove that risk is being reduced.