For the complete documentation index, see llms.txt. This page is also available as Markdown.

CSPM (Cloud Security Posture Management)

Introduction

Sec1 CSPM gives you continuous, agentless, read-only visibility into the security posture of your cloud estate. You connect a cloud account with a read-only credential, the Sec1 platform inventories your resources, and it continuously checks them for misconfigurations, compliance gaps, exposure, identity risk, and exploitable attack paths — then prioritises what to fix first and helps you remediate it.

Sec1 CSPM scans Google Cloud (GCP), Microsoft Azure, AWS, and Kubernetes (GKE, AKS, and EKS). Nothing is ever written back to your cloud — every credential Sec1 asks for is read-only.

One-line model: add a cloud account → provide a read-only credential → test the connection → run a scan → review assets, findings, compliance, and attack paths in the Sec1 console.

Key Features

These map to the core CSPM capability areas Sec1 covers:

  • Asset inventory — auto-discover and catalogue every resource across your connected cloud accounts and clusters.

  • Misconfiguration detection — out-of-the-box rules for common misconfigurations (public storage, open ingress, weak IAM, unencrypted data, and more), with severity and contextual remediation guidance, suppression with audit trail, and drift tracking over time.

  • Compliance management — ~12 frameworks out of the box (CIS, PCI DSS, ISO 27001, SOC 2, NIST CSF, NIST 800-53, CSA CCM, FedRAMP, CIS Controls), control-ID mapping, scoring, and exportable reports.

  • Attack path analysis — visualise chained risks from external exposure to critical assets, see blast radius, and get remediation that breaks the path at the optimal point.

  • Prioritisation & threat intelligence — risk-based scoring that factors in exposure, asset criticality, and exploit context, so you see the top risks to fix now rather than a flat severity list.

  • Kubernetes misconfiguration detection — cluster RBAC over-permission, privileged pods, exposed dashboards, network policy gaps, and CIS Kubernetes Benchmark checks on GKE and AKS.

  • AI-assisted remediation & Ask-AI — guided fixes and a natural-language assistant for investigating findings.

  • Point-in-time trends, reporting & ticketing — historical posture snapshots, PDF + CSV reports, Jira ticketing and assignment, and team-based access.

Getting Started

Work through these pages in order:

  1. Prerequisites — the read-only access model, network reachability, identity, supported providers, and the SaaS vs hybrid/on-prem split.

  2. Required Permissions — copy-pasteable read-only role lists for GCP, Azure, AWS, and Kubernetes (GKE / EKS / AKS), with a summary table.

  3. Onboarding & Your First Scan — add a cloud account in the Sec1 console, test the connection, run a scan, and view results.

  4. Frameworks, Coverage & FAQ — supported compliance frameworks, what gets scanned, reporting/exports, and frequently asked questions.

Onboarding at scale. Beyond a single account, you can onboard at organization scope — grant the read-only roles once at a GCP organization/folder or an Azure management group, and Sec1 discovers all child projects/subscriptions for you to multi-select and onboard in one flow. See Onboarding.

Last updated