Skip to content
NewVectasec audits service-mesh policy drift

Security that never
leaves your perimeter.

Six specialized products that run inside your boundary. Least privilege, no egress, stored evidence behind every finding.

30-minute call · NDA-friendly · No agents on your workloads

The console

A finding is a claim plus its evidence.

Each row links the exact API response that produced it, timestamped and replayable. Export the set as an audit packet your assessor can verify independently.

Tour the console
kaveo console · sample datalive
kaveo/ findingsprod · eu-west-1

Accounts

128

Open findings

37

Bytes egressed

0

Click any finding to read the API response that produced it.Click a row →

Contain at the boundary

kaveo finds misconfigurations across your cloud accounts. Vectasec hardens the middleware layer between your services. aegis controls what your agents are allowed to call. All three run inside your perimeter — nothing is shipped to a vendor cloud for analysis.

CLOUD ACCOUNTSMIDDLEWARECONFIG SNAPSHOTSZHASK DETECTORREAD-ONLY · IN YOUR VPCFINDINGSEVIDENCEAUDIT PACKETSTORED INSIDE YOUR BOUNDARY · EGRESS 0 BYTES

Platform layers

Six layers. One trust model.

Three layers ship today; three are in development and will be named when they ship, not before. Every one inherits the same architecture — deployed inside your perimeter, no egress, replayable evidence.

kaveoAvailable

Cloud Security Posture Management

Finds misconfigurations across AWS accounts for teams that can't ship telemetry to a vendor cloud. Runs in your account on a read-only role; every finding links the stored evidence that produced it.

Data egress
None
IAM access
Read-only
Deployment
Your own environment

Recent findings

S3 bucket “prod-artifacts” allows public readGetBucketAcl · 22:14:07ZHigh
IAM role “ci-deploy” permits iam:PassRole on *GetRolePolicy · 22:14:11ZMedium
CloudTrail log validation disabled in 2 regionsDescribeTrails · 22:14:19ZLow
KMS key rotation not enabled on 4 keysGetKeyRotationStatus · 22:14:24ZLow

Sample data. Severity comes from reviewable rules, never a model.

VectasecAvailable

Middleware Security

Hardens the connective layer most tools ignore. Audits API gateways, message brokers and service meshes for authentication gaps, over-broad routing and policy drift between environments.

Coverage
Gateways · brokers · meshes
Deployment
On-prem or VPC
Detection
Deterministic rules

Policy checks

Gateway route /internal/* has no auth policykong · stagingHigh
Broker topic “events.raw” world-readablekafka · prodMedium
mTLS enforced across meshistio · prodPass
Policy drift: prod vs staging3 rules differMedium

Sample data. Drift is diffed environment-to-environment, not scored.

aegisAvailable

MCP Gateway Security

Sits in front of the MCP servers your agents call. Authenticates and authorizes every tool call, filters the failure modes specific to tool use, and writes every decision to a hash-chained audit log.

Added latency
Under 50 ms
Throughput
1,000+ req/s
Audit log
Hash-chained

Recent decisions

tools/call “db.query” denied for role analystrbac · policy 14Denied
Prompt injection detected in tool argumentsfilter · payments-mcpBlocked
Response withheld, credential pattern matchedscan · files-mcpBlocked
Rate limit reached for session a41f120 calls / 60sThrottled

Sample data. Every decision is hash-chained and checkable at a verify endpoint.

Three more layersIn development

Unannounced layers

Three layers are in development. We name one when it ships, not before — no roadmap theatre and no pre-announced capability you can't verify today. What we will commit to now is the architecture every one of them inherits.

Trust model
Shared
Data egress
None
Availability
Waitlist

Committed on day one

Runs inside your perimeterInherited from the platformCommitted
No data egressInherited from the platformCommitted
Evidence-backed findingsInherited from the platformCommitted
Names, scope, pricingAnnounced at shipTBD

Join the waitlist and we'll write once, when a layer ships.

Keep scrolling to move through the stack

01 / 04

Architecture

The mechanism is the trust signal.

There is no vendor data plane and no outbound tunnel. Diff the published trust policy before you deploy anything — the shape below is the one kaveo installs.

The actual trust-policy shape kaveo installs
{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": { "AWS": "arn:aws:iam::YOU:role/kaveo-scanner" },
    "Action": "sts:AssumeRole",
    "Condition": { "StringEquals": { "sts:ExternalId": "<per-install>" } }
  }]
}
// Attached: SecurityAudit + ViewOnlyAccess.

Trust center

Our posture, stated plainly.

SOC 2 Type II is in progress; ISO 27001 is not yet pursued. We publish what we hold, what we’re working toward, and how to reach us when you find something wrong.

See your perimeter the way we do.

A 30-minute walkthrough of kaveo or Vectasec against your architecture. No deck-only demos.