CLOUD SECURITY PLATFORM
kaveo
kaveo scans your cloud accounts with read-only access, derives findings deterministically, and records what each collector read in an append-only evidence ledger. Its AI layer explains, prioritizes and drafts fixes, and every claim it makes cites that evidence.
- Detectors
- 97
- Collectors
- 48
- Compliance frameworks
- 10
- MCP tools
- 7
Why kaveo#
Deterministic detection
97 rules run as pure functions over the facts a scan collected, so the same account state gives the same findings. AI never creates a finding.
Evidence ledger
Each collector run, and for collectors such as IAM each API call and page, becomes an append-only observation. Each finding and each AI claim links to the observations behind it.
Grounded AI
Five stages: prioritize, explain, remediate, investigate and compliance impact. A claim with no citation, or with a citation that does not resolve to a stored observation, is dropped before it is stored.
Attack paths
kaveo traces internet-to-crown-jewel paths over the IAM and reachability graph, and flags toxic paths and choke points.
Verified remediation
Fixes move through a saga that an admin approves, and run as a dry run by default. With the AWS executor enabled, a supported fix is applied through a separate, narrowly scoped write role and then verified, in most cases by a targeted re-scan.
Read-only by default
On AWS, scanning uses a read-only role pinned by an ExternalId. AI runs offline out of the box, and hosted AI, Slack, GitHub and the MCP server are each opt-in.
Compliance mapping
Findings roll up onto 10 frameworks. Each rule carries an estimated breach-cost range and a documented public incident or published research case. Export as CSV, JSON, an evidence sheet or PDF.
Agent and CI access
A read-only MCP server exposes 7 tools to your agents, and a CI-first kaveo CLI returns stable exit codes for pipeline gates.
What it covers#
kaveo covers AWS in depth: 44 collectors and 93 detectors span public exposure, data stores, identity, logging, network, secrets, compute and AI services, plus Inspector CVEs that appear on CISA's Known Exploited Vulnerabilities list. It also imports your native GuardDuty, Inspector and Security Hub findings. These are marked native so you can tell them apart from kaveo's own deterministic results, and they pass through the same suppression rules. On top of individual findings, kaveo builds attack paths, groups findings per resource into issues you can triage, and maps each result to compliance controls. Coverage of Azure, GCP, Kubernetes and GitHub is early: each has one collector and one detector today.
How it fits#
kaveo runs entirely inside your perimeter as a Docker Compose stack of five containers. Caddy handles ingress and TLS, web serves the Next.js console, api is the FastAPI service, worker runs scans and other background jobs from the same build as api, and Postgres 16 stores everything. The app connects to Postgres as a non-superuser role, so row-level security is enforced by the database. An optional sixth service runs a local model through Ollama, and starts only when you pass --profile local-model. In the Compose stack the AI provider defaults to offline, a deterministic stub, so a scan's only outbound traffic is the role assumption and the read-only API calls it makes to the accounts you connect. For isolated networks, an air-gapped bundle packages the images with SHA256 checksums that you verify before loading. For a product-level view, see the kaveo product page.
Next steps#
- Quick start: set the required secrets, start the stack and explore a seeded demo scan.
- How kaveo works: follow a scan from collection through the evidence ledger, the graph and detection.
- Security model: the read-only role, tenant isolation, access control and how the AI layer is grounded.
- Connect cloud accounts: deploy the read-only role in AWS and register Azure, GCP, Kubernetes or GitHub.
- Remediation and autonomous patrol: approve fixes, enable the AWS executor and let patrol draft proposals for review.