
Cloud SecurityAI Security
Cyscale CNAPP Platform
Agentless CNAPP correlating posture, identity, data, and workload risk across multi-cloud.
Cyscale CNAPP Platform Overview
What it does
Cyscale CNAPP Platform is a cloud-native application protection platform (CNAPP) that unifies cloud security posture management, entitlement analysis, vulnerability management, data security, and AI security posture in one console. Its distinctive mechanism is the Security Knowledge Graph, which maps the relationships among cloud resources, identities, permissions, workloads, data stores, code, and AI services, so findings are ranked by exposure, reachability, and blast radius rather than raw severity scores and reach teams as fix-first remediation work.
How it works
The platform onboards cloud accounts through agentless, read-only provider APIs across AWS, Azure, Google Cloud, Alibaba Cloud, and Kubernetes, with an optional in-cluster agent supplying Kubernetes runtime inventory and package metadata. Connectors also pull identity context from identity providers and code scanning findings from source repositories. More than 500 out-of-the-box controls map findings to frameworks such as CIS, ISO 27001, SOC 2, PCI DSS, and NIST with continuous evidence collection, while the Security Knowledge Graph correlates misconfigurations, vulnerable packages, exposed secrets, and excessive permissions into attack paths and routes prioritized, owner-assigned remediation.
Credentials and traction
ISO 27001 certified, with a SOC 2 attestation in progress. Cyscale was named a Representative Vendor in the 2025 Gartner Market Guide for Cloud-Native Application Protection Platforms, and published case studies include FP Markets, MeetGeek, Smart Fintech, and Bays Consulting. Positioned as Europe-built cloud security, the platform targets startups, scaleups, and regulated mid-market companies across fintech, banking, and healthtech, as well as managed security service providers.
Key Capabilities
mapped to solution categoriesDiscovers and classifies sensitive data in IaaS and PaaS stores such as object storage, databases, and data warehouses, surfacing data exposure risk alongside infrastructure findings.
Exports compliance evidence pre-mapped to framework control requirements (SOC 2, ISO 27001, PCI DSS), in formats auditors can consume directly: not raw CSV exports requiring manual assembly.
Assesses the configuration of Kubernetes clusters and managed orchestrators (EKS, AKS, GKE, ECS, Fargate, OpenShift) against best-practice templates, surfacing cluster misconfigurations, weak RBAC, exposed control planes and configuration drift, and driving their remediation. Distinct from runtime workload monitoring: this is the posture of the orchestrator itself.
Maps the effective access of human and machine identities to compute, storage and data resources across AWS, Azure and GCP as an access relationship graph, surfacing over-permissioned roles, unused permissions, cross-account trust and toxic combinations of administrator permissions, and remediating them toward least privilege, including automatic revocation of excessive roles.
Enforces a single policy definition across AWS, Azure, and GCP resource types, translating to provider-native configurations rather than requiring separate policy sets per cloud.
Scans infrastructure-as-code templates (Terraform, CloudFormation, Kubernetes manifests and Helm charts) for misconfigurations, policy violations and embedded secrets before deployment, gates CI/CD pipelines on the resulting risk, and detects drift between the IaC definition and the deployed resource. Depth of productized pipeline integration and drift remediation varies across products.
Continuously audits cloud and Kubernetes configuration across AWS, Azure, and GCP against security benchmarks, flagging misconfigurations and identity-permission gaps that create exploitable exposures.
Correlates individual misconfigurations, CVEs and excessive entitlements into chained attack scenarios showing lateral movement paths from an exposed entry point to a target asset, visualized on the resource graph. Produces a prioritized list of attack paths rather than a flat CVE inventory. Products differ in whether they show only possible paths derived from posture data or also actual paths confirmed from runtime and log telemetry.
Analyzes container images and dependencies for CVEs, malicious or compromised packages, and SBOM generation across the build pipeline.
Shows compliance against each regulatory mandate as a timeline so auditors can see when a control passed or failed and how posture trended, and keeps platform policies under version control so administrators can review, roll back and automate policy changes from a versioned repository.
Aggregates posture findings and policy enforcement across multiple cloud accounts, subscriptions, and projects from a single control plane, critical for organizations with 10+ cloud accounts.
Applies the same posture policies and compliance benchmarks used against live cloud accounts to Terraform, CloudFormation, ARM templates and Pulumi configurations at pull-request or pipeline time, so a misconfiguration is caught before it appears in the deployed posture. Pipeline gating, secrets detection and drift remediation in IaC scripts are separate IaC security capabilities.
Maps detected misconfigurations to specific control requirements across CIS Benchmarks, NIST 800-53, SOC 2, PCI DSS, HIPAA, and ISO 27001 in a single assessment pass.
Builds a graph of which human and machine identities can reach which compute, storage and data resources, resolving roles, groups, trust relationships and inherited policies into effective access, so risky access patterns and toxic combinations of administrator permissions are visible before they are exploited.
Records approved exceptions and risk acceptances for specific findings, resources or policies, with owner, justification and expiry, so accepted risk is excluded from posture scores and reports without deleting the underlying evidence, and expired exceptions resurface automatically.
Audits configuration, compliance and entitlements on cloud platforms beyond AWS, Azure and Google Cloud, including Alibaba Cloud, Oracle Cloud Infrastructure, Tencent Cloud, IBM Cloud and OpenStack, using the same policy set applied to the hyperscalers. Which secondary platforms are supported, and at what check depth, varies significantly across products.
Detects configuration changes from a known-good baseline in near real time using cloud API event streams (CloudTrail, Azure Activity Log, GCP Audit Logs), rather than relying on periodic full scans.
Audits cloud service configurations across AWS, Azure, and GCP against security best practices and benchmarks, flagging misconfigurations such as public storage, permissive network rules, and disabled logging. Coverage breadth and per-service depth vary significantly across products.
Continuously discovers and inventories cloud resources across accounts, subscriptions and projects so posture assessment runs against a current, complete picture of the environment rather than a stale or partial asset list, and groups resources into collections by custom tags and account scope for targeted policies and reports. Coverage of newer and less common resource types varies across products.
Chains misconfigurations, exposed network paths, vulnerable assets and excessive entitlements into possible attack paths from internet-facing entry points to sensitive resources, visualized on the cloud resource graph, so posture findings are prioritized by exploitability rather than severity alone. Built from configuration and identity posture data rather than runtime telemetry.
Assesses the identities and service accounts that AI models, pipelines, and agents use, flagging over-permissioned non-human identities and access paths that violate least privilege. Reports identity risk as a posture finding, distinct from enforcing access policies at the model API at runtime.
Automatically discovers AI models, LLM API connections, ML pipelines, and AI-enabled SaaS applications in use across the organization, including those deployed without IT authorization.
Discovers AI model and inference endpoints and flags public exposure, weak authentication, default credentials, or excessive permissions as posture misconfigurations.
Detects sensitive or regulated data in AI training, fine-tuning, or third-party LLM flows without appropriate controls, such as unencrypted PII in inputs or PHI sent to external APIs.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
See how Cyscale CNAPP Platform fits your stack
Add Cyscale CNAPP Platform to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.