Security Stack Logo
JupiterOne Platform logo

Security Operations

JupiterOne Platform

Graph-native CAASM modeling assets as a queryable graph to surface coverage gaps and risk paths.

Cyber Asset Attack Surface Management (CAASM)

JupiterOne Platform Overview

What it does

The JupiterOne Platform is a graph-native Cyber Asset Attack Surface Management (CAASM) platform that models an organization's entire environment as a connected graph of assets and relationships rather than a flat inventory. Its distinguishing mechanism is J1QL, a purpose-built query language that lets security teams reason across those relationships, surfacing attack chains, excessive permissions, and risk paths that isolated tool inventories miss.

How it works

The platform ingests devices, cloud resources, users, code, vulnerabilities, and configurations from more than 200 prebuilt integrations into a single graph, resolving them into one connected model. Teams query it with J1QL or in natural language to answer questions such as which resources are unprotected, which users hold excessive permissions, or which assets run outdated software, and to identify where required security controls are missing. Relationship mapping links assets to their owners and dependencies, and the graph is used as the evidence layer for control monitoring. Named customers include HSBC, Okta, Rippling, and Mercury Financial.

Credentials and traction

JupiterOne's platform was used to automate SOC 2 evidence collection for a SOC 2 Type 2 examination the company passed in 2020. Gartner named JupiterOne a Sample Vendor for Cyber Asset Attack Surface Management in the 2022 Hype Cycle for Security Operations. Named customers include HSBC, Okta, Rippling, Mercury Financial, Blend, and Socotra. The platform targets enterprise security programs, including Fortune 500 organizations.

Key Capabilities

mapped to solution categories
Cyber Asset Attack Surface Management (CAASM)

Ingests and normalizes asset records from EDR, CMDB, cloud platforms, vulnerability scanners, and network discovery tools into a unified, deduplicated asset inventory.

Provides a structured query interface for ad hoc questions against the unified asset inventory ('which internet-exposed assets are running EOL software?'), without requiring a custom report.

Identifies assets not covered by required security controls, endpoints without EDR agents, systems absent from vulnerability scan scope, cloud resources not in CSPM coverage.

Consolidates and maps the scope of known vulnerabilities and exposures across the deduplicated asset inventory, pairing the vulnerability view with control-gap identification: the "scope of vulnerabilities" half of Gartner's CAASM definition that the coverage-gap row alone does not cover.

Associates discovered assets with business owners, application teams, and cost centers using directory, CMDB, and cloud tag data.

Automates remediation and data-correction actions on identified issues (including write-back to update asset records and CMDB data, and prioritization of necessary remediation and mitigation), going beyond a read-only inventory.

Compliance

certifications
SOC 2 Type II

Integrations

compatible tools
1PasswordAlibaba CloudAutomoxAWSAzureBitbucketCarbon BlackDatadogGitHubGoogle CloudJiraServiceNowSplunk

Implementation & support

Deployment model
SaaS
Pricing structure
Custom / Enterprise
Support channels
Documentation

Info last updated on June 30, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.