Safeguard Docs
Enterprise Software Supply Chain Manager (ESSCM)IntegrationsVAPT Scans (CLI)

Cloud Scan

Assess cloud configuration posture (CSPM) for AWS, Azure, or GCP

Cloud Scan

The cloud scan assesses your cloud configuration posture (CSPM) across AWS, Azure, or GCP. It reads your account configuration through your own read-only credentials and reports misconfigurations against widely used cloud security benchmarks. Because it reads configuration rather than probing hosts, it can be run from anywhere.

Prerequisites

  • The Safeguard CLI installed and signed in.
  • Read-only credentials for the cloud account, available in your environment (the same way the provider's own CLI reads them).
  • Authorization (--i-am-authorised).

Usage

safeguard cloud-scan --provider aws --i-am-authorised
safeguard cloud-scan --provider azure --i-am-authorised
safeguard cloud-scan --provider gcp --i-am-authorised

Credentials

Credentials are read from your environment and passed only to the scan for the duration of the run. They are never persisted and never stored in a finding. Use a read-only role scoped to configuration review.

What you get

  • Vulnerabilities — cloud misconfigurations, mapped to the relevant benchmark controls.

Results upload to a project in your console when the scan completes.

Notes

  • Scan only cloud accounts you own or are authorized to assess.

On this page