Stop triaging findings. Close attack paths. 

OnDuty joins cloud posture, code, secrets, runtime and AI-agent activity into one live graph — then shows you the handful of routes an attacker can actually walk.

app.onduty.ai/dashboard
Home Dashboard

Dashboard

Exposure over time

Reachable attack paths vs. raw findings

0critical paths

9 in 30d

Sep 9Sep 16Sep 23Sep 30now

Posture score

Weighted across all domains

0
  • Cloud posture0
  • Runtime defense0
  • Identity & access0
  • AI & data0

Severity distribution

Open findings · all sources

0open

  • Critical0
  • High0
  • Medium0
  • Low0

Top priority issues

Ranked by reachability, not CVSS

live
  • CRIT

    Exposed host with loaded RCE can read PII

    CSPMRuntimeCIEMprod-api-01
    2m
  • HIGH

    Reachable CVE-2024-6387 in internet-facing image

    VulnCSPMedge-proxy
    now
  • CRIT

    Egress to Tor exit node from worker pod

    Runtimeworker-07
    now
  • HIGH

    Public bucket holds customer exports

    CSPMDatareports-2026
    3h

Platform coverage

Agentless + eBPF

  • AWS3 accounts
  • Google Cloud1 project
  • Kubernetes12 clusters
  • eBPF sensors2,424 / 2,431
  • Repositories312
  • AI agents48 governed

Correlation

Four medium findings.
One critical path.

On their own, each of these sits in a different tool's backlog marked medium. OnDuty sees them on the same graph — and raises one critical issue instead of four tickets.

Findings, as separate tools see them

  • CSPM

    prod-api-01 reachable from 0.0.0.0/0 on :443

    MEDIUM
  • Vuln mgmt

    CVE-2024-3094 in liblzma — eBPF: loaded

    MEDIUM
  • CIEM

    prod-api-role has s3:* on *

    MEDIUM
  • DSPM

    prod-data-bucket holds 2.4 TB of PII

    MEDIUM
CRITICAL

Exposed host with loaded RCE can read customer PII

1 issue · replaces 4 tickets

The platform

Eight modules of signal. One graph to make sense of it.

01 · Cloud posture

Know what's exposed before anyone else does.

Agentless across AWS, GCP and Azure. Misconfigurations, identity sprawl and Kubernetes drift are mapped against CIS, SOC 2, PCI and HIPAA — and fixed with one-click remediation you approve.

CSPMCIEMKSPMCompliance
Learn more
Posture · aws-prod3 accounts · 1,204 resources

71%

CIS v3

  • FAILS3 bucket blocks public access
  • FAILSecurity group restricts 0.0.0.0/0
  • FAILIAM role least-privilege
  • FAILEKS audit logging enabled
  • FAILRDS encryption at rest

02 · Code & supply chain

Catch it in the pull request, not the postmortem.

SAST, SCA, secrets and container images scanned on every push. Live keys are verified, packages are checked for reachability, and every image ships with an SBOM.

SAST & SCASecret scanningImage & SBOM
Learn more
payments-api / handler.pyPR #482 · scanned in 4.1s
1import boto3, os
2 
3AWS_KEY = "AKIA5Q7XJ2…F4P"
4s3 = boto3.client('s3',
5 aws_access_key_id=AWS_KEY)
6 
7data = pickle.loads(req.body)
SCA · requests 2.19 → 2.32reachableSBOM · 412 pkgs

03 · Runtime

See what actually runs — and stop what shouldn't.

A single static eBPF binary, no kernel modules or sidecars. Every exec, connect and file open is evaluated in the kernel, so a CVE that's never loaded drops down the queue.

eBPF sensorCWPPCDR
Learn more
Runtime · node ip-10-0-4-21 eBPF live
  • nodeconnect 169.254.169.254:80ALERT
  • kubeletread /var/run/secretsOK
  • xmrigexecve /tmp/.x/xmrigBLOCK
  • postgresaccept 10.0.4.12OK
  • javadlopen libssl.so.3ALERT
  • nginxopen /etc/nginx/conf.dOK

04 · AI security

AI agents are your newest insiders.

Every command from Claude Code, Cursor and Gemini is checked against policy before it executes. MCP servers and agent skills are scanned for tool poisoning and over-broad scopes.

Agent guardrailsMCP & skill scanningAI inventory
Learn more
Agent guardrails enforcing
$
  • cat ~/.aws/credentialsBLOCK
  • pytest tests/ -qALLOW
  • curl http://169.254.169.254/latest/BLOCK

AI analyst

Ask in plain English. Get proof, not a guess. 

The analyst reasons over the same graph your engineers use. Every answer shows its work — which assets, which path, which runtime evidence — and ends in a fix you can merge.

OnDuty analyst

  1. Traversed graph

    2,914 assets · 41 internet-facing

  2. Checked reachability

    3 paths reach data stores tagged pii

  3. Verified in runtime

    CVE-2024-6387 loaded in payments-api

  4. Drafted remediation

    1 PR · rotate 1 key · scope 1 role

How it works

First findings in minutes,
not quarters.

01

Connect

Read-only cloud roles, a GitHub app, and one static eBPF binary for hosts. No kernel modules, no sidecars.

$ curl -fsSL https://get.onduty.ai | bash

02

Correlate

Posture, code, secrets, runtime and agent activity land in one graph. Reachability is computed for every finding.

$ 12,483 findings → 3 paths

03

Close

Block agent commands at the source, auto-remediate drift, or ship a PR that arrives with the full path attached.

$ rollback: onduty policy revert

Fits the stack you already run.

Native connectors across cloud, code, identity, telemetry and the AI tools your engineers use.

AWSGoogle CloudAzureKubernetesGitHubGitLabDocker HubJFrogOktaAWSGoogle CloudAzureKubernetesGitHubGitLabDocker HubJFrogOkta
SlackJiraPagerDutyDatadogSplunkCloudflareClaude CodeCursorGeminiSlackJiraPagerDutyDatadogSplunkCloudflareClaude CodeCursorGemini

See your attack paths before Friday. 

Read-only by default. Connect a cloud account in five minutes, get a runtime signal on day one, and a full posture readout by the end of the week.

invite-only early access · you approve every action · rollback is one command