Stop triaging findings. Close attack paths.
OnDuty joins cloud posture, code, secrets, runtime and AI-agent activity into one live graph — then shows you the handful of routes an attacker can actually walk.
Dashboard
Exposure over time
Reachable attack paths vs. raw findings
0critical paths
9 in 30d
Posture score
Weighted across all domains
- Cloud posture0
- Runtime defense0
- Identity & access0
- AI & data0
Severity distribution
Open findings · all sources
0open
- Critical0
- High0
- Medium0
- Low0
Top priority issues
Ranked by reachability, not CVSS
- CRIT2m
Exposed host with loaded RCE can read PII
CSPMRuntimeCIEMprod-api-01 - HIGHnow
Reachable CVE-2024-6387 in internet-facing image
VulnCSPMedge-proxy - CRITnow
Egress to Tor exit node from worker pod
Runtimeworker-07 - HIGH3h
Public bucket holds customer exports
CSPMDatareports-2026
Platform coverage
Agentless + eBPF
AWS3 accounts
Google Cloud1 projectKubernetes12 clusters
- eBPF sensors2,424 / 2,431
Repositories312
AI agents48 governed
Correlation
Four medium findings.
One critical path.
On their own, each of these sits in a different tool's backlog marked medium. OnDuty sees them on the same graph — and raises one critical issue instead of four tickets.
Findings, as separate tools see them
- MEDIUM
CSPM
prod-api-01 reachable from 0.0.0.0/0 on :443
- MEDIUM
Vuln mgmt
CVE-2024-3094 in liblzma — eBPF: loaded
- MEDIUM
CIEM
prod-api-role has s3:* on *
- MEDIUM
DSPM
prod-data-bucket holds 2.4 TB of PII
Exposed host with loaded RCE can read customer PII
1 issue · replaces 4 tickets
The platform
Eight modules of signal. One graph to make sense of it.
01 · Cloud posture
Know what's exposed before anyone else does.
Agentless across AWS, GCP and Azure. Misconfigurations, identity sprawl and Kubernetes drift are mapped against CIS, SOC 2, PCI and HIPAA — and fixed with one-click remediation you approve.
71%
CIS v3
- FAILS3 bucket blocks public access
- FAILSecurity group restricts 0.0.0.0/0
- FAILIAM role least-privilege
- FAILEKS audit logging enabled
- FAILRDS encryption at rest
02 · Code & supply chain
Catch it in the pull request, not the postmortem.
SAST, SCA, secrets and container images scanned on every push. Live keys are verified, packages are checked for reachability, and every image ships with an SBOM.
03 · Runtime
See what actually runs — and stop what shouldn't.
A single static eBPF binary, no kernel modules or sidecars. Every exec, connect and file open is evaluated in the kernel, so a CVE that's never loaded drops down the queue.
- nodeconnect 169.254.169.254:80IMDS probeALERT
- kubeletread /var/run/secretsexpectedOK
- xmrigexecve /tmp/.x/xmrigcryptominerBLOCK
- postgresaccept 10.0.4.12expectedOK
- javadlopen libssl.so.3CVE loadedALERT
- nginxopen /etc/nginx/conf.dexpectedOK
04 · AI security
AI agents are your newest insiders.
Every command from Claude Code, Cursor and Gemini is checked against policy before it executes. MCP servers and agent skills are scanned for tool poisoning and over-broad scopes.
cat ~/.aws/credentialsBLOCK
pytest tests/ -qALLOW
curl http://169.254.169.254/latest/BLOCK
AI analyst
Ask in plain English. Get proof, not a guess.
The analyst reasons over the same graph your engineers use. Every answer shows its work — which assets, which path, which runtime evidence — and ends in a fix you can merge.
Traversed graph
2,914 assets · 41 internet-facing
Checked reachability
3 paths reach data stores tagged pii
Verified in runtime
CVE-2024-6387 loaded in payments-api
Drafted remediation
1 PR · rotate 1 key · scope 1 role
How it works
First findings in minutes,
not quarters.
01
Connect
Read-only cloud roles, a GitHub app, and one static eBPF binary for hosts. No kernel modules, no sidecars.
$ curl -fsSL https://get.onduty.ai | bash02
Correlate
Posture, code, secrets, runtime and agent activity land in one graph. Reachability is computed for every finding.
$ 12,483 findings → 3 paths03
Close
Block agent commands at the source, auto-remediate drift, or ship a PR that arrives with the full path attached.
$ rollback: onduty policy revertFits the stack you already run.
Native connectors across cloud, code, identity, telemetry and the AI tools your engineers use.
AWS
Google Cloud
Azure
AWS
Google Cloud
AzureSee your attack paths before Friday.
Read-only by default. Connect a cloud account in five minutes, get a runtime signal on day one, and a full posture readout by the end of the week.
invite-only early access · you approve every action · rollback is one command