The platform
One sensor. One graph.
Every surface.
A single eBPF binary and a handful of agentless connectors feed cloud posture, code, secrets, identity, runtime, and AI agent activity into one live graph — so there's one place to look, not five tools to reconcile.
Architecture
Built as one system, not five products bolted together.
Most CNAPPs stitch together acquisitions with a shared login page. OnDuty is a single pipeline — ingestion, graph, reasoning, and action — built to share one model from day one.
Agentless connectors + one eBPF binary
Cloud accounts connect through short-lived, read-only API credentials — no standing access, no IAM roles left behind. On hosts, a single static eBPF binary streams process, network, and file-system events straight from the kernel. No kernel modules, no sidecars, no code changes.
<1% CPU overhead · curl -fsSL https://get.onduty.ai | bash
Every signal resolves into one model
Posture findings, SCA and SAST results, exposed secrets, identity permissions, runtime syscalls, and AI agent commands all land as nodes and edges in the same graph — not five separate tables you have to cross-reference by hand.
posture · code · secrets · identity · runtime · AI — one schema
Noise is cut before it reaches you
Every finding is checked against what's actually true right now: is the vulnerable function loaded in memory, is the identity reachable from the internet, is the secret used by a running process. Findings that fail reachability are demoted automatically.
CVE loaded in memory ✓ · package never loaded (demoted)
Enforce, remediate, or route — your call
High-confidence detections can respond automatically — block a command at the kernel, quarantine a workload, revoke a session. Everything else routes to a ticket with the full attack path attached, or waits for one-click approval.
approval-gated · audit-logged · rollback is one command
Three signals. One incident — not three tickets.
This is what "one graph" means in practice.
What runs on it
Eight modules. One graph underneath.
Turn on the modules you need — every one of them writes into the same graph described above, so nothing you enable becomes another silo.
Secret Scanning
Find live credentials in repos, images, and hosts — validated against the issuing provider and deduplicated.
- Provider-validated — only live secrets alert
- History and layer scanning across repos and images
- Deduplicated to a single finding per credential
Domain Scans
Map your external attack surface — subdomains, TLS posture, and exposed services — from the outside in.
- Subdomain and exposed-service discovery
- TLS and certificate posture checks
- Outside-in view correlated back to owning assets
Deployment & trust
Live in minutes. In control the whole time.
Agentless onboarding
Connect cloud accounts via read-only API keys. No code changes to start seeing findings.
One binary on hosts
A single static eBPF binary — no kernel modules, no sidecars, under 1% CPU overhead.
Read-only by default
Nothing acts on your environment until you explicitly turn enforcement on.
Approval-gated actions
Automated response can require a click before anything changes in production.
Everything audit-logged
Every finding, every action, every approval — an immutable trail for your auditors.
Rollback in one command
Any remediation OnDuty makes can be undone instantly, no ticket required.
Connect a cloud account and drop in the eBPF binary — OnDuty starts building your graph immediately and delivers a first runtime signal on day one.
- Invite-only early access — no procurement hoops
- Read-only by default — you approve every action
- Rollback is a single command


