The platform

One sensor. One graph.
Every surface.

A single eBPF binary and a handful of agentless connectors feed cloud posture, code, secrets, identity, runtime, and AI agent activity into one live graph — so there's one place to look, not five tools to reconcile.

Architecture

Built as one system, not five products bolted together.

Most CNAPPs stitch together acquisitions with a shared login page. OnDuty is a single pipeline — ingestion, graph, reasoning, and action — built to share one model from day one.

Layer 01Ingestion

Agentless connectors + one eBPF binary

Cloud accounts connect through short-lived, read-only API credentials — no standing access, no IAM roles left behind. On hosts, a single static eBPF binary streams process, network, and file-system events straight from the kernel. No kernel modules, no sidecars, no code changes.

<1% CPU overhead · curl -fsSL https://get.onduty.ai | bash

Layer 02Graph engine

Every signal resolves into one model

Posture findings, SCA and SAST results, exposed secrets, identity permissions, runtime syscalls, and AI agent commands all land as nodes and edges in the same graph — not five separate tables you have to cross-reference by hand.

posture · code · secrets · identity · runtime · AI — one schema

Layer 03Reachability

Noise is cut before it reaches you

Every finding is checked against what's actually true right now: is the vulnerable function loaded in memory, is the identity reachable from the internet, is the secret used by a running process. Findings that fail reachability are demoted automatically.

CVE loaded in memory ✓ · package never loaded (demoted)

Layer 04Action

Enforce, remediate, or route — your call

High-confidence detections can respond automatically — block a command at the kernel, quarantine a workload, revoke a session. Everything else routes to a ticket with the full attack path attached, or waits for one-click approval.

approval-gated · audit-logged · rollback is one command

Three signals. One incident — not three tickets.

This is what "one graph" means in practice.

Secret in repocheckout-api · AWS key
CVE in containersame key, image built from that repo
Syscall on hostkey used by a live process, right now
INC-4211 · one findingsev=critical · action: rotate key + patch image

What runs on it

Eight modules. One graph underneath.

Turn on the modules you need — every one of them writes into the same graph described above, so nothing you enable becomes another silo.

Code

Secret Scanning

Find live credentials in repos, images, and hosts — validated against the issuing provider and deduplicated.

  • Provider-validated — only live secrets alert
  • History and layer scanning across repos and images
  • Deduplicated to a single finding per credential
Surface

Domain Scans

Map your external attack surface — subdomains, TLS posture, and exposed services — from the outside in.

  • Subdomain and exposed-service discovery
  • TLS and certificate posture checks
  • Outside-in view correlated back to owning assets

Deployment & trust

Live in minutes. In control the whole time.

Agentless onboarding

Connect cloud accounts via read-only API keys. No code changes to start seeing findings.

One binary on hosts

A single static eBPF binary — no kernel modules, no sidecars, under 1% CPU overhead.

Read-only by default

Nothing acts on your environment until you explicitly turn enforcement on.

Approval-gated actions

Automated response can require a click before anything changes in production.

Everything audit-logged

Every finding, every action, every approval — an immutable trail for your auditors.

Rollback in one command

Any remediation OnDuty makes can be undone instantly, no ticket required.

Maps your environment to compliance frameworks:SOC 2ISO 27001HIPAAPCI DSS

Ready to see it live?

See your graph
in 5 minutes.

Connect a cloud account and drop in the eBPF binary — OnDuty starts building your graph immediately and delivers a first runtime signal on day one.

  • Invite-only early access — no procurement hoops
  • Read-only by default — you approve every action
  • Rollback is a single command