Analysis & detection
What is Cloud Posture (CSPM)?
Continuously auditing live cloud accounts for misconfiguration and policy drift.
CSPM connects to your cloud provider's APIs and evaluates what is actually deployed, not what your Terraform says should be deployed. It catches drift, console changes and resources created outside your IaC pipeline entirely.
It overlaps with IaC scanning but answers a different question. IaC scanning asks 'is this template safe to apply'; CSPM asks 'is what is running right now safe'. Tools in this directory that offer it usually do so as a lighter-weight feature than a dedicated cloud security platform.
Top 4 Cloud Posture (CSPM) tools
Every tool in the directory documented as supporting Cloud Posture (CSPM), 3 fully, 1 partially, with what its own documentation says.
Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
- 1
16+ providers; IAM, buckets, security groups, DNS, VPC, encryption, continuous monitoring
- 2CodeAnt AIPR Review
Multi-cloud CSPM for AWS, GCP, Azure, Alibaba with misconfigurations mapped to attack paths
- 3
Cloud scans of live AWS, Azure, Google Cloud resource configurations; Enterprise plan only.
- 4
Veracode Risk Manager aggregates cloud infrastructure and security-tool findings; no native CSPM scanner documented
What to look for
- Which cloud providers and services are covered
- Whether it detects drift from your declared infrastructure
- Scan frequency, and whether findings tie back to the owning team
- Depth compared to a dedicated CSPM product, if that is your main need
Related terms
FAQ
What is Cloud Posture (CSPM)?
Continuously auditing live cloud accounts for misconfiguration and policy drift.
How many tools support Cloud Posture (CSPM)?
4 of the 20 tools tracked in this directory support Cloud Posture (CSPM), 3 fully and 1 partially, including Aikido, CodeAnt AI, Snyk, Veracode. Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
What should you look for in Cloud Posture (CSPM)?
Which cloud providers and services are covered. Whether it detects drift from your declared infrastructure. Scan frequency, and whether findings tie back to the owning team. Depth compared to a dedicated CSPM product, if that is your main need.