CNAPP for real multi-cloud estates

The cloud security platform built for every cloud.

Redoubt unifies posture, identity, exposure, vulnerabilities, IaC risk, attack paths, remediation, and audit evidence across hyperscalers and the European clouds other platforms barely cover.

Read-only cloud connectors No forced telemetry lake Evidence on every finding Self-hosted or European-hosted
Built for the estate buyers actually run. Redoubt gives security teams one place to understand risk across every cloud they run: the major hyperscalers, the alternative clouds nobody else covers properly, and Kubernetes.
0write scopes required
1relationship-aware asset graph
100%security essentials included
Coverage

Provider-native depth, not checkbox breadth.

Each supported cloud gets discovery, relationships, posture rules, identity analysis, evidence, and remediation designed around that provider's real control plane.

OVHcloud

Control-plane discovery, posture rules, identity checks, public exposure, compliance mappings, and remediation guidance.

OpenStack

Normalized assets, relationships, network reachability, identity posture, and rule coverage for private and hosted OpenStack estates.

Scaleway

Compute, Kapsule, object storage, databases, IAM, inference endpoints, exposure analysis, and provider-specific rule packs.

Hetzner Cloud

Networks, firewalls, servers, volumes, snapshots, images, SSH keys, projects, attack paths, and reachability context.

Exoscale

Zone-aware assets, security groups, managed databases, object storage, credentials, account posture, and remediation context.

AWS

The major clouds are covered to the same evidence, prioritization, identity, graph, and remediation standard.

Azure

Azure posture and Entra identity analysis live in the same queue, graph, and compliance workflow as every other cloud.

Google Cloud

GCP assets, identities, vulnerabilities, and network exposure become part of one operational risk model.

Workflow

From read-only discovery to measurable risk reduction.

Redoubt turns cloud state into a clear operating loop for security teams: know what exists, see what matters, fix it cleanly, and prove the improvement.

Connect read-only

Least-privilege credentials enumerate cloud metadata without granting Redoubt permission to change production resources.

Build the graph

Assets and relationships normalize across clouds so security groups, identities, keys, buckets, and workloads can be reasoned about together.

Rank real risk

Findings are scored by severity, exposure, exploitability, asset criticality, vulnerability context, and whether they sit inside an attack path.

Ship the fix

Every finding carries evidence, exact remediation, control mappings, ownership, lifecycle history, and the expected posture improvement.

Platform

One platform for posture, exposure, identity, drift, remediation, and compliance.

Redoubt is designed to replace the fragmented ritual of spreadsheets, one-cloud scanners, manual graphing, and audit scramble with a single security operating view.

Attack-path analysis

Correlates reachability, weak controls, and credentials into chains an attacker could use.

Identity blast radius

Shows what a leaked credential or over-privileged principal can actually reach.

Posture drift

Tracks scan-over-scan changes so regressions and remediations do not disappear into a static score.

IaC scanning

Finds insecure infrastructure before deployment and maps code risk back to the same posture model.

Compliance reporting

Exports JSON, CSV, and PDF evidence mapped to frameworks auditors ask about.

Alert routing

Sends relevant findings through webhooks, Slack, Mattermost, email, syslog, tickets, and OCSF-shaped payloads.

Trust

Security essentials are included because security teams notice when they are not.

SSO, MFA, RBAC, audit logs, tenant isolation, encryption, and deployment control belong in the base product. Redoubt is built to earn trust before it asks for cloud access.

Auth

Passwordless and SSO-ready

Passkeys, SSO, MFA, RBAC, and no default credentials keep access control out of the upsell drawer.

Audit

Append-only activity history

Finding lifecycle, assignments, suppression, authentication, and tenant operations leave reviewable evidence.

Boundaries

Read-only and posture-first

Connectors observe and recommend. Remediation is generated for review and workflow, not silently applied to scanned clouds.

Deployment

Choose the control model your customers and regulators expect.

  • European-hosted service for teams that need residency and a managed operating model.
  • Self-hosted deployment with no SaaS dependency, phone-home, or telemetry by default.
  • Single-tenant simplicity for internal teams and strong multi-tenant isolation for MSSPs.
  • Optional AI assistance with bring-your-own model support, including local-capable deployments.
operating modelredoubt_
hosted-euManaged Redoubt on European infrastructure with residency-aligned operations.managed
self-hostedRun the full platform in your own environment, including restricted and air-gapped estates.control
mssp-readyServe many isolated tenants from one deployment without weakening customer boundaries.scale
api-firstQuery assets, relationships, findings, evidence, and compliance data from your own tools.integrate
Design partners

Running cloud infrastructure where the usual platforms fall short?

Redoubt is being shaped with teams that need serious cloud security coverage without migrating clouds, granting write access, or building another telemetry lake.