Launching today

EchelonGraph
EchelonGraph ยท Cloud + AI Security Know what to fix today.
5 followers
EchelonGraph ยท Cloud + AI Security Know what to fix today.
5 followers
Your cloud tools find 10,000 problems. EchelonGraph tells you which 5 matter today. We connect three things that usually live in separate products: which vulnerabilities attackers are actually exploiting, which of your assets they can genuinely reach, and which compliance controls break. Plus live scoring across 330 frameworks, attack-path mapping and shadow-AI discovery. Free CVE feed and free scanner, no signup. echelongraph.io
Interactive






Free Options
Launch Team / Built With




Hey Hunters ๐
I'm Akshay. I've spent about 13 years doing security and observability for production cloud systems, and this is the tool I kept wishing existed.
Here's the moment that started it. Every audit cycle, our team spent four to six weeks collecting evidence by hand. Screenshots, exported configs, IAM listings, policy attestations. And by the time the auditor actually looked at it, half the cloud had changed underneath us. The evidence wasn't wrong when we collected it. It was wrong by the time it mattered.
Then AI workloads showed up and made it worse. Teams were shipping KServe, Kubeflow and Ray to production, and there was no tool that could even describe what was running, let alone tell you whether it met EU AI Act or NIST AI-RMF. Meanwhile every security lead I knew was being asked "are we EU AI Act ready?" with the deadline closing in fast.
So we built EchelonGraph. Two of us, nights and weekends, no funding.
What it does:
๐ฐ๏ธ Scans your cloud agentlessly, crawls your external surface, and if you want runtime visibility, runs an eBPF agent inside your own Kubernetes cluster. That agent never holds plaintext. Findings are sealed with your KMS
key, not ours.
๐ฅ Builds a live attack graph. Click any asset and see what an attacker could actually reach from there. It's a real graph in Neo4j, not a flat list of findings.
โก Re-scores compliance when your cloud changes, instead of overnight. 330 frameworks and 3,473 controls, including the AI-specific ones: NIST AI-RMF, EU AI Act, ISO 42001, MITRE ATLAS and OWASP LLM Top 10.
Three things you can poke at right now, no signup, no email gate:
โ echelongraph.io/shadow-ai-radar โ live stream of exposed AI infrastructure
โ echelongraph.io/ai-security-index โ AI services and AI CVEs, drillable
โ echelongraph.io/ai-threat-map โ globe of unauthenticated vector databases
And a free tier: 3 cloud accounts, 500 assets, no card.
Two things I'd genuinely like:
1. Try it and tell me where it breaks. I mean that literally. I want the part where the workflow annoys you, not the compliment. DMs are open.
2. For the security folks here: how often does your compliance posture actually get re-checked today? Nightly job? Only at audit time? Never? I have a suspicion about the answer and I'd like to know if I'm wrong.
Happy to go deep on eBPF, attack graphs, or EU AI Act Article 14 in the replies.
โ Akshay