iCompaas provides a suite of tools and services to maintain the Compliance and Security posture of your cloud infrastructure. We automate services of a Cloud Security Specialist, a Compliance Analyst, and a Cloud Architect all rolled into one product.
No reviews yetBe the first to leave a review for iCompaas
HI ICompass Team,
I have been through the technical write up in the above sections and also through your website , I liked the idea of planning a single solution for Security , Compliance and also providing some architecture guidance with cost effective product to small/mid and large enterprise which are the need of hour and it is really commendable.
I would like to understand more on this product and its capabilities , below are few queries
- Is this product suitable for any kind of AWS models/architectures.. EC2 or ECS ..???
- How are the vulnerabilities tracked by your product specific to an EC2 instance .. do you need any plugin or client running on the EC2 instances to fetch this information
- What kind of permissions IAM roles does your icompass product needs for customers AWS account..??
@sathish_simhachalam We support all AWS application architectures (EC2 and ECS). The policy checks we run are on AWS infrastructure metadata. We do not run any plugin or client running on EC2.
Proud to be part of iCompaas solution thats helps fellow Ops guys to feel `secure in the cloud` #SharedResponsibility #RethinkSecurity
I want to share my Angle of an Infrastructure Operations Guy:
Having worked as an admin and in management roles for over a decade, have noticed many a times, critical challenges would often drill down to security and compliance deviations.
Over the past few years, cloud security has been the cause, leading to the need of a tool like iCompaas, which has multiple capabilities which can answer the questions:
What do we protect? - Understanding that firewalls and endpoints as our potential attack surfaces
How many resources do we have? - Consolidation of cloud asset/resource inventory and management
How many of them are patched and up to date? - Vulnerability assessment of resources
Has anything changed? - New cloud technologies that may cause security issues that were previously not considered
We rounded up an array of all annoying things that we could find in security/compliance and automated it in one place, so no one would have to solve the same problem again.
I have met several entrepreneurs, who are creating awesome products and services, but are not aligned with security and compliance right at the outset. The clomplexities in creating ad-hoc scripts and catering to increasing number of new services could be one of the factors for not focusing on security issues, that may lead to difficulties while we move to production.
We are happy to answer any questions you might have on our offerings, I Look forward to hear your feedback... Cheers !!!
Report
Does your product adapt to customized security requirements as per any specific organization standards?
@ravi_kumar_penugonda Thanks for the question. We plan to support "user" (organization) customized security requirements in the future; currently only support standard requirements like CIS Level 1 & 2 and HIPAA; Coming soon with GDPR, SOC 2, PCI DSS, NIST CSF, NIST 800-53, ISO 27001, and CSA CCM.
Hello Producthunters!
We are happy to launch our cloud infrastructure security and compliance product - iCompaas!
Our team has experience working in mid-sized and large enterprises where automating security and compliance is painstaking and really expensive. Even after the advent of cloud IAAS, most companies continue to struggle with securing their application stack due to a lack of good automation tools. And we wanted to fill that gap with our product.
We believe companies of all sizes should get the benefit of top quality security and compliance software at a low cost. This is our mission and we are launching on producthunt.com today to get your feedback.
Here are some of our product highlights:
Security - We provide cloud infrastructure security where we cover AWS Well-Architected Framework, checking if Interfaces and APIs are Insecure, validate configurations, User and Permissions Management(RBAC), Authentication events, check for Malicious Insiders and Account Hijacking attempts.
Compliance - Real-time monitoring of compliance changes with resource-level details, along with report generation. We offer compliance solutions such as CIS Level 1 & 2 and HIPAA; Coming soon with GDPR, PCI DSS, NIST CSF, NIST 800-53, SOC 2, ISO 27001, and CSA CCM.
Cost Optimization - We monitor usage patterns and provide a breakdown of cost using various dimensions like services, type of operation, and regions. Our tool will find unused and hidden resources that can be decommissioned to potentially save Capex and Opex costs. We also offer cost forecasting and reduction recommendations, and also recommendations based on usage(CPU, Memory, Storage).
Looking forward to engaging with the community; our team of makers is available all day (and night) to answer any of your questions.
Cheers!
JP
@sudarshan_suda Its wonderful to know that you like the iCompaas website.
We are getting requests from small teams to have a "Free For Life" Tier so that they have an understanding of where they stand in terms of security and compliance posture. Its already in the pipeline and we will announce within a couple of weeks, please stay tuned !!!
For now, you can also "Enjoy our 30-Day Free Trial! Cancel anytime". We are certain you would see value in the product.
Report
Will this support lambda function in aws when we are configuring the service using multiple accounts.
@arunkumar_natarajan; If I understand your question correctly, you want to know if we check your lambda function to see if they are vulnerable?
We are adding endpoint scanning as part of our arsenal, if lambda is exposed via API Gateway or Application Load Balancer (ALB can trigger a lambda function now!), we can scan the endpoint and generate vulnerability results - coming soon!
If they are event-driven lambda, we would only scan the network configuration of the lambda, not the lambda function itself. As we access your cloud account metadata, we also check security group configuration so that would be included.
Report
Simple and clear minimalist website, I like the information that the dashboards are providing, will Login and share more feedback
iCompaas
iCompaas
iCompaas
iCompaas
iCompaas
iCompaas
iCompaas
iCompaas