Platform Overview

The full-stack cloud security platform

EchelonGraph fuses cloud posture, live CVE & exposure intelligence, AI security and continuous compliance into a single, tenant-scoped attack graph — so you see what's wrong, what it's connected to, and what to fix first. One platform, four pillars, three delivery tiers.

724
cloud detection rules
AWS · GCP · Azure
349K+
CVEs tracked
EG Score v2.2
330
compliance frameworks
3,473 controls
8
internet-scale radars
free public feeds
35
surface-scan modules
25 free · no signup
87
asset types mapped
AWS · GCP · Azure

All figures are platform capabilities, code-verified. Live counts shown as of July 2026.

What it is

Four pillars, one graph

How it works

From the internet to your dashboard

DISCOVERY8 RadarsCT logs · Shodan · GitHubSCANNERSTier 1/2/3cloud · crawler · eBPFINGESTIONNATSauth-gated pipelineGRAPH + STORESAttack graphCVE · compliance stateINTELLIGENCEEG Score + AIrisk · remediationSURFACESTenant dashboard3D graph · findings · compliance/pulse — public CVE feedEG Score + EG Risk, free/surface-scanner — freeA+ to F, no signup

Read-only by default. The attack/blast-radius graph is Postgres-authoritative; Neo4j powers CVE product-version matching.

How you deploy it

Three tiers — agentless to zero-knowledge runtime

Tier 1 · Agentless SaaS

Read-only API posture scan of AWS/GCP/Azure + managed Kubernetes (GKE/EKS/AKS). No install, no agent. Runs all CSPM/CIEM/AI-SPM/IaC rules + the attack graph.

no agent · read-only

Tier 2 · In-network crawler

Deploy-and-destroy or enrolled agent for deep network + in-cluster Kubernetes audit (CIS/RBAC/NetworkPolicy). Runs in-house or customer-side, air-gap capable.

outbound-443 only

Tier 3 · eBPF runtime agent

Zero-knowledge eBPF runtime on the customer's own Kubernetes — TLS/egress/LSM probes, JA3/JA4 traffic analysis, statistical anomaly detection. BYOK AES-256-GCM envelopes: we store ciphertext only, kernel to dashboard.

customer-hosted · BYOK
Cloud Security

551 rules across AWS, GCP & Azure — in one graph

CSPM

490 rules

Misconfiguration + within-cloud cross-service correlation, CIS-mapped, evaluated on discovered assets.

CIEM

46 rules

IAM privilege-escalation & toxic-combination detection with effective-permission gating.

AI-SPM

15 rules

Posture for managed AI — AWS Bedrock/SageMaker, GCP Vertex, Azure ML + OpenAI.

KSPM

41 rules

Kubernetes control-plane posture across GKE / EKS / AKS.

IaC scanner

58 native + Trivy + KICS

Typed HCL2/CFN/K8s rules for depth, plus Trivy + KICS (17 formats) for breadth — one merged, offline, no-creds scan.

Attack graph

depth 40

One tenant-scoped graph with identity (RUNS_AS / CAN_ASSUME / CAN_ACCESS) + network edges, 2D and 3D — including cross-cloud CAN_ASSUME lateral-movement paths.

551 total = 490 CSPM + 46 CIEM + 15 AI-SPM (KSPM and IaC counted separately). Per cloud: AWS 303 · GCP 167 · Azure 81. Attack-path edges are effective-permission-aware — trust that's MFA/IP-gated or SCP-blocked is marked distinctly, not drawn as naive reachability.

Cyber Security · CVE intelligence

A live CVE risk engine — 349K+ CVEs, re-scored continuously

EG Score — two numbers, not one

EG Score (0–10) answers "how severe?"; EG Risk (0–100) answers "how urgently?" — a transparent fusion of severity, exploitation and automatability that separates equal-severity CVEs. Each CVE also carries an in-house CISA SSVC action (Act / Attend / Track). Algorithm v2.2, fully auditable factors.

NVD/CNA CVSSCISA KEVFIRST EPSSGHSAown exploitation modelSSVC

Continuously fresh, not static

  • 349,106 CVEs synthesized from 19 upstream feeds (NVD, MITRE, KEV, EPSS, GHSA, exploit-code, 10 vendor PSIRTs).
  • Recompute-on-change — re-scores when any signal moves; hot CVEs (KEV / ≥9.0) refresh every 4h.
  • Continuous EPSS (smooth ramp, no 0.85 cliff) + honest reject-suppression of withdrawn CVEs.
  • • Public, free at /pulse — every CVE gets a rationale you can hover.
Cyber Security · Exposure intelligence

8 internet-scale discovery radars

Always-on, read-only, passive radars that map exposure across the public internet — a free intelligence feed and the demand engine that shows a prospect their problem before we ever pitch. (Counts are internet-wide observations as of July 2026, never client data.)

Compliance

330 frameworks, live-scored against your real posture

330 / 3,473

frameworks / controls, wired into the runtime scorer — not a static list. ~86% automated from live cloud posture; the rest are honest manual-evidence requests.

7 / 100

AI-governance frameworks / controls live — EU AI Act, NIST AI-RMF, ISO 42001, MITRE ATLAS, OWASP LLM, Korea AI Basic Act, CSA AICM. Rare among CNAPPs.

28

cross-cloud evaluator primitives reused across every framework. Evidence text names the offending resource — not GRC boilerplate. Adding a framework is a data change.

AI Security

Grounded AI — answers from your data, not the internet

AI Security Analyst (RAG)

A natural-language analyst that answers only from your real data via structured retrieval across four sources — the attack graph, CVE findings, compliance scores and risk rollup (graph + SQL, not fuzzy vector search). Multi-model: Claude Opus 4.8 primary with Gemini 2.5 Flash, automatic failover, no vendor lock-in. Hard tenant isolation by construction.

AI-SPM + Shadow-AI radar

Cross-cloud posture (15 rules) over managed AI — SageMaker, Bedrock, Vertex, Azure ML/OpenAI — mapped to NIST AI-RMF / EU AI Act / ISO 42001. Paired with the public Shadow-AI radar that finds exposed AI infra across the internet.

Free front door

Surface Scanner — 35 modules, no signup

A free external scanner that runs 35 parallel security modules (25 free, results visible with no signup) against any domain and returns an A+ to F grade in 2–3 minutes — TLS, headers, DNS/email-auth, secrets, cloud buckets (11 providers), exposed paths, subdomain-takeover, tech-fingerprint→CVE and more. Grade ceilings mean an open CRITICAL can never earn an A. It's the widest free tier in the category and the top of our funnel.

For investors

The wedge, the moat, and the honest status

The wedge

We own both sides of the exposure equation — internet-scale discovery of what's exposed and the live CVE risk engine that ranks it. The KEV-Exposure radar (KEV/EPSS × Shodan banners) is a join no pure-scanner or pure-CVE vendor can make.

The moat (flywheel)

8 free public radars + a free scanner + a 349K-CVE feed = an SEO/AEO top-of-funnel that shows a prospect their exposure before we pitch. Discovery → warm, evidence-backed demand → protect. The exposure data is the demand engine.

The breadth

A single graph unifies what incumbents sell as 4+ products (CSPM, CIEM, CNAPP, GRC) across 3 clouds — plus genuinely rare AI-governance depth (7 frameworks incl. EU AI Act & Korea AI Basic Act) as AI regulation lands.

What's live vs. newer (we'd rather you hear it from us)

  • “Zero-knowledge” refers to the Tier-3 runtime agent specifically: BYOK AES-256-GCM envelope encryption (E2EE), not zero-knowledge proofs. The rest of the platform is standard read-only SaaS.
  • Runtime anomaly detection is statistical (EWMA + z-score), not machine learning.
  • Azure is a fully-wired provider (158 rules incl. CIEM + AI-SPM). As of 29 Jul 2026 it is validated against a live subscription: 19 asset types collected end-to-end, and detections confirmed firing against deliberately-misconfigured resources we provisioned for the purpose. The managed-database collectors we previously listed here as unproven — MySQL, PostgreSQL, Cosmos DB, Key Vault and Container Instances — have since been exercised against real provisioned instances and are now proven. Azure SQL remains the one collector without a live fixture, so we still do not claim it. Cross-cloud attack paths are modeled for all three clouds; the proven end-to-end chain today is AWS→GCP.
  • Two of the 724 cloud rules are currently known not to fire — AWS-ELB-011 (Classic load balancers are not enumerated) and AWS-EC2-017 (EC2 user-data secrets are reported through a separate path). Found by our own July 2026 audit and listed here rather than quietly removed from the count.
  • The EU AI Act framework has ~4 of 21 controls machine-evaluated from live cloud state; the rest run as an evidence workflow.
  • ~21% of the CVE corpus (74,806 CVEs) shows no severity. These are almost entirely pre-2016 records that NVD only ever scored under CVSS v2, which we do not yet ingest — so the data exists upstream and the gap is ours, not the record's. They are tracked and searchable, just unscored. CVSS v2 ingestion is planned; until it lands, treat a NONE on an older CVE as 'we have not scored this', not 'this is not severe'.
  • The AI Security Analyst’s streaming chat runs on Gemini 2.5 Flash for latency; Claude Opus 4.8 is the primary model on the router-backed (reasoning / remediation) paths.

See it on your own environment

Start free with a domain scan or the live CVE feed — no signup. Or talk to us about the full platform.