Continuous scanning across AWS, GCP, and Azure. Findings mapped to SOC2, HIPAA, PCI-DSS, GDPR, and more. Auto-remediation generates fix PRs with confidence scores.
The problem
Compliance is a moving target. Each framework has hundreds of controls, findings pile up faster than your team can triage them, and auditors need evidence you cannot easily produce. Manual remediation is slow and often introduces new issues.
The solution
Multi-framework scanning
Scans cloud accounts against 12+ compliance frameworks including SOC2, HIPAA, PCI-DSS, GDPR, NIST 800-53, FedRAMP, CIS Benchmarks, and AWS/GCP/Azure best practices.
AI-powered auto-remediation
Select a finding, and Genie generates a Terraform fix PR with confidence scoring. Batch remediation handles multiple findings in one operation.
Finding lifecycle management
Full lifecycle tracking: detect, triage, fix, verify on next scan. Supports acknowledged and accepted-risk states for exceptions that auditors accept.
Audit evidence & reporting
Compliance scoring per framework with exportable evidence. SOC2 evidence collection on Enterprise tier for direct auditor handoff.
Real Prompts
Real examples you can type today. Every response is backed by actual actions.
“Show me critical findings across all accounts”
Found 4 critical findings across 2 accounts: S3 bucket 'acme-uploads' has public access, RDS instance 'prod-db' is unencrypted, IAM root account has no MFA, and CloudTrail logging is disabled in us-west-2.
“Fix the S3 public access finding”
PR #53 created — adds block_public_access configuration to the acme-uploads bucket. Confidence: 97%. Will auto-verify on next scan.
Change adds aws_s3_bucket_public_access_block resource with block_public_acls, block_public_policy, ignore_public_acls, and restrict_public_buckets all set to true.
“Show me compliance status for SOC2”
SOC2 score: 78% (156/200 controls passing). Critical gaps: 3 controls in CC6 (Logical Access), 2 in CC7 (System Operations). Biggest quick win: enabling MFA on 4 IAM users would pass 6 controls.
“Fix all high severity findings for the production VPC”
Found 5 high-severity findings for vpc-prod. Generating batch remediation... PR #61 created with 5 changes: security group tightening (2), flow log enabling (1), NACLs update (1), and default SG cleanup (1). Overall confidence: 91%.
No credit card required. Connect your first cloud account in 5 minutes.