ArcScan sweeps your network, builds a live CMDB from agentless probes, matches every package against NVD, OSV, GHSA, RHSA, USN, DSA, Alpine, ALAS and MSRC feeds with KEV and EPSS enrichment, then generates Ansible remediation that is blast-radius analyzed and dry-run verified before a human approves the apply, with an HMAC-signed, offline-verifiable evidence bundle for your QSA, FedRAMP assessor, or 3PAO.
MSRC ships enabled-on-request; 8 feeds run out of the box.
ArcScan is a pre-revenue platform. The industries above are our design targets, not a customer list.
One platform in place of a discovery tool, a vulnerability scanner, a CMDB sync, and a remediation runner, built for regulated mid-market and federal teams.
Agentless masscan/zmap sweep, then credentialed SSH/WinRM/SNMP/SMB/IPMI probes build a typed asset graph with software, packages, and open ports. 34 built-in software patterns recognize the stacks you actually run: nginx, Postgres, Kafka, Kubernetes, AWX, Vault and 28 more.
Every discovered package is matched against nine vulnerability feeds: NVD, OSV, GHSA, RHSA, USN, DSA, Alpine, ALAS and MSRC. CISA KEV exploitation status and EPSS scoring are layered on top and pulsed onto your topology map.
Trust-tier model: deterministic, registry-checked, syntax-validated playbooks auto-apply under policy. Generated playbooks dry-run only. Every action is logged for your auditor.
Before anything executes, ArcScan walks the reverse-dependency closure of the package and maps it to the services actually running on that host. The approver sees the restart list, not a version bump. That is what makes "we will not take production down" something you can check instead of hope.
Every generated fix runs in Ansible check mode against the real host, and the diff is what the approver reads. A deterministic dangerous-operations linter runs between the dry run and the approval, so nobody signs off on an unlinted change. Each fix ships with its own rollback playbook, and a post-apply scan confirms the CVE actually cleared. Quorum approvals, maintenance windows, and policy-as-code gates all land in an HMAC-signed evidence bundle that verifies offline.
The Remediation Reliability dashboard answers the question every regulated buyer asks first: how often does your auto-fix break something. Patch success rate, MTTR mean and median split by severity with outliers called out honestly, rollback counts, the proposed-to-applied funnel, and a per-fix-class rollup with a weekly trend.
Exclude specific hosts or apps from a single run, or write a standing rule at host, package-on-host, or path-prefix granularity, each tagged vendor managed, risk accepted, or false positive so the reason survives to the audit. When a vendor forbids the upgrade, pin instead: apt hold or dnf versionlock, reported honestly as pinned rather than quietly as fixed.
Orphaned .dist-info and .egg-info directories left behind by a half-removed package make most scanners report a vulnerable version that is not installed. ArcScan records those remnants as not installed and never matches them, then generates a cleanup playbook that removes them so your other scanners stop crying wolf too.
Agent-based crypto-asset discovery finds the SSH keys, X.509 certificates, and Java keystores across your estate, grades them on an algorithm-aware severity scale, and exports a CycloneDX 1.6 CBOM. The executive readiness report tracks you against the CNSA 2.0 milestone timeline, and PQC remediation runs through the same governed pipeline. Linux agents today.
A unified asset graph with 10 edge kinds. East-west traffic observed on the hosts themselves sits alongside cloud control-plane routing pulled from NSG rules, VNet peering, and Front Door and load balancer config, each edge labeled by origin so you can always tell what actually talks from what is merely allowed to. Blast radius and attack paths run on top.
A self-extracting offline bundle ships the ArcScan CLI, Ollama, and a GGUF model with no outbound calls; the full platform air-gaps via Docker Compose. AES-256-GCM encryption mode (FIPS-approved algorithms) for FedRAMP and DoD environments. SDVOSB sole-source eligible.
21 control packs loaded: NIST 800-53, NIST 800-171, NIST CSF, FedRAMP Low and Moderate, CIS (AWS, Linux, Docker, Kubernetes), HIPAA, PCI-DSS, SOC 2, ISO 27001, FFIEC, NCUA ACET, GDPR, Saudi NCA ECC, SAMA CSF, and UAE IA, plus MITRE ATT&CK mapping and a crosswalk engine so SOC 2 evidence maps onto HIPAA and ISO without redoing the work. SSP, POA&M, and evidence export for cATO.
SARIF 2.1 into GitHub code scanning, CycloneDX 1.5 and SPDX 2.3 SBOMs, CycloneDX 1.6 CBOM, ArcSight CEF streaming for Splunk, Sentinel, QRadar and Chronicle, and streaming CSV/JSON. Hand your auditor a read-only portal and an HMAC-chained log they can verify has not been altered.
After every terraform apply, parsed tfstate upserts every compute instance it finds to ServiceNow CMDB, Jira, and FreshService. Closes the "CMDB is 60% out of date" gap regulated buyers know they have.
Three steps. No agents to deploy. Works in air-gapped networks.
Point ArcScan at a CIDR or cloud account. Agentless masscan/zmap sweep, then credentialed SSH/WinRM/SNMP probes pull packages, open ports, and software stacks.
Every package is matched against 9 live vulnerability feeds. KEV-listed and high-EPSS CVEs surface first, filtered by whether the vulnerable code is actually reachable in your environment, with blast-radius context from your asset graph.
Generate a remediation playbook, review its blast radius, watch it dry-run in check mode, then approve the apply. Or open a remediation PR or file a ServiceNow change request instead. Every action lands in an HMAC-signed evidence bundle, framework-mapped and offline-verifiable.
A complete IaC security and automation platform — not just a linter. Discover, audit, build, provision, and monitor your entire cloud estate from a single pane of glass.
Paste, upload, or zip-scan your existing Ansible, Terraform, or mixed IaC repos. Get scored findings, policy-gated remediation playbooks, and compliance mapping in the same pass.
Describe what you need in plain English and ArcScan generates security-hardened Ansible and Terraform IaC using AI. Generated code enters the review tier: dry-run verified and human-approved before it touches anything.
Connect Google Drive, OneDrive, Dropbox, GitHub, GitLab, or Bitbucket and scan playbooks directly from where your team already works.
A 14-day Trial covers evaluation. Small, Medium, and Large annual platform contracts scale by host and user capacity. SSO/SAML, ITSM and SIEM integrations, and the governed remediation loop are standard on every paid tier. All 21 compliance control packs, including Middle East (Saudi NCA ECC, SAMA CSF, UAE IA), are included from Medium up. Federal and Air-Gap are quote-only and unlock unlimited sweeps, air-gap deployment, and AES-256-GCM encryption mode.
14-day evaluation
For small teams getting to production
Mid-market production deployments
Enterprise-scale fleets
Federal civilian & defense
Fully offline / classified environments
Overages: $100/host/yr list, sold in 1,000-host blocks, and $15K/agent/yr. Multi-year commitments discount list price by 8% (2 years), 15% (3 years), or 25% (5 years). Organizations above roughly 250 users are scoped into a Federal or Air-Gap contract.
A billable host is a compute instance (VM or bare-metal server). Security groups, subnets, IAM roles, storage, and serverless functions are analyzed at no charge and never count as hosts.
Purpose-built for the compliance realities of healthcare, federal agencies, and financial services — the three verticals where IaC risk and audit pressure converge.
Healthcare IaC teams typically manage hundreds of Ansible and Terraform modules across clinical, billing, and infrastructure systems, and manual pre-deployment security review competes directly with release cadence.
Federal civilian and defense agencies running air-gapped environments need consistent NIST 800-53 and FedRAMP validation across every IaC module, without sending source code to a SaaS. CNSA 2.0 adds a second clock: agencies must know where their pre-quantum cryptography lives before they can plan the migration.
Credit unions, payment processors, and regional banks face annual PCI-DSS QSA audits where evidence collection, screenshots, policy documents, and system check exports across dozens of IaC modules, is done by hand.
Target deployment profiles. ArcScan is a pre-revenue platform actively exploring design-partner relationships in each vertical.
Infrastructure as Code has transformed how teams deploy systems — but it has also moved security risk upstream. Traditional security tooling was built for running systems, not declarative configuration files. This white paper examines how automated IaC security analysis closes that gap.
Start free with your own AI key, or book a 20-minute demo and we'll walk a sweep, a CVE match, and a governed remediation on real infrastructure.