SDVOSB · Air-gap ready · AES-256-GCM encryption mode

Find every CVE in your estate. Fix it with proof, not guesswork.

ArcScan sweeps your network, builds a live CMDB from agentless probes, matches every package against NVD, OSV, GHSA, RHSA, USN, DSA, Alpine, ALAS and MSRC feeds with KEV and EPSS enrichment, then generates Ansible remediation that is blast-radius analyzed and dry-run verified before a human approves the apply, with an HMAC-signed, offline-verifiable evidence bundle for your QSA, FedRAMP assessor, or 3PAO.

0
Compliance control packs
0
Live CVE feeds
Air-gap
Self-host ready
SDVOSB
Federal-eligible

MSRC ships enabled-on-request; 8 feeds run out of the box.

arcscan — discover 10.0.0.0/16
Illustrative output
Find Risks
Prioritize What Matters
Remediate Automatically
Stay Secure
Designed for the compliance realities of these industries

ArcScan is a pre-revenue platform. The industries above are our design targets, not a customer list.

NIST 800-53 Rev 5 baseline
CIS AWS · Linux · Docker · Kubernetes
HIPAA Security Rule safeguards
PCI-DSS v4.0 mapping · v3.2.1 scanner catalog
SOC 2 evidence generation (not SOC 2 certified)
FedRAMP Low + Moderate

A CMDB, a vuln scanner, and a remediation engine — in one platform

One platform in place of a discovery tool, a vulnerability scanner, a CMDB sync, and a remediation runner, built for regulated mid-market and federal teams.

Arc Discover: network sweep to CMDB

Agentless masscan/zmap sweep, then credentialed SSH/WinRM/SNMP/SMB/IPMI probes build a typed asset graph with software, packages, and open ports. 34 built-in software patterns recognize the stacks you actually run: nginx, Postgres, Kafka, Kubernetes, AWX, Vault and 28 more.

Live CVE matching, every asset

Every discovered package is matched against nine vulnerability feeds: NVD, OSV, GHSA, RHSA, USN, DSA, Alpine, ALAS and MSRC. CISA KEV exploitation status and EPSS scoring are layered on top and pulsed onto your topology map.

Governed remediation, verified before apply

Trust-tier model: deterministic, registry-checked, syntax-validated playbooks auto-apply under policy. Generated playbooks dry-run only. Every action is logged for your auditor.

Know what a patch restarts, before it runs

Before anything executes, ArcScan walks the reverse-dependency closure of the package and maps it to the services actually running on that host. The approver sees the restart list, not a version bump. That is what makes "we will not take production down" something you can check instead of hope.

Dry run first, approve second, undo included

Every generated fix runs in Ansible check mode against the real host, and the diff is what the approver reads. A deterministic dangerous-operations linter runs between the dry run and the approval, so nobody signs off on an unlinted change. Each fix ships with its own rollback playbook, and a post-apply scan confirms the CVE actually cleared. Quorum approvals, maintenance windows, and policy-as-code gates all land in an HMAC-signed evidence bundle that verifies offline.

Prove your automation works

The Remediation Reliability dashboard answers the question every regulated buyer asks first: how often does your auto-fix break something. Patch success rate, MTTR mean and median split by severity with outliers called out honestly, rollback counts, the proposed-to-applied funnel, and a per-fix-class rollup with a weekly trend.

The boxes you are not allowed to patch

Exclude specific hosts or apps from a single run, or write a standing rule at host, package-on-host, or path-prefix granularity, each tagged vendor managed, risk accepted, or false positive so the reason survives to the audit. When a vendor forbids the upgrade, pin instead: apt hold or dnf versionlock, reported honestly as pinned rather than quietly as fixed.

Fewer false positives than the scanner you have

Orphaned .dist-info and .egg-info directories left behind by a half-removed package make most scanners report a vulnerable version that is not installed. ArcScan records those remnants as not installed and never matches them, then generates a cleanup playbook that removes them so your other scanners stop crying wolf too.

Quantum Arc: post-quantum readiness

Agent-based crypto-asset discovery finds the SSH keys, X.509 certificates, and Java keystores across your estate, grades them on an algorithm-aware severity scale, and exports a CycloneDX 1.6 CBOM. The executive readiness report tracks you against the CNSA 2.0 milestone timeline, and PQC remediation runs through the same governed pipeline. Linux agents today.

Topology that tells you what it saw

A unified asset graph with 10 edge kinds. East-west traffic observed on the hosts themselves sits alongside cloud control-plane routing pulled from NSG rules, VNet peering, and Front Door and load balancer config, each edge labeled by origin so you can always tell what actually talks from what is merely allowed to. Blast radius and attack paths run on top.

Air-gap and federal, day one

A self-extracting offline bundle ships the ArcScan CLI, Ollama, and a GGUF model with no outbound calls; the full platform air-gaps via Docker Compose. AES-256-GCM encryption mode (FIPS-approved algorithms) for FedRAMP and DoD environments. SDVOSB sole-source eligible.

Continuous ATO and compliance evidence

21 control packs loaded: NIST 800-53, NIST 800-171, NIST CSF, FedRAMP Low and Moderate, CIS (AWS, Linux, Docker, Kubernetes), HIPAA, PCI-DSS, SOC 2, ISO 27001, FFIEC, NCUA ACET, GDPR, Saudi NCA ECC, SAMA CSF, and UAE IA, plus MITRE ATT&CK mapping and a crosswalk engine so SOC 2 evidence maps onto HIPAA and ISO without redoing the work. SSP, POA&M, and evidence export for cATO.

Exports your existing pipeline already reads

SARIF 2.1 into GitHub code scanning, CycloneDX 1.5 and SPDX 2.3 SBOMs, CycloneDX 1.6 CBOM, ArcSight CEF streaming for Splunk, Sentinel, QRadar and Chronicle, and streaming CSV/JSON. Hand your auditor a read-only portal and an HMAC-chained log they can verify has not been altered.

Terraform-to-CMDB sync

After every terraform apply, parsed tfstate upserts every compute instance it finds to ServiceNow CMDB, Jira, and FreshService. Closes the "CMDB is 60% out of date" gap regulated buyers know they have.

From unknown estate to a ranked, remediation-ready backlog in one sitting

Three steps. No agents to deploy. Works in air-gapped networks.

1

Sweep & probe

Point ArcScan at a CIDR or cloud account. Agentless masscan/zmap sweep, then credentialed SSH/WinRM/SNMP probes pull packages, open ports, and software stacks.

2

Match & rank

Every package is matched against 9 live vulnerability feeds. KEV-listed and high-EPSS CVEs surface first, filtered by whether the vulnerable code is actually reachable in your environment, with blast-radius context from your asset graph.

3

Remediate & prove

Generate a remediation playbook, review its blast radius, watch it dry-run in check mode, then approve the apply. Or open a remediation PR or file a ServiceNow change request instead. Every action lands in an HMAC-signed evidence bundle, framework-mapped and offline-verifiable.

Manage infrastructure from discovery to operations

A complete IaC security and automation platform — not just a linter. Discover, audit, build, provision, and monitor your entire cloud estate from a single pane of glass.

Discover
Connect AWS or Azure and pull live infrastructure inventory (GCP in preview)
Cloud Inventory
Scan
Run CIS-benchmark posture checks and AI security analysis on configs
Posture Scanner
Build
Generate Terraform HCL from inventory or from a plain-text description
Terraform Generator
Provision
Generate and audit Ansible & Terraform IaC to configure and harden systems
IaC Engine
Operate
Create ServiceNow tickets, Slack alerts, and remediation PRs automatically
ServiceNow · SCM · Slack
Monitor
Scheduled scans, drift baselines, regression alerts, and compliance tracking
Analytics · Baselines
Or start from existing automation

Scan existing IaC

Paste, upload, or zip-scan your existing Ansible, Terraform, or mixed IaC repos. Get scored findings, policy-gated remediation playbooks, and compliance mapping in the same pass.

Generate from scratch

Describe what you need in plain English and ArcScan generates security-hardened Ansible and Terraform IaC using AI. Generated code enters the review tier: dry-run verified and human-approved before it touches anything.

Import from storage

Connect Google Drive, OneDrive, Dropbox, GitHub, GitLab, or Bitbucket and scan playbooks directly from where your team already works.

Frequently asked questions

What is ArcScan?
ArcScan is an AI-powered IaC security and automation platform. It analyzes Ansible, Terraform, and cloud infrastructure for misconfigurations, generates hardened remediation code, maps findings to compliance frameworks (NIST, CIS, HIPAA, PCI-DSS, SOC2), and manages the full infrastructure lifecycle from discovery to operations. Built by Arcus Forge LLC, a Service-Disabled Veteran-Owned Small Business (SDVOSB).
What cloud providers are supported?
ArcScan supports AWS and Microsoft Azure for live inventory, CIS-aligned posture scanning, drift detection, and Ansible/Terraform remediation generation. Google Cloud connection and inventory are available in preview: you can connect a project and pull resources, but GCP posture coverage is not yet at parity with AWS and Azure. You can connect multiple accounts per provider from the Cloud dashboard.
What AI providers can I use?
ArcScan works with Anthropic Claude, OpenAI, Google Gemini, DeepSeek, NVIDIA, Azure OpenAI, Azure AI Foundry (Enterprise), a custom OpenAI-compatible endpoint, or a fully local Ollama model for air-gapped installs. Bring your own API key from Settings, or let enterprise admins configure managed platform keys. The platform default is Azure OpenAI; air-gapped deployments default to local Ollama inference with no outbound calls.
What does the Cloud Security Posture scanner check?
The posture scanner runs 21 deterministic (no AI required) checks aligned with CIS benchmarks: 10 for AWS, 6 for GCP (preview), and 4 for Azure, with more Azure coverage in progress. It checks for: open security groups and firewalls, publicly accessible databases, unencrypted storage, overly permissive IAM policies, missing tags/labels, stale IAM users, public IPs on compute instances, and more. Each finding includes a severity rating, CIS reference, remediation steps, and an IaC remediation hint for Ansible and Terraform.
How does the full infrastructure lifecycle work?
ArcScan covers six stages: Discover (pull cloud inventory from AWS and Azure; GCP in preview), Scan (posture checks + AI analysis), Build (generate Terraform HCL), Provision (generate and audit Ansible & Terraform IaC), Operate (ServiceNow tickets, Slack alerts, GitHub/GitLab remediation PRs), and Monitor (scheduled scans, drift baselines, regression detection). You can start from existing IaC, cloud inventory, or generate everything from a plain-English description.
Is my data safe? Are playbooks or credentials stored?
Cloud credentials are encrypted at rest with Fernet (AES-128-CBC + HMAC) and only decrypted at scan time. With FIPS mode enabled, credentials use AES-256-GCM. Encryption is mandatory: there is no plaintext or base64 fallback path. API keys are stored per-user and never shared. Playbook content is stored for your report history but never sent to third parties, only to the AI provider you choose, using your API key. If your organization has not configured a key, requests route to ArcScan's managed Azure OpenAI endpoint instead. Air-gapped deployments use a local Ollama model and make no outbound calls at all. Enterprise customers can self-host with Docker for full data sovereignty.
Can I integrate with CI/CD pipelines?
Yes. ArcScan provides a REST API with webhook tokens for CI/CD integration. It also includes a Workflow Builder that generates ready-to-use pipeline configs for GitHub Actions, GitLab CI, Jenkins, Azure DevOps, and Ansible AWX/Tower — with configurable quality gate scores so builds fail if IaC doesn't meet your security threshold.
What integrations are available?
Cloud: AWS and Azure inventory and posture scanning; GCP inventory in preview.
Storage: Google Drive, OneDrive, Dropbox, GitHub, GitLab, Bitbucket.
SCM: Post findings to GitHub PRs, GitLab MRs, Bitbucket PRs; create remediation PRs; inbound webhooks from GitHub, GitLab, Bitbucket, and Azure DevOps.
Automation: AWX/AAP project imports, HashiCorp Vault secret scanning.
ITSM: ServiceNow change-request gating of automation, CMDB CI and dependency sync, plus Jira and FreshService ticket and asset sync.
Exports: SARIF 2.1, CycloneDX 1.5 and SPDX 2.3 SBOM, CycloneDX 1.6 CBOM, ArcSight CEF streaming, CSV/JSON, and HMAC-signed evidence bundles that verify offline.
Notifications: Slack, Microsoft Teams, and Discord webhooks.
Auth: SAML 2.0 and OAuth SSO (Google, GitHub, Microsoft, GitLab); SCIM 2.0 user provisioning; TOTP and WebAuthn/security-key 2FA; email OTP fallback.
Is ArcScan suitable for government and defense?
Yes. Arcus Forge LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB), eligible for sole-source and set-aside federal contracts. ArcScan supports air-gapped deployment via Docker, FedRAMP Low and Moderate control mapping with SSP and POA&M export, and NIST 800-53 Rev 5 / NIST 800-171 Rev 2 reporting. It runs entirely self-hosted with no external API calls in air-gapped mode.
How much does it cost?
Trial ($0, 14 days): 50 hosts, 3 users, 0 agents. Full platform access except deployed agents, and it converts to read-only when the 14 days are up. No credit card required.
Small ($95K/yr): 1,000 hosts, 15 users, 0 agents. Includes SSO/SAML, ITSM and SIEM integrations. Excludes Quantum Arc and Arc Probe agents.
Medium ($275K/yr): 5,000 hosts, 40 users, 1 agent. All 21 compliance control packs (including Middle East: Saudi NCA ECC, SAMA CSF, UAE IA), all AI providers, cloud and Terraform analysis, scheduled scans, CI/CD, baselines, and PDF exports.
Large ($525K/yr): 25,000 hosts, 150 users, 5 agents. Everything in Medium plus self-hosted deployment, white-label branding, a dedicated CSM, 24x7 support with a 15-minute P1 SLA, and one custom policy pack.
Federal & Air-Gap (quote only): Unlimited hosts, users, and agents. Air-gapped deployment, AES-256-GCM encryption mode, NIST 800-53 and FedRAMP reporting, SDVOSB sole-source eligibility.
Overages: $100/host/yr list (sold in 1,000-host blocks) and $15K/agent/yr. AI provider costs are separate, billed by your provider at their published rates and typically cents per scan.
Multi-year commitments discount list price by 8% (2 years), 15% (3 years), or 25% (5 years).
A billable host is a compute instance — a VM or bare-metal server enrolled in scanning. Cloud resources such as security groups, subnets, IAM roles, storage, and serverless functions are analyzed at no charge and never count as hosts.
Can I try the platform before buying?
Yes. Every new account can activate a 14-day Trial from the Billing page. No credit card is required. The Trial includes 50 hosts and 3 users with full access to cloud scanning, Terraform generation, scheduled scans, and the storage, SCM, ITSM, SIEM and notification integrations. Deployed agents (Arc Probe, Quantum Arc) are not included, and the trial converts to read-only after 14 days.

Trial to start. Annual platform contracts for regulated teams.

A 14-day Trial covers evaluation. Small, Medium, and Large annual platform contracts scale by host and user capacity. SSO/SAML, ITSM and SIEM integrations, and the governed remediation loop are standard on every paid tier. All 21 compliance control packs, including Middle East (Saudi NCA ECC, SAMA CSF, UAE IA), are included from Medium up. Federal and Air-Gap are quote-only and unlock unlimited sweeps, air-gap deployment, and AES-256-GCM encryption mode.

Trial

14-day evaluation

$0 / 14 days
  • 50 hosts
  • 3 users
  • AI security analysis
  • Bring your own API key
  • Converts to read-only after 14 days
  • Agents
  • Production SLA
Start free trial

Small

For small teams getting to production

$95K / year
  • 1,000 hosts
  • 15 users
  • Cloud & Terraform analysis
  • Governed remediation & reliability metrics
  • SSO / SAML, ITSM & SIEM integrations
  • Baseline & PDF export
  • Quantum Arc
  • Arc Probe agents
Contact sales

Large

Enterprise-scale fleets

$525K / year
  • 25,000 hosts
  • 150 users
  • 5 Arc Probe agents included
  • SOC 2, NIST 800-53, NIST 800-171, PCI-DSS, HIPAA
  • Self-hosted deployment option
  • White-label, dedicated CSM & 15-min P1 SLA
Contact sales

Federal

Federal civilian & defense

Quote
  • Unlimited hosts, users, agents
  • NIST 800-53 Rev 5 & NIST 800-171 Rev 2
  • AES-256-GCM encryption mode
  • SDVOSB sole-source eligible
  • GSA Schedule eligible
Contact sales

Air-Gap

Fully offline / classified environments

Quote
  • Unlimited hosts, users, agents
  • Air-gapped Docker deployment
  • No external API calls
  • Local model inference supported
  • Offline evidence-bundle verification
Contact sales

Overages: $100/host/yr list, sold in 1,000-host blocks, and $15K/agent/yr. Multi-year commitments discount list price by 8% (2 years), 15% (3 years), or 25% (5 years). Organizations above roughly 250 users are scoped into a Federal or Air-Gap contract.
A billable host is a compute instance (VM or bare-metal server). Security groups, subnets, IAM roles, storage, and serverless functions are analyzed at no charge and never count as hosts.

Built for federal contracts

ArcusForge LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) eligible for sole-source and set-aside federal contracts. ArcScan supports air-gapped deployment, FedRAMP Low and Moderate control mapping, and NIST 800-53 / 800-171 compliance reporting with SSP and POA&M export.

SDVOSB, federal set-aside eligible
Air-gap ready
GSA Schedule eligible
SSP & POA&M export

Built for regulated industries

Purpose-built for the compliance realities of healthcare, federal agencies, and financial services — the three verticals where IaC risk and audit pressure converge.

Healthcare
HIPAA-governed IaC
HIPAA-ready by default
Target outcome for healthcare DevOps teams

Healthcare IaC teams typically manage hundreds of Ansible and Terraform modules across clinical, billing, and infrastructure systems, and manual pre-deployment security review competes directly with release cadence.

How ArcScan fits
  • Automated HIPAA Technical Safeguard mapping
  • Per-sprint audit-ready compliance export
  • ServiceNow change-request gating of automation
  • Arc Redactor for PII/PHI sanitization, 20 detection categories
HIPAA Evidence export ServiceNow
Federal government
Air-gap + ATO workflows
ATO-ready
NIST 800-53 + FedRAMP automation

Federal civilian and defense agencies running air-gapped environments need consistent NIST 800-53 and FedRAMP validation across every IaC module, without sending source code to a SaaS. CNSA 2.0 adds a second clock: agencies must know where their pre-quantum cryptography lives before they can plan the migration.

How ArcScan fits
  • Air-gapped Docker deployment, fully offline
  • Automated NIST 800-53 Rev 5 & FedRAMP Low/Moderate reporting with SSP and POA&M export
  • Quantum Arc PQC discovery, CBOM export, and CNSA 2.0 readiness reporting (Linux agents)
  • SDVOSB sole-source & set-aside eligibility
NIST 800-53 FedRAMP Air-gapped deployment
Financial services
PCI-DSS & SOC2 evidence
Audit-ready
PCI-DSS 4.0 continuous evidence

Credit unions, payment processors, and regional banks face annual PCI-DSS QSA audits where evidence collection, screenshots, policy documents, and system check exports across dozens of IaC modules, is done by hand.

How ArcScan fits
  • PCI-DSS 4.0 control mapping per module
  • Automated QSA evidence packs, HMAC-signed and verifiable offline
  • Read-only external auditor portal over a tamper-evident log
  • Crosswalk engine: satisfy SOC 2 once, map it onto PCI, HIPAA and ISO 27001
PCI-DSS 4.0 SOC 2 Type II NCUA-aligned

Target deployment profiles. ArcScan is a pre-revenue platform actively exploring design-partner relationships in each vertical.

Shifting security left in IaC: a practical guide

Infrastructure as Code has transformed how teams deploy systems — but it has also moved security risk upstream. Traditional security tooling was built for running systems, not declarative configuration files. This white paper examines how automated IaC security analysis closes that gap.

The IaC security gap
Why CSPM and SAST coverage models leave a structural blind spot in the IaC layer
Framework mapping at scale
How to automatically map playbook tasks to NIST 800-53, CIS, HIPAA, PCI-DSS, and SOC2 controls
CI/CD integration patterns
Practical patterns for integrating IaC security gates into GitHub Actions, GitLab CI, and Jenkins pipelines
Remediation playbooks
Ansible and Terraform remediation snippets for the most common IaC security findings, ready to copy into your codebase
ROI and risk-reduction metrics
Industry data on the cost of a misconfigured deployment and how shift-left tooling reduces mean-time-to-remediation
Download white paper (PDF)
Free download — no email required.
ArcusForge LLC · Technical white paper
Shifting security left in Infrastructure as Code
A practitioner's guide to automated IaC security analysis
Coverage
Ansible Terraform
Frameworks NIST · CIS · HIPAA · PCI-DSS · SOC2
Pages 7 pages
Audience DevSecOps · Security Architects · CTOs
Table of contents
  1. The state of IaC security in 2026
  2. Understanding the misconfiguration attack surface
  3. Automated detection: how security rules work
  4. Mapping IaC to compliance frameworks
  5. Integrating security gates into CI/CD
  6. ITSM workflows for IaC findings
  7. Measuring and reporting security posture
  8. Remediation reference library

Run your first network sweep this afternoon

Start free with your own AI key, or book a 20-minute demo and we'll walk a sweep, a CVE match, and a governed remediation on real infrastructure.

14-day free Trial Air-gap self-host AES-256-GCM encryption mode SDVOSB — federal-eligible