Agentless Cloud CVE Scanning That Catches What's Still Running

Enterprise cloud environments fail in two ways: assets nobody knows about, and known vulnerabilities nobody prioritized. ArcScan is a cloud security SaaS that closes both gaps: agentless discovery builds a live inventory of your AWS and Azure estate, and continuous vulnerability management tells you which exposures actually matter and drives the fix through a governed pipeline.

See every cloud asset first

Connect an AWS account or Azure subscription. Credentials are encrypted at rest and only decrypted at scan time. ArcScan pulls your live inventory, covering more than 40 AWS resource types and 30 Azure security policies, into a typed asset graph. The resource topology view maps real relationships across 10 edge kinds: which role can reach which bucket, which load balancer fronts which instance. Crucially, east-west traffic observed on the hosts themselves is labeled separately from cloud control-plane routing read out of NSG rules, VNet peering, and Front Door configuration, so you can tell what actually talks to what from what is merely permitted to.

Network sweeps extend discovery to hosts, open ports, and service banners; a credentialed agentless probe over SSH, WinRM, SNMP, SMB, or IPMI adds the installed-package inventory that CVE matching runs against. AWS SSM inventory, syft-generated SBOMs, ECR container image scanning, and Terraform state ingestion feed the same graph. For segmented or air-gapped networks the optional Arc Probe agent (cosign-signed, mTLS, outbound only) reaches what agentless cannot. The vulnerability program starts from an inventory instead of a guess.

Vulnerability management with real prioritization

Every discovered package is matched against nine live advisory feeds: NVD, OSV, GHSA, RHSA, USN, DSA, Alpine, ALAS, and MSRC for Windows. CISA KEV status and EPSS scores are layered on top as enrichment, surfacing the CVEs attackers are actually using, and reachability analysis asks whether the vulnerable code is exposed in your environment at all. Blast-radius and attack-path context from your asset graph show what an exploited host can reach. Instead of a 4,000-row CSV of CVSS scores, your enterprise security team gets a ranked queue: exploited, reachable, and yours. Delta alerting tells you when a CVE you already carry flips to known-exploited overnight.

Two things keep that queue honest. Version matching is distro-scoped, so a Debian backport is not reported as an unpatched upstream release. And orphaned .dist-info and .egg-info directories left behind by a half-removed package are recorded as not installed and never matched, with a cleanup playbook available to delete them so your other scanners stop flagging them too.

Posture scanning aligned to CIS benchmarks

Deterministic policy checks run against your cloud inventory with no AI call required: open security groups and firewalls, publicly accessible databases, unencrypted storage, over-permissive IAM, stale users, and public IPs. Each finding includes severity, its CIS reference, and concrete remediation guidance. AWS identity and entitlement analysis (CIEM) runs over the collected IAM graph; Azure RBAC CIEM is not yet available. Data-store discovery classifies where sensitive data lives, with content sampling on AWS S3 today and exposure-only inventory elsewhere, marked as such rather than passed as clean. Drift detection against baselines and scheduled recurring scans keep posture continuous rather than point-in-time.

Fix it, prove it, integrate it

Enterprise SaaS, federal-ready

ArcScan runs as a multi-tenant SaaS with four organization roles and five functional roles, object-level permission checks, SCIM 2.0 provisioning, SAML and OAuth SSO, TOTP and WebAuthn 2FA, and a tamper-evident hash-chained audit log with anomaly detection. MSPs and partners get a client console with org switching, SLA and MTTR rollups, branded QBR PDFs, and white-label reports. For regulated and defense environments it also ships as an air-gapped Linux bundle with a local AI model and a FIPS-approved AES-256-GCM encryption mode, built by an SDVOSB, eligible for federal set-aside contracts.

Connect your cloud free →