v0.5 · network + identity · WA design · AWS + GCP live

Solon runs in your cloud,
not in ours.

Your cloud's access posture, who and what can reach what, audited, recommended, and designed by an agent that runs in your own account. Every recommendation cites its evidence, so your team and your auditors can trust it.

0
copies of your config on our side
OIDC
only, no long-lived keys
100%
recommendations cite their evidence
Reversible
every change ships with a back-out

Reads native cloud state · runs inside your account

AWSGoogle CloudAnthropic ClaudeBedrockTerraformOIDC
What Solon does

Six things, read at your altitude.

Ask your cloud anything.

ask

Plain-language questions, straight answers, every claim backed by what Solon actually saw.

Business

Get a yes-or-no answer in a minute instead of an afternoon of console spelunking.

Check yourself before the auditor does.

audit

Measure your setup against the security rulebooks (CIS, PCI, NIST) and see exactly where you stand.

Business

Walk into the audit already knowing the result.

See what a breach could reach.

path-analysis

Trace what an exposed resource or a compromised principal can actually reach across your cloud.

Business

Know the blast radius before an attacker maps it for you.

Get the exact fix, not a vague warning.

recommend

Describe what you need; Solon returns the precise, minimal change to get there.

Business

Changes ship faster and break less.

A change plan with the undo already written.

change-package

A reviewable, reversible package: the steps, the checks, and the rollback for each one.

Business

Make changes without the 2 a.m. rollback panic.

Prove it.

conformance

Every run lands in your own tamper-evident log, and Solon's behavior is machine-checked against it.

Business

Show an auditor exactly what ran, with receipts, from your own records.

Every verb runs read-only. Solon advises; you apply. It never touches your cloud.

$ See every verb in depth →
The console

One screen: the issues, ranked, fix a click away.

Solon ships a lightweight dashboard that runs in your own cluster. It reads your witnessed audit log and lays out an issue-first decision queue, each card correlating one problem on one surface, with its blast radius and a review-only fix. Ask it anything from the same bar.

your-cluster.internal/ui · solon
$Ask your cloud… “which of these can reach a customer database?”Ask →
Decision queue12 issues · 3 critical · over your witnessed log

SSH open to the internet on prod-bastion

sg-0a1b2c3d4e5f · CIS AWS §5.2
↳ blast radius reaches 3 resources → app-runtime → customer-exports (r/w), prod-orders
criticalGenerate fixreview-only

CI role grants s3:* on every bucket

role/ci-deploy · CIS AWS §1.16
↳ blast radius 41 buckets in scope, 2 hold PII
reviewGenerate fixreview-only

The dashboard never writes. It shows you the decision; you approve the change.

$ Tour the console →
Why it is different

Three things the incumbents cannot say.

01

It runs in your cloud, not ours.

Solon deploys into your own account. Your configuration never leaves it, and there is no vendor SaaS holding a copy of your setup.

02

Every answer is cited.

Each finding and recommendation traces to the real resource and rule behind it. When Solon cannot back something with evidence, it flags it instead of guessing.

03

Your audit log, not our portal.

Every run lands in your own tamper-evident store. You can show a regulator exactly what the agent did and why, without logging into anyone else's system.

A little proof

Every finding,
cited to the resource.

An audit names an open SSH rule and cites the exact security group. A path-analysis traces what a compromised role can reach and cites every hop. Every answer Solon returns carries its evidence like this, so your team and your auditors can check the work.

solon · zsh● live
$ solon audit --section 5 "open SSH to the world?"
Finding: security group allows SSH from anywhere
  sg-0a1b2c3d4e5f  prod-bastion   0.0.0.0/0 → :22   ⚠ critical

Cited: sg-0a1b2c3d4e5f  ✓ grounded
Customer-hosted

It lives in your account, not ours.

Solon runs inside your own AWS or GCP account, with Azure supported on a limited, emerging basis. It connects through OIDC, with no long-lived keys; it reads your cloud read-only and never holds a copy of your config; every run lands in your own audit log; and the reasoning runs on your own Anthropic or Bedrock key, under your account's data terms. The commercial Claude API does not train on your data, you can run it zero-retention, and on Bedrock the call never leaves your AWS boundary. Nothing about your setup sits on a vendor server.

$ See the mechanics →
One of three

Solon is the first of a customer-hosted family.

Same substrate, same principle: each agent runs in your own cloud, reasons over your real state with cited evidence, and never sends your data to a vendor. Solon audits and proves; Praktor safely applies the fix you approve; Tamias finds the savings your provider will not.

Solon

available now

Audit, recommend, prove.

Audits who and what can reach what across network and identity, designs the fix against the benchmarks, and proves what it did. Read-only.

Praktor

private pilot

The safe hands.

Applies a change Solon recommends under hard gates: dry-run, live re-check, lockout refusal, auto-rollback, every action witnessed. Solon advises; Praktor enacts.

Tamias

private pilot

Independent cloud cost.

Finds the savings your provider has no reason to point out, idle and over-provisioned resources, each cited with the math shown. Read-only.

auditsafely fixoptimize, all in your own account.

$ Meet the family →
Playbooks

Versioned baselines, served as content.

Two CIS Foundations baselines run live today, AWS (IAM and networking) and GCP (networking); CIS Azure networking is emerging. Beyond CIS, two evidence-for crosswalks are partial and live: PCI DSS v4.0.1 (Requirements 1, 7, 8, 10) and NIST SP 800-53 Rev 5 (8 controls, multi-cloud), each mapping our existing checks to the framework as evidence toward a requirement, not a compliance certification. HIPAA and NIST CSF remain engine-only stubs with no controls yet. We would rather show you what is live than imply a corpus we have not written yet.

Show the full framework matrix
CIS AWSv3.0.0

Foundations, partial. IAM (Section 1) and networking (Section 5) live, 10 controls.

CIS GCPv3.0.0

Foundations, partial. Networking (Section 3) live, 4 controls.

CIS Azurev3.0.0

Foundations, emerging. Networking live, 3 controls (RDP, SSH, Network Watcher).

PCI DSSv4.0.1

Partial evidence-for crosswalk. Req 1, 7, 8, 10 mapped, 14 controls. Evidence toward, not certification.

NIST 800-53Rev 5

Partial evidence-for crosswalk. 8 controls across 7 families, multi-cloud. Evidence toward, not certification.

HIPAASecurity Rule

Engine-only stub. No controls evaluable yet, content brief pending.

NIST CSFv2.0

Engine-only stub. No controls evaluable yet, content brief pending.

CustomAny

Bring your own baseline. The engine does not change.

See Solon run
against your own cloud.

We are pre-launch and onboarding a small number of pilot customers across AWS and GCP, with Azure on an emerging basis. The pilot is a fixed-price build-and-hand-off: we land Solon inside your infrastructure, and you keep what we build.