Your cloud's access posture, who and what can reach what, audited, recommended, and designed by an agent that runs in your own account. Every recommendation cites its evidence, so your team and your auditors can trust it.
Reads native cloud state · runs inside your account
askPlain-language questions, straight answers, every claim backed by what Solon actually saw.
Get a yes-or-no answer in a minute instead of an afternoon of console spelunking.
auditMeasure your setup against the security rulebooks (CIS, PCI, NIST) and see exactly where you stand.
Walk into the audit already knowing the result.
path-analysisTrace what an exposed resource or a compromised principal can actually reach across your cloud.
Know the blast radius before an attacker maps it for you.
recommendDescribe what you need; Solon returns the precise, minimal change to get there.
Changes ship faster and break less.
change-packageA reviewable, reversible package: the steps, the checks, and the rollback for each one.
Make changes without the 2 a.m. rollback panic.
conformanceEvery run lands in your own tamper-evident log, and Solon's behavior is machine-checked against it.
Show an auditor exactly what ran, with receipts, from your own records.
Every verb runs read-only. Solon advises; you apply. It never touches your cloud.
$ See every verb in depth →Solon ships a lightweight dashboard that runs in your own cluster. It reads your witnessed audit log and lays out an issue-first decision queue, each card correlating one problem on one surface, with its blast radius and a review-only fix. Ask it anything from the same bar.
The dashboard never writes. It shows you the decision; you approve the change.
$ Tour the console →Solon deploys into your own account. Your configuration never leaves it, and there is no vendor SaaS holding a copy of your setup.
Each finding and recommendation traces to the real resource and rule behind it. When Solon cannot back something with evidence, it flags it instead of guessing.
Every run lands in your own tamper-evident store. You can show a regulator exactly what the agent did and why, without logging into anyone else's system.
An audit names an open SSH rule and cites the exact security group. A path-analysis traces what a compromised role can reach and cites every hop. Every answer Solon returns carries its evidence like this, so your team and your auditors can check the work.
Finding: security group allows SSH from anywhere sg-0a1b2c3d4e5f prod-bastion 0.0.0.0/0 → :22 ⚠ critical Cited: sg-0a1b2c3d4e5f ✓ grounded
Solon runs inside your own AWS or GCP account, with Azure supported on a limited, emerging basis. It connects through OIDC, with no long-lived keys; it reads your cloud read-only and never holds a copy of your config; every run lands in your own audit log; and the reasoning runs on your own Anthropic or Bedrock key, under your account's data terms. The commercial Claude API does not train on your data, you can run it zero-retention, and on Bedrock the call never leaves your AWS boundary. Nothing about your setup sits on a vendor server.
$ See the mechanics →Same substrate, same principle: each agent runs in your own cloud, reasons over your real state with cited evidence, and never sends your data to a vendor. Solon audits and proves; Praktor safely applies the fix you approve; Tamias finds the savings your provider will not.
Audit, recommend, prove.
Audits who and what can reach what across network and identity, designs the fix against the benchmarks, and proves what it did. Read-only.
The safe hands.
Applies a change Solon recommends under hard gates: dry-run, live re-check, lockout refusal, auto-rollback, every action witnessed. Solon advises; Praktor enacts.
Independent cloud cost.
Finds the savings your provider has no reason to point out, idle and over-provisioned resources, each cited with the math shown. Read-only.
audit → safely fix → optimize, all in your own account.
$ Meet the family →Two CIS Foundations baselines run live today, AWS (IAM and networking) and GCP (networking); CIS Azure networking is emerging. Beyond CIS, two evidence-for crosswalks are partial and live: PCI DSS v4.0.1 (Requirements 1, 7, 8, 10) and NIST SP 800-53 Rev 5 (8 controls, multi-cloud), each mapping our existing checks to the framework as evidence toward a requirement, not a compliance certification. HIPAA and NIST CSF remain engine-only stubs with no controls yet. We would rather show you what is live than imply a corpus we have not written yet.
Foundations, partial. IAM (Section 1) and networking (Section 5) live, 10 controls.
Foundations, partial. Networking (Section 3) live, 4 controls.
Foundations, emerging. Networking live, 3 controls (RDP, SSH, Network Watcher).
Partial evidence-for crosswalk. Req 1, 7, 8, 10 mapped, 14 controls. Evidence toward, not certification.
Partial evidence-for crosswalk. 8 controls across 7 families, multi-cloud. Evidence toward, not certification.
Engine-only stub. No controls evaluable yet, content brief pending.
Engine-only stub. No controls evaluable yet, content brief pending.
Bring your own baseline. The engine does not change.
We are pre-launch and onboarding a small number of pilot customers across AWS and GCP, with Azure on an emerging basis. The pilot is a fixed-price build-and-hand-off: we land Solon inside your infrastructure, and you keep what we build.