SOC 2 Type II · ISO 27001 · 1,400 security teams
SOC 2 Type II · ISO 27001 · 1,400 security teams
Palisade
Palisade
Risk score82/100open
Next page/
Home
Cloud · Cloud
See what your cloud shows the internet.
Buckets, ports and roles that answer to the whole internet.
WatchedAWS accountsWatchedAzure subscriptionsWatchedGoogle Cloud projectsWhat it closes.
0 of 4 closed
01Open
Public by mistake
Buckets, databases and snapshots that anyone can read, ranked by what is inside.
02Open
Open ports
Management ports that answer to the whole internet, with the rule that opened them.
03Open
Role reach
The roles that can do far more than their job needs, and the one-line policy that fixes each.
04Open
Read-only by design
One role per account, no agents, nothing written to your cloud.
Palisade connects read-only to AWS, Azure and Google Cloud and checks every resource against the way it is really used. A public bucket that holds nothing is a note. A public bucket with customer exports is a page at 3 am.
What it closes
- Storage open to the public
- Management ports reachable from anywhere
- Roles with far more reach than they use
What you get in week one
- Everything public that should not be
- Management ports open to the internet
- Roles with rights they have never used
How it connects
One read-only role per account, created from a template you can read line by line. Remove the role and Palisade is gone.
Cloud · Cloud
See what your cloud shows the internet.
Buckets, ports and roles that answer to the whole internet.

What it closes.
0 of 4 closed
01Open
Public by mistake
Buckets, databases and snapshots that anyone can read, ranked by what is inside.
02Open
Open ports
Management ports that answer to the whole internet, with the rule that opened them.
03Open
Role reach
The roles that can do far more than their job needs, and the one-line policy that fixes each.
04Open
Read-only by design
One role per account, no agents, nothing written to your cloud.
Palisade connects read-only to AWS, Azure and Google Cloud and checks every resource against the way it is really used. A public bucket that holds nothing is a note. A public bucket with customer exports is a page at 3 am.
What it closes
- Storage open to the public
- Management ports reachable from anywhere
- Roles with far more reach than they use
What you get in week one
- Everything public that should not be
- Management ports open to the internet
- Roles with rights they have never used
How it connects
One read-only role per account, created from a template you can read line by line. Remove the role and Palisade is gone.
Cloud · Cloud
See what your cloud shows the internet.
Buckets, ports and roles that answer to the whole internet.
WatchedAWS accountsWatchedAzure subscriptionsWatchedGoogle Cloud projectsWhat it closes.
0 of 4 closed
01Open
Public by mistake
Buckets, databases and snapshots that anyone can read, ranked by what is inside.
02Open
Open ports
Management ports that answer to the whole internet, with the rule that opened them.
03Open
Role reach
The roles that can do far more than their job needs, and the one-line policy that fixes each.
04Open
Read-only by design
One role per account, no agents, nothing written to your cloud.
Palisade connects read-only to AWS, Azure and Google Cloud and checks every resource against the way it is really used. A public bucket that holds nothing is a note. A public bucket with customer exports is a page at 3 am.
What it closes
- Storage open to the public
- Management ports reachable from anywhere
- Roles with far more reach than they use
What you get in week one
- Everything public that should not be
- Management ports open to the internet
- Roles with rights they have never used
How it connects
One read-only role per account, created from a template you can read line by line. Remove the role and Palisade is gone.
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
