• by ziddoap on 4/30/2025, 7:49:50 PM

    Looks interesting, and I'll be diving into it a bit deeper, but I just wanted to mention that this quote:

    "even non-experts can guarantee the security of their cloud environments"

    Even though I understand that this is part of a marketing blurb, not a literal guarantee, it was an immediate yellow-flag for me. No tool can possibly guarantee the security of my cloud environment, so please don't imply/say your tool can. It reminds me of shady VPN companies guaranteeing my security by providing me with "military-grade encryption".

    To be abundantly clear, I am not saying that this product is shady or anything -- I have not had the time to evaluate it in the depth needed -- but statements like that make the rest of the pitch an uphill battle. For me, at least.

  • by mrbluecoat on 4/30/2025, 2:48:24 PM

    An admittedly superficial comment: what is your logo supposed to be? A mouse? Reminds me of that famous young/old optical illusion: https://www.braingle.com/brainteasers/26745/old-or-young-wom...

    Great job on the tool, by the way. Anything to improve the security posture of companies is a good thing!

  • by stego-tech on 4/30/2025, 4:57:51 PM

    I’m always a fan of automated compliance and vulnerability management tooling - looking forward to giving this a spin at some point.

    One bit of UX feedback: your “Offers” page isn’t rendering correctly on my iPhone (14 Pro) device. The text isn’t wrapping, graphics don’t seem to be scaling, and the columns are misaligned.

    Once the current network rebuild is done, I’m looking forward to rolling this and Wazuh to try out both.

  • by jmpavlec on 5/1/2025, 12:20:31 AM

    FYI seems like multiple typos in the GitHub description that shows at the top (not in the readme)

    Quoting it here:

    > Kexa's simple rules (Open Source) make it easy to monitoring and manage alerting of your entire cloud. With various monitoring and alerting options, instant and detailed alerts, easy-to-deploy and low in infrastructure costs, in turns complexity into simplicity.

  • by gitroom on 4/30/2025, 3:46:11 PM

    this kinda stuff is right up my alley, love when folks make it easier to cut through all the security noise

  • by sontek on 4/30/2025, 7:39:30 PM

    Can you give a brief explanation of the benefits of your policy engine over using cloud custodian?

  • by zufallsheld on 4/30/2025, 6:37:43 PM

    Does this work without your SaaS component? Can I run it air-gapped?

  • by shooker435 on 4/30/2025, 3:57:23 PM

    Wow, very cool. Would this replace a Vanta or complement it?