Heeler · Cloud Security

Secure everything you build and run, from the first line of code to the cloud it runs on.

The Context Engine connects your code, dependencies, infrastructure code, container images and cloud accounts to the services they power and the teams that own them. Every risk arrives with its context: where it runs, what it exposes and who fixes it. Heeler fixes it at the source, in code or in the cloud, and guards every change so it stays fixed.

  1. 01
    At a glance
  2. 02
    How it works
  3. 03
    Cloud posture and compliance
  4. 04
    IaC security
  5. 05
    Container security
  6. 06
    Risk prioritization
  7. 07
    Remediation at the source
  8. 08
    Guardrails and drift
keyboard
Use the arrow keys or the dots on the right
01 · At a glance

Heeler cloud security capabilities by layer.

Rows are what Heeler does. Columns are the three places cloud risk lives.

cloud
Cloud accounts
code
Infrastructure code
deployed_code
Container images
travel_explore
Discover
Every account, project and subscription across AWS, Google Cloud and Azure, and every resource in them.Terraform, OpenTofu, CloudFormation, Pulumi, Kubernetes manifests and Dockerfiles in every repository.Every image in ECR, Artifact Registry and ACR, and every workload running it.
rule
Detect
Hundreds of built-in checks in 11 categories, plus checks you write.600+ rules across network, access, encryption, logging, workloads and secrets.Vulnerable OS packages and runtimes, end-of-life software and secrets, layer by layer.
priority_high
Prioritize
One queue for cloud, IaC and image findings. Each is Urgent, Plan or Defer, based on internet exposure, service tier, known exploitation and EPSS.
account_tree
Trace and route
Every finding linked to its live resource, the IaC file and line, the repository, the service and the owning team.
build
Fix
A proposed cloud setting change, approved by the owner, with its impact shown and a rollback.A pull request to the exact file and line, validated with a plan.A Dockerfile pull request to the safest base image, with the CVEs it removes.
shield
Prevent
Drift flagged when a console change undoes what the code says.PR guardrails stop new misconfigurations from merging.Dockerfile rules in the pull request: pinned base tags, no root user.
fact_check
Report
FSBP, CIS AWS, CIS Google Cloud and your own frameworks, with exemptions and audit evidence.A full history for every finding, from first seen to fixed.SBOM export in CycloneDX and SPDX, with vendor VEX applied.
01 · At a glance

Six functional areas and the outcome of each.

Each area has its own section in this deck. Select a card to jump to it.

02 · How it works

How Heeler works, from discovery to guardrails.

Heeler runs the whole job. People step in to approve a change and merge a pull request.

travel_explore
Discover
Every account, resource, repo and image
rule
Check
Cloud checks, IaC rules, image scans
priority_high
Prioritize
Urgent, Plan or Defer by real exposure
account_tree
Trace
To the IaC line, repo and owning team
build
Fix
IaC pull request or reviewed cloud change
task_alt
Verify
The next scan confirms the fix
shield
Guard
PR guardrails and drift detection
Continuous · every account · every pull request · every image
02 · How it works

Heeler links each cloud resource to its code, service and owner.

Heeler links each resource to the IaC that defines it, the repo it lives in, the workload that uses it and the team that owns it. That link is what turns a finding into the right fix for the right team.

Heeler links a cloud account and resource to the IaC file, repository, owning team, service, container image and running workload.
03 · Cloud posture and compliance

Cloud posture dashboard for AWS, Google Cloud and Azure.

Failing checks, what changed this week, every asset and every framework score, filterable by provider, account, team, service and severity.

cloud_sync
AWS, Google Cloud and Azure
Accounts, projects and subscriptions across every region.
lock_open_right
Read-only by design
Heeler reads configuration, never your data.
groups
Each team sees its own accounts
Posture scoped by ownership, with 180 days of history.
Cloud Posture
Failing checks
1,284
C 38
H 212
M 640
New this week
97
C 3
H 14
M 52
Cloud assets
6,008
AWS
GCP
Azure
Compliance posture
AWS Foundational Security Best Practices
63%
CIS AWS Foundations v7.0.0
43%
CIS GCP Foundations v4.0.0
29%
Top failing checks
SeverityCheckFrameworkFailing
CRITICAL
Security groups should not allow unrestricted access to ports with high risk
FSBP EC2.19
14
CRITICAL
S3 general purpose buckets should block public read access
FSBP S3.2
5
HIGH
Cloud SQL instances should require SSL for all connections
CIS GCP 6.4
8

Sample data.

03 · Cloud posture and compliance

Hundreds of cloud checks in 11 categories.

Every check explains why it matters, how to fix it in the console or CLI, and which framework controls it satisfies.

badge
Identity and access
51 checks
  • CRITICAL
    Hardware MFA should be enabled for the root user
  • CRITICAL
    IAM roles should not be assumable by anyone
  • CRITICAL
    IAM roles trusting an OIDC identity provider should restrict the token subject
key
Encryption and secrets
12 checks
  • CRITICAL
    KMS keys should not be publicly accessible
  • CRITICAL
    AWS KMS keys should not be deleted unintentionally
  • CRITICAL
    Secrets Manager secrets should not be publicly accessible
lan
Network and edge
74 checks
  • CRITICAL
    Security groups should not allow unrestricted access to ports with high risk
  • HIGH
    AWS AppSync GraphQL APIs should not be authenticated with API keys
  • HIGH
    CloudFront distributions should not point to non-existent S3 origins
memory
Compute
27 checks
  • CRITICAL
    SSM Documents Allow Anonymous Access
  • HIGH
    Auto Scaling group launch configurations should configure EC2 instances to require Instance Metadata Service Version 2 (IMDSv2)
  • HIGH
    Amazon EC2 instances launched using Auto Scaling group launch configurations should not have Public IP addresses
deployed_code
Containers and Kubernetes
22 checks
  • HIGH
    ECR repositories should not be publicly accessible
  • HIGH
    ECR private repositories should have image scanning configured
  • HIGH
    ECS services should not have public IP addresses assigned to them automatically
bolt
Serverless and messaging
22 checks
  • CRITICAL
    Database Migration Service replication instances should not be public
  • CRITICAL
    MSK clusters should have public access disabled
  • CRITICAL
    Lambda function policies should prohibit public access
inventory_2
Storage
25 checks
  • CRITICAL
    S3 general purpose buckets should block public read access
  • CRITICAL
    S3 general purpose buckets should block public write access
  • CRITICAL
    Amazon EBS snapshots should not be publicly restorable
database
Databases
110 checks
  • CRITICAL
    DocumentDB Cluster Snapshots with Public Permissions
  • CRITICAL
    Neptune Cluster Snapshots with Public Permissions
  • CRITICAL
    OpenSearch Domains that are Internet facing
monitoring
Logging and threat detection
24 checks
  • CRITICAL
    AWS Config should be enabled and use the service-linked role for resource recording
  • HIGH
    GuardDuty should be enabled
  • HIGH
    GuardDuty EKS Audit Log Monitoring should be enabled
neurology
Data, AI and build
13 checks
  • CRITICAL
    CodeBuild Bitbucket source repository URLs should not contain sensitive credentials
  • CRITICAL
    CodeBuild project environment variables should not contain clear text credentials
  • CRITICAL
    Ensure That BigQuery Datasets Are Not Anonymously or Publicly Accessible
account_tree
Account and project governance
19 checks
  • HIGH
    Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level
  • HIGH
    Ensure That Cloud Audit Logging Is Configured Properly
  • MEDIUM
    Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC
add_circle
Your own checks
custom
  • Clone any built-in pack and add or remove checks
  • Map checks to your internal control IDs
03 · Cloud posture and compliance

Compliance reporting for FSBP, CIS and custom frameworks.

AWS Foundational Security Best Practices
63%
AWS Security Hub standard · 281 controls
CIS AWS Foundations Benchmark
43%
v3.0 through v7.0
CIS Google Cloud Foundations Benchmark
29%
v4.0.0
Your framework
88%
Draft, preview, publish and compare versions. Crosswalk controls between frameworks.
approval
Exemptions with a second approver
Scoped to one control or all frameworks, approved by someone other than the requester, and set to expire.
download
Evidence on demand
Export controls, results and exemptions for auditors.
CIS AWS Foundations · Heatmap by account
prod
staging
data
shared
sandbox
logs
IAM
82%
61%
79%
94%
38%
97%
Storage
58%
40%
71%
77%
22%
91%
Logging
93%
80%
90%
85%
35%
100%
Monitoring
55%
31%
60%
52%
12%
74%
Networking
43%
57%
72%
81%
18%
95%

Group by account, AWS OU, GCP folder or environment. Sample data.

04 · IaC security

IaC scanning across every repository.

Heeler scans Terraform and OpenTofu, CloudFormation, Pulumi, Kubernetes manifests and Dockerfiles in every repository, against more than 600 rules, and ties each finding to the exact file and line.

Security · IaC · Active findings
Heeler IaC findings table with rule, module, file, risk, severity and confidence for Kubernetes manifests.
04 · IaC security

IaC rules in 8 categories.

From the network and identity around a workload to the pod spec and the Dockerfile inside it.

lan
Network exposure
  • Security group open to 0.0.0.0/0 on a database port
  • Load balancer listening on plain HTTP
  • Public IP assigned to instances by default
badge
Access control
  • IAM policy with wildcard actions or resources
  • Kubernetes RBAC wildcard or secret read
  • Cross-account trust with no conditions
lock
Encryption
  • Storage, volumes and snapshots without encryption at rest
  • Customer-managed key rotation turned off
  • TLS not enforced on database connections
monitoring
Logging
  • VPC flow logs turned off
  • Audit logging missing on buckets and clusters
  • CloudTrail without log file validation
deployed_code
Kubernetes workloads
  • Privilege escalation allowed
  • Container can run as root
  • Writable root filesystem, capabilities not dropped
inventory
Dockerfiles
  • No USER directive, so the image runs as root
  • Base image tag not pinned
  • No HEALTHCHECK instruction
key
Secrets in config
  • Plaintext secret in a Kubernetes env var
  • Credentials in CloudFormation parameters
  • Hardcoded provider keys
tune
Secure defaults
  • Deletion protection off on production data
  • Backups and point-in-time recovery disabled
  • Public access blocks not set
04 · IaC security

IaC checks on every pull request, with a suggested fix.

block
New misconfigurations never merge
Guardrails by severity, confidence, framework or rule.
auto_fix_high
The fix is in the comment
A suggested change the developer can commit in one click.
sensors
Risk from the live resource
If the resource is already deployed and exposed, the finding says so.
acme/infra · Pull request #412
H
Heeler PR Guardrail
·
1 blocking finding
Security group allows all inbound to a database
CRITICAL

modules/db/security.tf:14 · live resource sg-0a41 is internet facing
Suggested change
- cidr_blocks = ["0.0.0.0/0"]
+ cidr_blocks = [var.vpc_cidr]
Commit suggestion
Request exception

Sample data.

05 · Container security

Container image inventory across registries and running workloads.

Heeler scans every image pushed to AWS ECR, Google Artifact Registry and Azure ACR, links it to the repo that built it and the workloads that run it, and rescans running images daily.

Security · Containers · Images
Heeler container images table with registry, tags, scan status, tier, running status and vulnerability counts.
05 · Container security

Image detail: vulnerabilities, layers, base image and SBOM.

Containers · api-gateway
Container image detail: end-of-life OS, source repository, base image amazoncorretto:17 and a base upgrade that removes 113 of 118 base CVEs.
bug_report
OS and package vulnerabilities
Every package in every layer, with CVSS, EPSS and known-exploited status.
code
Language runtimes
Java, Python, Node and more, down to the installed version and the version that fixes it.
event_busy
End-of-life software
Operating systems and runtimes that are past or near end of support.
key
Secrets in layers
Keys and tokens baked into an image, found in the layer that added them.
layers
Base vs. your layers
Which vulnerabilities come from the base image and which from your own build steps.
verified
Vendor VEX
Vendor statements that a CVE does not apply are honored, so noise drops away.
rocket_launch
Running workloads
ECS, Kubernetes, Cloud Run and Lambda: which images run, where, and how exposed.
description
SBOM
CycloneDX and SPDX export for every image, on demand.
06 · Risk prioritization

One prioritized queue for cloud, IaC and container findings.

Cloud checks, IaC findings and image vulnerabilities land in one list. Each gets Urgent, Plan or Defer from how critical the service is, whether it is exposed, and whether the flaw is being exploited.

public
Real exposure
Internet facing, public access, cross-account trust.
star
Business impact
Service tier and environment.
crisis_alert
Threat
Known exploited, EPSS likelihood.
Priorities · Cloud, IaC and containers
URGENT
Cloud

Security group open to 0.0.0.0/0 on 5432
internet facing
Tier 1
production
@payments
URGENT
Container

CVE-2025-24813 in tomcat-embed-core
running
known exploited
Tier 1
@orders
PLAN
IaC

RDS instance without deletion protection
production data
not exposed
@data
DEFER
Cloud

S3 bucket without access logging
sandbox
no public access
@platform

Sample data.

06 · Risk prioritization

Toxic combinations: findings that are minor alone and critical together.

Many cloud findings look harmless on their own. Heeler looks at how misconfigurations, vulnerabilities and permissions connect, finds the chains an attacker could follow, and ranks the chain instead of each finding.

Attack path · web-01 to customer data
Entry
public
Internet
Anyone
→
Exposure
dns
EC2 instance web-01
Port 8080 open to 0.0.0.0/0
Alone
MEDIUM
→
Vulnerability
bug_report
CVE-2025-24813 in Tomcat
Known exploited, runs on web-01
Alone
HIGH
→
Permission
key
Role web-01-role
s3:GetObject on every bucket
Alone
MEDIUM
→
Target
database
S3 bucket customer-exports
Customer PII, not public
Alone
LOW
CRITICAL
Together: a known exploit on an internet-facing server can read customer data.
Break the chain at any link: patch Tomcat, close port 8080, or scope the role to the buckets web-01 needs.
route
See the path
Every step from the internet to sensitive data, with the finding at each step.
priority_high
Rank the chain
A path with a known-exploited flaw goes above higher-scoring findings that lead nowhere.
swap_calls
See how an attacker moves
Which step allows lateral movement or privilege escalation.
content_cut
Fix the cheapest link
Heeler shows which single change breaks the path, and sends it to the team that owns it.

Sample data.

06 · Risk prioritization

Each cloud finding traced to its IaC line and owning team.

Heeler matches the live resource to the Terraform, CloudFormation or Pulumi that defines it, and to the team that owns that module.

Cloud finding
cloud

Security group allows 0.0.0.0/0 on 5432

CRITICAL
FSBP EC2.19
→
Live resource
lan

aws_security_group
sg-0a41

on
orders-db
, Tier 1, production
→
Defined in
code

acme/infra

modules/db/security.tf:14
→
Owned by
groups

@payments-team

Ticket and message sent

Sample data.

07 · Remediation at the source

Three ways Heeler fixes a finding: in IaC, in the cloud or in the image.

A fix in the wrong place does not last. Heeler picks the right one for each finding.

code
Defined in IaC
A pull request to the file and line, validated with a plan, sent to the owning team.
Fix the code
cloud
Not in IaC
The exact cloud setting to change, shown with its impact, applied after a person approves it.
Fix the cloud
deployed_code
In a container image
A Dockerfile pull request to the safest base image, scanned before it is proposed.
Fix the image
07 · Remediation at the source

IaC fix: a validated pull request to the exact line.

difference
Minimal change
Only the attributes that fail the check.
task_alt
Validated before you see it
terraform validate
, a clean plan, and the rule passes on the new code.
link
Closes both findings
The IaC finding and the cloud check it caused.
[Heeler] Restrict database ingress to the VPC
modules/db/security.tf
ingress {
from_port = 5432
to_port = 5432
protocol = "tcp"
- cidr_blocks = ["0.0.0.0/0"]
+ cidr_blocks = [var.vpc_cidr]
}
✓ terraform validate
✓ plan: 1 to change
✓ FSBP EC2.19 passes
Review and merge
Fixes 1 cloud finding and 1 IaC finding

Sample data.

07 · Remediation at the source
Proposed change · acme-logs bucket
Turn on S3 Block Public Access for acme-logs
CRITICAL
FSBP S3.2
not managed by IaC
Change
BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets:
false → true
Impact
No principal outside the account read this bucket in the last 30 days.
Approval
Awaiting the bucket owner, @platform
Approve and apply
Send as ticket
Rollback available

Cloud fix: a proposed setting change, approved by the owner.

verified_user
A person approves every change
Heeler proposes the exact setting and applies it only after approval.
insights
Impact shown first
What the change affects, so the owner can approve with confidence.
undo
Scoped and reversible
A narrow write role you grant, and a one-click rollback.

Sample data.

07 · Remediation at the source

Image fix: a Dockerfile pull request to a safer base image.

Heeler finds newer base tags, scans each one, and shows exactly which CVEs an upgrade removes and which it introduces.

shield_lock
Safe by default
Never crosses a major version and skips pre-releases.
edit_note
Only the FROM line changes
Every build stage, and any ARG that feeds it.
Base image upgrade · api-gateway
CandidateRemovesRemainingIntroduces
amazoncorretto:17
113530
Open Dockerfile PR
amazoncorretto:17-al2023
1041412
Compare
Dockerfile
- FROM amazoncorretto:17@sha256:e2adb8e2da67…
+ FROM amazoncorretto:17@sha256:9c41f07b3e1a…
08 · Guardrails and drift

Verification, pull request guardrails and drift detection.

task_alt
Verified by the next scan
Cloud checks rerun every 12 hours. Running images are rescanned daily.
block
Blocked at the pull request
A later change that reopens the problem cannot merge.
compare_arrows
Drift caught
When a console change undoes what the code says, Heeler flags it and routes it to the owner.
History · sg-0a41
FSBP EC2.19 failing

0.0.0.0/0 allowed on 5432
Oct 2
Fix PR merged

modules/db/security.tf · @payments-team
Oct 3
Check passing

Confirmed by the next cloud scan
Oct 3
PR blocked

A later change tried to reopen ingress
Oct 9
Drift detected

Rule added in the console, ticket sent
Oct 14
Back in line with code

Console change reverted by the owner
Oct 14

Sample data.

Heeler · Summary

What Heeler cloud security delivers.

visibility
One view
Cloud accounts, infrastructure code and container images in one posture and one queue.
priority_high
Real risk first
Ranked by exposure, business impact and active threat, not by count.
build
Fixed at the source
Pull requests to code and images, reviewed changes to the cloud, sent to the owning team.
shield
Stays fixed
Verified by the next scan, guarded in every pull request, drift flagged when it happens.
Heeler

Find it. Fix it at the source.

Keep it fixed.