CloudFence continuously ingests native cloud logs to build real‑time behavioral baselines for each workload, detecting anomalous ports, unexpected east‑west traffic, and risky outbound connections. The platform automatically recommends usage‑based least‑privilege changes to security groups and IAM roles, and visualizes workload communication across accounts and regions to help security teams investigate and respond quickly.
Funding
Funding not disclosed

Founders
Product
Problem
Cloud environments lack continuous, behavior-based visibility, causing security teams to rely on static configuration checks and on‑prem network appliances that generate excessive alerts and cannot scale with dynamic workloads.
Solution
CloudFence ingests native cloud workload logs to create real‑time behavioral baselines for each service. By comparing live traffic and identity activity against these baselines, the platform detects anomalous ports, unexpected east‑west communication, and risky outbound connections. Detected deviations trigger automated recommendations to tighten security groups and IAM permissions, enabling usage‑based least‑privilege enforcement without manual rule changes. The solution also provides continuous egress traffic analysis, classifying destinations by reputation and alerting on high‑risk flows. All insights are presented through a real‑time visual map of workload communications, giving security teams immediate context for investigation and response.
Target Audience
Primary customers are cloud security and network teams in enterprises that operate multi‑account, multi‑region cloud environments and need continuous visibility and automated least‑privilege enforcement.
Features
- Agentless ingestion of native cloud logs (VPC flow logs, IAM events) to build per‑workload behavioral baselines
- Real‑time detection of deviations such as new ports, unexpected inter‑service traffic, and abnormal outbound activity
- Automated usage‑based least‑privilege recommendations for security groups and IAM roles
- Scalable egress traffic monitoring with domain reputation and geographic risk classification
- Interactive visual map showing real‑time workload communication across accounts, regions, and VPCs
- Alert reduction through behavior‑driven detection, eliminating reliance on static rule sets