AI-powered security & compliance platform

Your AI Security Analyst,
Built into Your
Compliance Platform.

StratSecure continuously scans cloud accounts, Linux and Windows servers, and containers against six compliance frameworks — then an embedded AI analyst explains every finding, triages CVEs, and helps your team prepare for audits.

6Frameworks
360+Controls
3Cloud providers
117Linux checks
53Windows CIS
6AI tools live

Multi-tenancy · RBAC · Mandatory TOTP 2FA · AES-256-GCM encryption · AI Assistant · Audit-ready


AI Security Assistant

An AI analyst built into every page of your security platform. Ask about your compliance posture, investigate CVE exposure, triage FIM alerts — and get answers grounded in live data from your environment, not generic advice.

Live-Data Chat Assistant
Six tools querying your real-time environment — always one click away
  • get_compliance_summary — current framework scores and posture trends
  • get_findings — open findings filtered by severity, framework, or agent
  • get_agent_status — online, offline, and degraded agents across your fleet
  • get_fim_alerts — unacknowledged file integrity changes by severity
  • get_cve_findings — CVE exposure per agent, package, and severity band
  • get_patch_status — pending approval, approved, and applied patches
6 live toolsStreaming SSEVisual components
Custom AI Agent Builder
Purpose-built compliance agents your team defines and schedules
  • Describe your goal — "alert me when any CIS score drops below 70%"
  • AI generates a name and an optimised system prompt for the task
  • Verify — run the agent against live data before committing
  • Schedule on cron — daily briefings, weekly CVE triage, monthly audit summaries
  • Each run stores a structured result: summary, findings, and proposed actions
3-step wizardCron-scheduledVerified against live data

Rich Visual Responses

Tool results render as visual components — not plain text. Severity cards, compliance score bars, agent status tables, CVE lists, and patch pills give analysts exactly what they need at a glance.

Built-in Compliance Agents

Pre-built agents for compliance checking, vulnerability triage, and patch readiness run on demand or on schedule — no configuration needed. Use them as starting templates for your own custom agents.

Conversation History

Every chat session saved, searchable, and attributed. Review what your team asked last week, replay a compliance briefing, or share analysis with auditors directly from the conversation log.

Contextual Suggestions

Empty-state chips surface the most relevant questions for your environment — open critical CVEs, failing controls, agents that just went offline, and patches awaiting approval. Start an investigation in one click.

Your Model, Your Control

Connect any OpenAI-compatible endpoint — StratAI, OpenAI, Azure OpenAI, or a self-hosted LiteLLM proxy. The API key is stored AES-256-GCM encrypted and never leaves the platform.

Background Agent Runs

Custom agents run silently on your cron schedule and store structured results per run. Review a week of daily compliance briefings, compare CVE triage outputs, or export agent findings as compliance evidence.

The AI assistant sees exactly what your analysts see — live data, not stale snapshots.
Every tool call fetches fresh data from the database at query time. Ask about your posture right now, not from a cached report generated hours ago.
Real-time data LiteLLM compatible AES-256-GCM key storage

Six Compliance Frameworks. One Platform.

A single scan provides evidence for every framework on your roadmap — cloud and server, simultaneously.

ISO 27001:2022 114 controls · Cloud
SOC 2 TSC 5 trust criteria · Cloud
PCI DSS v4.0 78+ sub-requirements · Cloud
NIST 800-53 Rev 5 50 agent checks · Linux
CIS Benchmark 67 checks · Linux
CIS Windows Server 2022 53 controls · Windows
CVE / OSV package vulnerability enrichment

A Unified Compliance Platform

One platform — continuous scanning, AI-powered analysis, and audit-ready evidence — replacing the patchwork of tools your team assembles before every audit.

Cloud & Container Scanning

Continuously scan AWS, Azure, and GCP accounts plus Docker, Kubernetes, Swarm, ECS, and EKS environments — every finding mapped to ISO 27001, SOC 2, or PCI DSS controls.

AWSAzureGCP DockerKubernetesECS/EKS
Endpoint & Server Agents

Lightweight agents run 117 NIST and CIS checks on Linux, 53 CIS Windows Server controls, and Active Directory domain analysis — no SSH credentials stored, no perimeter required.

LinuxWindows Server NIST 800-53CIS Benchmark Active Directory
AI Intelligence & Evidence

An embedded AI analyst explains every finding, triages CVEs, and briefs your team — while scan results become audit-ready evidence mapped automatically to the controls they satisfy.

AI ChatCustom AgentsEvidence Library

Multi-Cloud Posture Assessment

Connect with read-only credentials. Every finding maps directly to the ISO 27001, SOC 2, or PCI DSS control it violates.

Amazon Web Services
SDK v3

Scans IAM, S3, EC2, RDS, CloudTrail, KMS, and CloudWatch. Credentials are validated the moment you connect.

  • IAM
  • EC2
  • S3
  • RDS
  • CloudTrail
  • KMS
  • CloudWatch
  • STS
Microsoft Azure
ARM SDK

Scans virtual machines, storage accounts, networking, Key Vault, and SQL databases. Service principal authentication — Tenant ID, Client ID, Secret, Subscription ID.

  • Compute
  • Storage
  • Network
  • Key Vault
  • Monitor
  • SQL
  • Subscriptions
Google Cloud Platform
SDK v8

Scans Compute Engine instances, Cloud Storage buckets, KMS key policies, and Cloud Logging. Service account JSON key authentication, Viewer role minimum.

  • Compute
  • Storage
  • KMS
  • Logging
  • Resource Manager
Credentials are AES-256-GCM encrypted at rest and only decrypted for the duration of a scan.
Read-only policies across all three providers — AWS ReadOnlyAccess, Azure Reader role, GCP Viewer — mean StratSecure can see your environment without being able to change it.
AES-256-GCM Read-only IAM Credential validation

Agent-Based Endpoint & Server Security

Agents install in minutes with a single command, authenticate with tokens, and immediately begin reporting on hardening posture and vulnerabilities.

Linux Server Agent
NIST 800-53 Rev 5 + CIS Linux Benchmark
117 checks across NIST and CIS control families, mapped to exactly what your auditor will ask about.
50
NIST checks
67
CIS checks
117
combined
  • NIST 800-53 Rev 5 — AC, AU, CM, IA, SC, SI control families
  • CIS Linux Benchmark — Initial Setup, Services, Network, Logging, Access, Maintenance
  • Token-based authentication — no SSH credential storage
  • CVE scanning, file integrity monitoring, and scheduled compliance runs
Windows Server Agent
CIS Windows Server 2022 + Active Directory
53 CIS Windows controls plus Active Directory domain security posture — Kerberoastable accounts, privilege sprawl, and trust relationships.
53
CIS controls
12
categories
AD
domain scan
  • CIS Windows Server 2022 v3.0.0 — Account Policies, Firewall, Audit Policy, Defender, BitLocker, RDS, PowerShell
  • Active Directory scanning — password policy, privileged group membership, stale accounts
  • Kerberoastable & AS-REP Roastable account detection
  • Windows registry key monitoring via FIM
Agent updates are dispatched from the platform — no SSH sessions, no maintenance windows.
The agent downloads the binary, verifies the SHA-256 checksum, and restarts via systemd automatically.
SHA-256 verified systemd restart Zero SSH

Container & Orchestration Security

The same systematic compliance scanning applied to Docker, Kubernetes, Swarm, ECS, and EKS environments — via the existing agent binary and AWS SDK, with no additional tooling required.

Agent-based scanning

Docker Host Scanning

The Linux agent detects Docker automatically and checks host configuration, daemon security, and container runtime against CIS Docker Benchmark v1.6.

  • CIS Docker Benchmark v1.6 — ~50 checks across 6 sections
  • Daemon security options, socket permissions, image policies
  • Privileged container and resource limit checks
CIS Docker v1.6~50 checks

Kubernetes Cluster Scanning

Deploys a lightweight in-cluster agent and runs CIS Kubernetes Benchmark v1.8 plus NSA hardening guidelines — no external credentials stored.

  • CIS Kubernetes Benchmark v1.8 — 100+ checks
  • API server, etcd, kubelet, and worker node hardening
  • RBAC audit — cluster-admin bindings and service account permissions
CIS K8s v1.8100+ checks

Docker Swarm Scanning

Extends the Linux agent on manager nodes to enumerate services, validate network encryption, and check secret access controls — no additional tooling required.

  • Service, node, and secret inventory snapshots
  • Overlay network encryption and TLS certificate validation
  • Findings mapped to CIS Docker and NIST 800-53 controls
Swarm managerZero new binary
AWS cloud-native scanning (no agent required)
AWS ECS
Elastic Container Service — server-side via AWS SDK
  • No agent needed — extends the existing AWS cloud scanner
  • ECS cluster, service, and task definition security analysis
  • IAM task role least-privilege and secrets audit
  • On-demand and cron-scheduled scans
AWS SDKSchedulableNo agent
AWS EKS
Elastic Kubernetes Service — AWS SDK + in-cluster agent
  • AWS-side: control plane endpoint access, API server logging, secrets encryption
  • Node group hardening — IMDSv2 enforcement, launch template checks
  • In-cluster: full CIS Kubernetes Benchmark via the K8s agent
  • Combined AWS + cluster findings in a single unified scan result
AWS SDKK8s agentUnified scan
CIS Docker Benchmark v1.6 ~50 checks · Docker host
CIS Kubernetes v1.8 100+ checks · K8s
NSA/CISA K8s Hardening Guide RBAC · network policies
NIST SP 800-190 container security guide

CVE Vulnerability & Patch Management

Discover what's installed, understand which packages carry known CVEs, and apply patches through an approval workflow with a complete audit trail.

CVE Vulnerability Scanning
Know exactly what's running — and what's exploitable
  • Collects all installed packages via dpkg-query or rpm
  • Enriched via OSV API — CVSS-based severity scoring, CVE ID, fixed version
  • Weekly re-enrichment of stale findings with current OSV data
  • Feeds into the unified risk score alongside compliance posture
CriticalHigh MediumLow
Patch Management
Structured patching with a full audit trail
  • Per-agent approval workflow before any changes are applied
  • Automated application via apt / yum / dnf with optional auto-reboot
  • Package-level tracking with CVE IDs and security flags per package
  • Recurring cron-based schedules with 90-day history retention
Awaiting approvalAppliedScheduled

File Integrity Monitoring

SHA256-based change detection that surfaces every deviation from your verified baseline within minutes of it happening.

Multi-Agent Baselines

Define a baseline once and deploy it across your fleet. Any file deviation triggers an alert within minutes.

  • Change types: created, modified, deleted, permissions, ownership
  • Open-event deduplication prevents duplicate alerts
  • Default 2-minute scan interval

Server-Side Reference Files

Store authoritative configuration files in StratSecure. Drift against the golden copy is detected automatically — restore with a single action.

  • Auto-push to all agents on upload
  • Inline reference file viewer
  • File restore dispatch to agent

Windows Registry Monitoring

Monitor compliance-critical registry keys alongside file system integrity — covering CIS Windows controls in a single baseline.

  • Severity classification: critical → info
  • Acknowledgement workflow per change event
  • History retained after acknowledgement


Evidence & Compliance Automation

Every scan result, FIM acknowledgement, and policy document becomes compliance evidence — automatically mapped to the control it satisfies.

Evidence Library

All scan results, acknowledgements, and policy documents in one registry — each already mapped to the ISO 27001, SOC 2, PCI DSS, NIST, or CIS control it satisfies.

Audit Requests

Track every evidence obligation — owner, due date, attachments — so your auditor always receives a complete, timely response.

Policy Documents

Full policy lifecycle — drafted, reviewed, approved, and periodically renewed — with each version attached to the framework controls it addresses.

Evidence Pack Export

Export a complete evidence pack when your audit arrives. The Control Coverage view shows gaps before your auditor finds them.

Control Coverage View

A living picture of your compliance position — controls with strong evidence, partial coverage, and genuine gaps — for every framework.

Activity Timeline

An immutable record of every significant platform event — logins, changes, scans, and results — searchable back three months.


Notifications, Alerting & Compliance Drift

Critical findings, offline agents, and compliance drift surface automatically — wherever your team already works.

Webhook
Integrate StratSecure alerts into any system that accepts an HTTP request — SIEM, ticketing, or on-call tools.
Slack
Route critical findings and FIM alerts to your Slack security channels with per-severity rules and cooldown periods.
Microsoft Teams
Rich alert cards delivered directly into your Teams security channel — findings, agent status, and drift events with full context.

Event-triggered rules

Define which events trigger which channels. Cooldown periods ensure your team gets signal, not noise.

Compliance drift detection

Alerts the moment your score drops below a threshold you define, with a breakdown of exactly which controls are newly failing.

In-app notification bell

Polls every 60 seconds for critical FIM changes, offline agents, and new CVEs — surfaced in-app even without external channel setup.


Risk Scoring & Compliance Reports

A unified risk score per agent combining compliance posture with live CVE data. Reports in PDF, HTML, CSV, and JSON.

Unified Risk Scoring
One number per server — compliance posture plus CVE exposure
  • complianceScore = passed / total checks × 100
  • vulnPenalty = critical×20 + high×8 + medium×2 + low×0.5
  • unifiedRiskScore = compliance×50% + vulnScore×50%
  • Risk levels: ≥80 low · 60–79 medium · 40–59 high · <40 critical
Report Generation
From scan result to auditor-ready evidence in a single export
Cloud
ISO / SOC2 / PCI
CVE
Vulnerability scan
NIST
800-53 Rev 5
CIS
Linux Benchmark
Windows
CIS Server 2022
PDF
Charts & tables
HTML
Web review
JSON
API & automation
CSV
Spreadsheet

Built for Enterprise Security

Hardened at every layer — encrypted at rest, mandatory 2FA, granular RBAC, and immutable audit trails.

AES-256-GCM Encryption
Every credential — cloud keys, agent tokens, TOTP secrets — encrypted at rest. Nothing decrypted unless a scan specifically requires it.
Mandatory TOTP 2FA
Every account requires TOTP two-factor authentication before reaching the dashboard — enforced by the platform, not left as a user preference.
RBAC — 93 Permissions
93 granular permissions across 17 categories — give analysts view access without touching scan configuration.
PCI DSS Password Policy
PCI-compliant password policy enforced for platform accounts and every OS user provisioned through the platform.
Immutable Audit Trails
Every significant action written to an immutable record — who logged in, what changed, what scans ran, and what the results showed.
Multi-Tenancy & Sessions
Complete data isolation between tenants. Idle timeouts, HSTS headers, and HTTP-only cookies enforced server-side.

How it works

From first connection to AI-powered, continuously operating compliance coverage in four steps.

1

Connect

Add cloud accounts with read-only credentials, install agents on servers with a single command, and connect any OpenAI-compatible model for the AI assistant. No SSH credentials stored, no perimeter required.

2

Configure

Set scan schedules, FIM baselines, alert channels, and drift thresholds with sensible defaults. Build custom AI agents using the 3-step wizard — describe your goal, verify against live data, schedule on cron.

3

Scan & Ask

StratSecure runs continuously across cloud, servers, and containers. Ask the AI assistant what any finding means, which controls are at risk, or what's changed since last week — answers grounded in live data, always.

4

Report & Remediate

Assign findings to owners, export an evidence pack, and generate a compliance report in seconds. Custom AI agents can brief your team daily and flag drift before your auditor does.

Stop reading dashboards.
Start asking questions.

StratSecure connects every layer of your environment into a single continuously operating compliance posture — with an AI analyst available at any moment to explain findings, triage risks, and brief your team before an auditor does.

What you get
• Multi-cloud scanning (AWS / Azure / GCP)
• Linux & Windows agent compliance
• Docker host + Kubernetes + Swarm scanning
• AWS ECS & EKS container security
• CVE scanning + OSV enrichment
• Patch management with approval workflow
• File Integrity Monitoring + reference files
• Active Directory security analysis
• Centralized OS user management
• Evidence library + audit request tracking
• Slack / Teams / Webhook alerts
• AI security assistant + custom agents
• Unified risk scoring dashboard
• Multi-tenancy, RBAC, TOTP 2FA
• PDF / HTML / JSON / CSV reports
6 frameworks 360+ controls 5 container platforms Enterprise-ready