

Security execution, under your command.
Moonfort is an agentic security workforce that investigates risks, builds fixes, and enforces guardrails across your cloud. Give your team more capacity to execute, with permissions and approvals under your control.
Resolve the risks that keep your team chasing.
ChaseOps is the cycle of alerts, handoffs, and repeat findings that leaves little time to fix the underlying cause. Moonfort investigates the risk, prepares the remediation, and turns what it learns into preventive controls.
Moonfort compares granted permissions with runtime activity and application source to identify access an identity does not need.
It proposes scoped permission changes with supporting evidence, then follows your approval requirements before applying them.
Moonfort evaluates scanner findings against your architecture, checks whether an exposure is reachable, and identifies its root cause and owner.
It prepares the fix and creates a ticket with the evidence and responsible owner, so your team can move from prioritization to remediation.
Moonfort translates security requirements into controls across cloud accounts and delivery pipelines, using IAM policies, Terraform, SCPs, and the checks you already run.
Choose audit or enforcement for each control. Pipeline checks flag misconfigurations during code review, helping prevent the same issue from reaching production.
Moonfort prepares preventive controls for attack paths identified in your environment, using security engineering methods informed by incident response.
Controls can restrict reconnaissance, permission discovery, and access from anonymizing VPNs. Each is scoped to the relevant exposure and your approved boundaries.
When a security control blocks work, Moonfort contacts the affected engineer in Slack or Teams to understand the intended change.
It uses your internal documentation and environment context to propose a secure alternative, helping the engineer proceed without bypassing the control.
Moonfort can ask an engineer to confirm suspicious activity associated with a blocked action.
If the engineer does not recognize the activity, Moonfort escalates to your SOC with the event sequence and the engineer's response for further investigation.
Moonfort gathers evidence around cloud alerts from your existing detection tools, checking the activity against the surrounding environment.
It provides a true-positive or false-positive assessment with its reasoning, giving analysts the context they need to decide what happens next.
Moonfort investigates the exposures and misconfigurations behind recurring alerts, then prepares changes that address those underlying conditions.
Preventive controls help keep the same issues from returning, reducing repeat investigation work for your SOC.
Moonfort brings new accounts, subscriptions, and projects into its security workflows when they fall within the scope your team has authorized.
It assesses exposures and applies the relevant guardrails through your chosen approval process, extending coverage as your cloud grows.
Moonfort carries out ongoing cloud security engineering through your own accounts, repositories, and control workflows.
Knowledge of your environment and past decisions stays with the workforce, giving your engineers a consistent foundation for each investigation and change.
Moonfort checks exposed ports, vulnerable services, workload permissions, and asset ownership to establish which findings are reachable from the internet.
It prepares the remediation and can propose a scoped WAF rule while a patch is underway. Each proposed change follows your permissions and approval requirements.
Security engineering for your industry.
Apply investigation, remediation, and preventive controls to the cloud systems your business depends on. Moonfort uses your architecture and operating requirements to guide the work.
Financial Services
Reduce unnecessary access to sensitive financial systems. Moonfort checks identity permissions against actual usage, prepares scoped changes, and proposes guardrails to prevent excessive access from being granted again. Your team reviews the evidence and expected impact through its approved workflow.
Telecommunications
Extend security coverage as cloud accounts and projects multiply. Moonfort assesses reachable exposures across authorized environments and prepares the relevant fixes and guardrails. New accounts enter the same workflow, helping your engineers maintain consistent controls as infrastructure grows.
Manufacturing and Automotive
Secure the cloud services behind connected vehicles, telematics, and charging infrastructure. Moonfort investigates exposures in those environments and builds controls into your accounts and Terraform workflows. Security context stays available as systems evolve, so each change benefits from the work before it.
Technology and SaaS
Keep security requirements connected to the way developers ship. Moonfort builds checks into cloud and CI/CD workflows, then helps engineers resolve blocked changes in Slack or Teams. Guidance draws on your documentation and architecture to offer a secure route forward.
Aviation and Transportation
Cover the cloud services behind booking, loyalty, and business operations. Moonfort investigates findings against your architecture, identifies the responsible owner, and prepares remediation with supporting evidence. Your engineers can direct more work across the environment while retaining control over changes.
Healthcare
Review cloud access to sensitive health information with evidence. Moonfort compares granted permissions with actual use and prepares changes for your team's approval process. The reasoning and expected impact support security decisions alongside the operational requirements of the environment.
One fleet runs all 6 stages, so the work stops changing hands.
Surface, investigate, remediate, prevent, enforce, and guide, across your cloud, your pipelines, and your identities, through the control planes you already own.

Specialist agents. Shared security context.
Moonfort combines security engineering playbooks with knowledge of your environment, policies, and past decisions. Agents carry that context from investigation through remediation and prevention, getting sharper with every workflow.







Surface Gaps
Everything you run
Continuously scan authorized environments and consolidate findings from existing tools. Keep cloud accounts, repositories, and pipelines in view as infrastructure changes.
- Connects to your cloud accounts, pipelines, and repositories
- Ingests from the scanners you already own
- Resolves each asset to what it can reach and the identity attached to it
- Re-scans on change, so new infrastructure is in scope the day it ships
Investigate Risks
Signal from the noise
Assess reachability, root cause, asset ownership, and the likely impact of a fix. Give your team the evidence it needs to set priorities.
- Proves the vulnerable path is reachable and executes, read-only
- Establishes blast radius from the identity attached to the asset
- Confirms the finding against runtime logs and application source
- Identifies the owner and opens the ticket to them
Fix Issues
Fixed end to end
Build the code or configuration needed to address the root cause. Check expected production impact and carry the change through your approved workflow.
- Produces the artefact: the WAF rule, the IAM policy, the SCP, the Terraform
- Checks production impact against runtime behaviour before proposing
- Opens the pull request and the ticket with reasoning and evidence attached
- Deploys on your green light, or hands you the change to apply
Prevent Attacks
Stopped in real time
Prepare targeted controls to limit exploitation while permanent remediation is underway. Apply them only within the scope and permissions your team has set.
- Denies anonymising VPN sources, reconnaissance, and secrets enumeration
- Contains the session on cross-role assumption outside the normal pattern
- Built on how threat actors operate, from years of incident response
- Scoped to one proven exposure, so the control stays narrow and reversible
Enforce Guardrails
Guardrails everywhere
Turn findings into reusable cloud and CI/CD controls. Use your existing policy formats and choose where to audit or enforce.
- Converts a closed finding into a guardrail that blocks the class at source
- Enforces the same rule across every account and every pipeline
- Runs in audit before it blocks, so you see the impact first
- Writes in your own policy artefacts: SCPs, RCPs, IAM boundaries
Guide Teams
Secure and fast
Help developers, IT, and DevOps resolve security blocks in Slack or Teams. Explain the control and propose an alternative that fits your environment.
- Opens a Slack or Teams thread within seconds of the block
- Reads your Confluence and Jira, so the alternative fits your stack
- Returns the working steps, so the engineer ships the same day
One fleet takes security from thousands of findings to lasting prevention. It investigates every issue, fixes what matters, protects the environment while the fix is underway, enforces the lesson everywhere, and guides teams forward.
Works where your team works.
Direct Moonfort in Slack or Microsoft Teams, with ServiceNow supporting your existing workflows. Request an investigation, review a proposed change, or ask for the evidence behind a recommendation.






Review a risk
Ask which findings are reachable and why they matter. Moonfort brings together the root cause, asset owner, and supporting evidence.
Approve a change
Review the proposed fix and expected production impact. Approve execution within scope, request a revision, or have your team implement it.

Set a guardrail
Describe the security requirement. Moonfort prepares the relevant cloud policy or pipeline check for your review and chosen enforcement mode.
Moonfort keeps working within its authorized scope and brings decisions to your team when input is needed.
Security execution and knowledge are fragmented across tools, teams, and individuals.
When a risk spans tools and teams, context must be rebuilt, priorities revisited, and the response manually coordinated. As the environment grows, so does this operational burden.
Security execution and knowledge are fragmented across tools, teams, and individuals.
When a risk spans tools and teams, context must be rebuilt, priorities revisited, and the response manually coordinated. As the environment grows, so does this operational burden.
Evaluate Moonfort for your team.
10 questions, each answered in full.
- What does an agentic security workforce do?+
Moonfort's specialist agents perform security engineering work: investigating findings, identifying root causes, preparing fixes, and enforcing approved controls. They share context about your environment and bring decisions to your team with supporting evidence. Your engineers direct the work and set its boundaries.
- Which capabilities are available today?+
Moonfort's current depth is in cloud security engineering, vulnerability management, and exposure management. It also supports selected cloud alert-triage and threat-intelligence workflows. Broader phishing, endpoint investigation, and containment capabilities are in development.
- How does Moonfort work with our existing tools?+
Moonfort scans authorized environments and uses findings from your existing CSPM, CNAPP, and other security tools. It turns those findings into investigations, proposed changes, and preventive controls through your existing cloud and engineering workflows.
- Can Moonfort change our production environment?+
Yes, when your team authorizes it. Moonfort can prepare pull requests, IAM changes, SCPs, WAF rules, and other configuration changes. You can permit execution within defined boundaries, require approval for each action, or keep Moonfort read-only and implement changes manually.
- How do we control permissions and approvals?+
Your team defines what Moonfort can access, which actions it can take, and when approval is required. Before deciding on a proposed action, you can review its reasoning, supporting evidence, root cause, and expected production impact.
- How does the workforce learn our environment?+
Moonfort combines security engineering methods with context from your connected environment, internal documentation, and past decisions. Agents retain and share that context across workflows, so later investigations and changes build on what the workforce has already learned.
- How does Moonfort help prevent recurring issues?+
Moonfort uses findings and their root causes to build controls in your cloud accounts and CI/CD pipelines. These controls help prevent the same misconfiguration from being introduced again. Where appropriate and authorized, it can also apply targeted protection while a permanent fix is underway.
- What remains with our security engineers?+
Your engineers retain strategy, judgment, and ownership of the security program. They set priorities and operating boundaries, review decisions, and choose how changes are executed. Moonfort adds capacity for investigation, remediation, and enforcement so the team can direct more work.
- How does Moonfort help engineers resolve security blocks?+
Moonfort can contact the affected engineer in Slack or Teams, explain why the action was blocked, and ask what they need to accomplish. It uses your environment and internal documentation to propose a secure alternative that respects the control.
- Which environments does Moonfort support?+
Moonfort's current work centers on AWS, Azure, and Google Cloud. Coverage is expanding into on-premises, SaaS, and hybrid environments. During evaluation, confirm the scope and integrations required for your environment.
Put Moonfort to work.
Explore how Moonfort investigates a risk, prepares a fix, and works within your controls. Start with the security work your team needs to move forward.