
Security execution, under your command.
Moonfort is an agentic security workforce that investigates risks, builds fixes, and enforces guardrails across your cloud. Give your team more capacity to execute, with permissions and approvals under your control.

Resolve the risks that keep your team chasing.
ChaseOps is the cycle of alerts, handoffs, and repeat findings that leaves little time to fix the underlying cause. Moonfort investigates the risk, prepares the remediation, and turns what it learns into preventive controls.
Work happens through your cloud accounts, repositories, and ticketing workflows. Review proposed changes with their evidence and expected impact. You choose whether Moonfort executes within agreed boundaries, requests approval for each action, or remains read-only.

Excess identity permissions
Moonfort compares granted permissions with runtime activity and application source to identify access an identity does not need.

Excess identity permissions
Moonfort compares granted permissions with runtime activity and application source to identify access an identity does not need.
It proposes scoped permission changes with supporting evidence, then follows your approval requirements before applying them.

Vulnerability and exposure backlog
Moonfort evaluates scanner findings against your architecture, checks whether an exposure is reachable, and identifies its root cause and owner.
It prepares the fix and creates a ticket with the evidence and responsible owner, so your team can move from prioritization to remediation.

Cloud and CI/CD guardrails
Moonfort translates security requirements into controls across cloud accounts and delivery pipelines, using IAM policies, Terraform, SCPs, and the checks you already run.
Choose audit or enforcement for each control. Pipeline checks flag misconfigurations during code review, helping prevent the same issue from reaching production.

Attack path prevention
Moonfort prepares preventive controls for attack paths identified in your environment, using security engineering methods informed by incident response.
Controls can restrict reconnaissance, permission discovery, and access from anonymizing VPNs. Each is scoped to the relevant exposure and your approved boundaries.

Developer guidance
When a security control blocks work, Moonfort contacts the affected engineer in Slack or Teams to understand the intended change.
It uses your internal documentation and environment context to propose a secure alternative, helping the engineer proceed without bypassing the control.

Account takeover investigation
Moonfort can ask an engineer to confirm suspicious activity associated with a blocked action.
If the engineer does not recognize the activity, Moonfort escalates to your SOC with the event sequence and the engineer's response for further investigation.

Cloud alert investigation
Moonfort gathers evidence around cloud alerts from your existing detection tools, checking the activity against the surrounding environment.
It provides a true-positive or false-positive assessment with its reasoning, giving analysts the context they need to decide what happens next.

Recurring SOC alerts
Moonfort investigates the exposures and misconfigurations behind recurring alerts, then prepares changes that address those underlying conditions.
Preventive controls help keep the same issues from returning, reducing repeat investigation work for your SOC.

New cloud accounts
Moonfort brings new accounts, subscriptions, and projects into its security workflows when they fall within the scope your team has authorized.
It assesses exposures and applies the relevant guardrails through your chosen approval process, extending coverage as your cloud grows.

Ongoing cloud security engineering
Moonfort carries out ongoing cloud security engineering through your own accounts, repositories, and control workflows.
Knowledge of your environment and past decisions stays with the workforce, giving your engineers a consistent foundation for each investigation and change.

Internet-exposed workloads
Moonfort checks exposed ports, vulnerable services, workload permissions, and asset ownership to establish which findings are reachable from the internet.
It prepares the remediation and can propose a scoped WAF rule while a patch is underway. Each proposed change follows your permissions and approval requirements.
Security engineering for your industry.
Apply investigation, remediation, and preventive controls to the cloud systems your business depends on. Moonfort uses your architecture and operating requirements to guide the work.
Financial Services
Reduce unnecessary access to sensitive financial systems. Moonfort checks identity permissions against actual usage, prepares scoped changes, and proposes guardrails to prevent excessive access from being granted again. Your team reviews the evidence and expected impact through its approved workflow.
Telecommunications
Extend security coverage as cloud accounts and projects multiply. Moonfort assesses reachable exposures across authorized environments and prepares the relevant fixes and guardrails. New accounts enter the same workflow, helping your engineers maintain consistent controls as infrastructure grows.
Manufacturing and Automotive
Secure the cloud services behind connected vehicles, telematics, and charging infrastructure. Moonfort investigates exposures in those environments and builds controls into your accounts and Terraform workflows. Security context stays available as systems evolve, so each change benefits from the work before it.
Technology and SaaS
Keep security requirements connected to the way developers ship. Moonfort builds checks into cloud and CI/CD workflows, then helps engineers resolve blocked changes in Slack or Teams. Guidance draws on your documentation and architecture to offer a secure route forward.
Aviation and Transportation
Cover the cloud services behind booking, loyalty, and business operations. Moonfort investigates findings against your architecture, identifies the responsible owner, and prepares remediation with supporting evidence. Your engineers can direct more work across the environment while retaining control over changes.
Healthcare
Review cloud access to sensitive health information with evidence. Moonfort compares granted permissions with actual use and prepares changes for your team's approval process. The reasoning and expected impact support security decisions alongside the operational requirements of the environment.
Specialist agents. Shared security context.
Moonfort combines security engineering playbooks with knowledge of your environment, policies, and past decisions. Agents carry that context from investigation through remediation and prevention, getting sharper with every workflow.
Surface Gaps
You set the strategy. Moonfort runs the mission.
Your engineers define the objectives and rules. Moonfort carries out the operational work within them.
Your team
Strategy and control
Set priorities, permissions, and approval requirements. Authorize execution within defined limits, review each proposed change, or keep Moonfort read-only. Request the reasoning, evidence, and expected production impact before deciding.
- Set priorities
- Review evidence
- Approve changes







Moonfort
Agentic security workforce
Investigate findings, prepare fixes, and enforce approved controls. Agents use shared knowledge of your environment to coordinate the work and inform future decisions. Your team gains execution capacity while retaining ownership of the security program.
- Investigate risks
- Prepare fixes
- Enforce guardrails
Define boundaries
Review decisions
Works where your team works.
Direct Moonfort in Slack or Microsoft Teams, with ServiceNow supporting your existing workflows. Request an investigation, review a proposed change, or ask for the evidence behind a recommendation.
Review a risk
Ask which findings are reachable and why they matter. Moonfort brings together the root cause, asset owner, and supporting evidence.
Approve a change
Review the proposed fix and expected production impact. Approve execution within scope, request a revision, or have your team implement it.

Set a guardrail
Describe the security requirement. Moonfort prepares the relevant cloud policy or pipeline check for your review and chosen enforcement mode.
Moonfort keeps working within its authorized scope and brings decisions to your team when input is needed.
Evaluate Moonfort for your team.
What does an agentic security workforce do?
Moonfort's specialist agents perform security engineering work: investigating findings, identifying root causes, preparing fixes, and enforcing approved controls. They share context about your environment and bring decisions to your team with supporting evidence. Your engineers direct the work and set its boundaries.
Which capabilities are available today?
Moonfort's current depth is in cloud security engineering, vulnerability management, and exposure management. It also supports selected cloud alert-triage and threat-intelligence workflows. Broader phishing, endpoint investigation, and containment capabilities are in development.
How does Moonfort work with our existing tools?
Moonfort scans authorized environments and uses findings from your existing CSPM, CNAPP, and other security tools. It turns those findings into investigations, proposed changes, and preventive controls through your existing cloud and engineering workflows.
Can Moonfort change our production environment?
Yes, when your team authorizes it. Moonfort can prepare pull requests, IAM changes, SCPs, WAF rules, and other configuration changes. You can permit execution within defined boundaries, require approval for each action, or keep Moonfort read-only and implement changes manually.
How do we control permissions and approvals?
Your team defines what Moonfort can access, which actions it can take, and when approval is required. Before deciding on a proposed action, you can review its reasoning, supporting evidence, root cause, and expected production impact.
How does the workforce learn our environment?
Moonfort combines security engineering methods with context from your connected environment, internal documentation, and past decisions. Agents retain and share that context across workflows, so later investigations and changes build on what the workforce has already learned.
How does Moonfort help prevent recurring issues?
Moonfort uses findings and their root causes to build controls in your cloud accounts and CI/CD pipelines. These controls help prevent the same misconfiguration from being introduced again. Where appropriate and authorized, it can also apply targeted protection while a permanent fix is underway.
What remains with our security engineers?
Your engineers retain strategy, judgment, and ownership of the security program. They set priorities and operating boundaries, review decisions, and choose how changes are executed. Moonfort adds capacity for investigation, remediation, and enforcement so the team can direct more work.
How does Moonfort help engineers resolve security blocks?
Moonfort can contact the affected engineer in Slack or Teams, explain why the action was blocked, and ask what they need to accomplish. It uses your environment and internal documentation to propose a secure alternative that respects the control.
Which environments does Moonfort support?
Moonfort's current work centers on AWS, Azure, and Google Cloud. Coverage is expanding into on-premises, SaaS, and hybrid environments. During evaluation, confirm the scope and integrations required for your environment.

Put Moonfort to work.
Explore how Moonfort investigates a risk, prepares a fix, and works within your controls. Start with the security work your team needs to move forward.