Radius360 by BlueRadius
Radius360by BlueRadius

What's internet-facing and at risk, today

Attack Surface

Public storage, APIs without auth, overly permissive IAM, exposed ports, and weak TLS across your connected cloud and API security tools. Distinct from vulnerability data (what's unpatched), this is about what's reachable.

Why it matters

Built for outcomes, not checkboxes

Pulled from AWS Security Hub

Public Storage Visibility

S3 buckets, Blob containers, and GCS buckets that are anonymously readable, surfaced before an attacker or researcher does.

API auth gaps

APIs Without Auth

Endpoints missing an authorizer, plus shadow APIs discovered but not documented. Akto and Cloudflare API Security feed the list.

IAM hygiene

Overly Permissive IAM

Wildcard principals, stale access keys, admin roles unused for 90+ days. The insider-risk signals auditors actually ask about.

Severity × criticality

Exposure on Critical Assets

Findings on assets you've labeled critical get a dedicated count. If the SSO gateway is exposed, that's a different conversation than a dev box.

How it works

Everything in one place, nothing to bolt on

Eight-Type Taxonomy

Every exposure gets a type: public_storage, api_no_auth, shadow_api, exposed_service, overly_permissive_iam, weak_tls, exposed_secret, open_port. Type segmentation drives the conversation.

  • Public storage with flags for public_read and encryption_missing
  • API auth gaps (no_api_auth flag) and shadow API discovery
  • Overly permissive IAM (wildcard_principal flag)
  • Open ports with CIDR-based flags (cidr_0.0.0.0/0 for internet exposure)
  • Weak TLS, exposed secrets, and uncategorized exposures

Source Coverage

AWS Security Hub is the primary source today. Akto, Cloudflare API Security, and CrowdStrike Spotlight plug in through a shared writer, same upsert semantics, same stale cleanup, same stats refresh.

  • AWS Security Hub, public buckets, IAM, security groups, resources
  • Akto, API security issues (OWASP API Top 10 class)
  • Cloudflare API Security, exposed / discovered APIs, schema validation
  • CrowdStrike Spotlight, internet-facing endpoints with known CVEs

Asset-Linked Exposure

Findings resolve to cmdb_assets when the scanner hostname or ARN matches. Team ownership inherits from the linked asset, so platform/cloud exposures route to Platform and API gaps route to AppSec.

  • Best-effort asset linking by hostname, IP, or ARN
  • Team inheritance via cmdb_assets.team_id
  • Critical-asset flag call-out on the exec strip
  • Per-asset drill-in when the finding matches

Aging and Auto-Mitigation

Stale-row cleanup marks anything not seen in the latest sync as mitigated. Aging buckets surface exposures sitting past 90 days, the ones that slipped through.

  • Mark-missing-as-mitigated on each sync
  • Aging buckets: >90d / 30-90d / <30d
  • Resolved-last-30-days counter for trend
  • Resolution happens in the source console; the next sync auto-closes here

Get started today

Run your security program, not just your tools

Whether you're the security lead holding it together in-house without a CISO, or a vCISO, consultant, or MSSP running client programs, Radius360 turns your stack into decisions your board and auditors trust.

7-day free trial included
No credit card required
Radius360

We use cookies

We use strictly necessary cookies to make Radius360 work. With your consent, we'd also like to use analytics cookies to understand how visitors use our site so we can improve it. You can change your choice anytime. See our Privacy Policy.