What's internet-facing and at risk, today
Public storage, APIs without auth, overly permissive IAM, exposed ports, and weak TLS across your connected cloud and API security tools. Distinct from vulnerability data (what's unpatched), this is about what's reachable.
Why it matters
S3 buckets, Blob containers, and GCS buckets that are anonymously readable, surfaced before an attacker or researcher does.
Endpoints missing an authorizer, plus shadow APIs discovered but not documented. Akto and Cloudflare API Security feed the list.
Wildcard principals, stale access keys, admin roles unused for 90+ days. The insider-risk signals auditors actually ask about.
Findings on assets you've labeled critical get a dedicated count. If the SSO gateway is exposed, that's a different conversation than a dev box.
How it works
Every exposure gets a type: public_storage, api_no_auth, shadow_api, exposed_service, overly_permissive_iam, weak_tls, exposed_secret, open_port. Type segmentation drives the conversation.
AWS Security Hub is the primary source today. Akto, Cloudflare API Security, and CrowdStrike Spotlight plug in through a shared writer, same upsert semantics, same stale cleanup, same stats refresh.
Findings resolve to cmdb_assets when the scanner hostname or ARN matches. Team ownership inherits from the linked asset, so platform/cloud exposures route to Platform and API gaps route to AppSec.
Stale-row cleanup marks anything not seen in the latest sync as mitigated. Aging buckets surface exposures sitting past 90 days, the ones that slipped through.
Get started today
Whether you're the security lead holding it together in-house without a CISO, or a vCISO, consultant, or MSSP running client programs, Radius360 turns your stack into decisions your board and auditors trust.

We use strictly necessary cookies to make Radius360 work. With your consent, we'd also like to use analytics cookies to understand how visitors use our site so we can improve it. You can change your choice anytime. See our Privacy Policy.