An AI-powered cloud security vulnerability detection and remediation platform that scans, analyzes, and provides intelligent remediation guidance for Google Cloud Platform, Amazon Web Services, and Databricks environments.
- GCP: Cloud Storage buckets, IAM policies, BigQuery datasets, VPC networks, Compute Engine instances
- AWS: S3 buckets, IAM policies, EC2 instances, Security Groups, Security Hub integration
- Databricks: Unity Catalog governance, cluster security, workspace access, data access patterns
- Google Gemini Integration: Natural language security analysis and insights
- Intelligent Remediation: AI-generated step-by-step remediation instructions
- Risk Scoring: Automated risk assessment with 0-100 scoring
- Compliance Reporting: CIS benchmark compliance analysis
- Scheduled Scans: Daily, weekly, or monthly security assessments
- Real-time Alerts: Immediate notification of critical vulnerabilities
- Trend Analysis: Historical security posture tracking
- Executive Reporting: High-level summaries for leadership
- React Dashboard: Interactive security overview with charts and metrics
- Detailed Reports: Comprehensive technical and executive reports
- Finding Management: Track and resolve security issues
- Real-time Updates: Live scan progress and status updates
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
β React Frontend β β FastAPI Backend β β Airflow Schedulerβ
β β β β β β
β - Dashboard βββββΊβ - Security APIs βββββΊβ - Scheduled Scansβ
β - Reports β β - AI Analysis β β - Monitoring β
β - Findings β β - Cloud Scannersβ β - Notifications β
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
β β β
β β β
βΌ βΌ βΌ
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
β Cloud Run β β PostgreSQL β β Redis Cache β
β (Frontend) β β Database β β β
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
β
βΌ
βββββββββββββββββββ
β Cloud Storage β
β (Scan Data) β
βββββββββββββββββββ
- FastAPI: High-performance Python web framework
- PostgreSQL: Primary database for findings and reports
- Redis: Caching and session management
- SQLAlchemy: ORM for database operations
- Pydantic: Data validation and serialization
- React 18: Modern UI framework
- Material-UI: Component library and theming
- Recharts: Data visualization
- Axios: HTTP client for API communication
- Google Cloud Platform: Primary cloud provider
- Cloud Run: Serverless container platform
- Cloud SQL: Managed PostgreSQL database
- Artifact Registry: Container image storage
- Terraform: Infrastructure as Code
- Google Gemini: AI analysis and remediation generation
- Google Cloud Security Center: GCP security findings
- AWS Security Hub: AWS security findings
- Databricks APIs: Unity Catalog and workspace scanning
- Google Cloud Project with billing enabled
- Google Gemini API Key for AI features
- AWS Credentials (if scanning AWS resources)
- Databricks Token (if scanning Databricks workspaces)
- Docker for local development
- Terraform for infrastructure deployment
The simplest way to get started:
# Make the deployment script executable
chmod +x deploy.sh
# Deploy locally with Docker Compose
./deploy.sh --type docker-composeFor production deployments on Google Cloud Platform:
# Deploy to GCP (replace with your hosting project ID)
./deploy.sh --type terraform --project-id YOUR_HOSTING_PROJECT_ID --region us-central1If you prefer to run Docker Compose directly:
# Start all services
docker-compose -f infrastructure/docker/docker-compose.yml up -d
# View logs
docker-compose -f infrastructure/docker/docker-compose.yml logs -f
# Stop services
docker-compose -f infrastructure/docker/docker-compose.yml down
## π§ Local Development
### Backend Development
```bash
cd backend
python -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate
pip install -r requirements.txt
# Start PostgreSQL and Redis
docker-compose -f infrastructure/docker/docker-compose.yml up postgres redis -d
# Run the backend
python -m uvicorn app.main:app --reload --host 0.0.0.0 --port 8000cd frontend
npm install
npm startdocker-compose -f infrastructure/docker/docker-compose.yml up- Navigate to the Scans page
- Click "New Scan"
- Select cloud provider (GCP, AWS, Databricks)
- Enter project/account ID
- Start the scan
- View real-time scan status
- Monitor finding discovery
- Track completion progress
- Browse discovered vulnerabilities
- Filter by severity, type, or resource
- View detailed AI analysis
- Access remediation instructions
- Create executive summaries
- Generate technical reports
- Download PDF reports
- Schedule automated reporting
- Follow AI-generated steps
- Use provided Terraform configurations
- Execute CLI commands
- Mark findings as resolved
- GCP: Security Command Center, Cloud Asset Inventory, IAM Policy Intelligence
- AWS: Security Hub, IAM API, CloudTrail, Config API
- Databricks: Unity Catalog APIs, Clusters API, SCIM API
- Risk Assessment: Automated vulnerability scoring
- Remediation Generation: Step-by-step fix instructions
- Compliance Analysis: CIS benchmark evaluation
- Executive Insights: Business impact assessment
- Scheduled Scans: Configurable intervals (daily/weekly/monthly)
- Real-time Alerts: Critical vulnerability notifications
- Trend Analysis: Security posture tracking over time
- Compliance Reporting: Regular compliance status updates
- Health Checks: API and service health monitoring
- Scan Progress: Real-time scan status tracking
- Error Handling: Comprehensive error logging and reporting
- Slack: Security team notifications
- Email: Executive and technical alerts
- Webhooks: Custom integration endpoints
- Cloud Monitoring: GCP monitoring integration
# Database
DATABASE_URL=postgresql://user:password@host:port/database
REDIS_URL=redis://host:port
# Cloud Providers
GCP_PROJECT_ID=your-gcp-project
AWS_ACCESS_KEY_ID=your-aws-key
DATABRICKS_HOST=your-databricks-host
# AI Integration
GEMINI_API_KEY=your-gemini-key
# Application
SECRET_KEY=your-secret-key
DEBUG=False# Set scan configurations
airflow variables set scan_configs '[
{
"scan_name": "Production GCP Scan",
"provider": "gcp",
"project_id": "your-project-id",
"scan_config": {}
}
]'cd backend
pytest tests/ -vcd frontend
npm testdocker-compose -f infrastructure/docker/docker-compose.yml -f docker-compose.test.yml up --abort-on-container-exitPOST /api/v1/scans- Create new scanGET /api/v1/scans- List scansGET /api/v1/scans/{id}- Get scan detailsPOST /api/v1/scans/{id}/cancel- Cancel scan
GET /api/v1/findings- List findingsGET /api/v1/findings/{id}- Get finding detailsPUT /api/v1/findings/{id}- Update findingPOST /api/v1/findings/{id}/remediate- Apply remediation
POST /api/v1/reports- Generate reportGET /api/v1/reports- List reportsGET /api/v1/reports/{id}- Get report detailsGET /api/v1/reports/summary- Get security summary
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
This project is licensed under the MIT License - see the LICENSE file for details.
- Documentation: Wiki
- Issues: GitHub Issues
- Discussions: GitHub Discussions
- Email: security-team@company.com
- β Multi-cloud security scanning
- β AI-powered analysis and remediation
- β Web dashboard and reporting
- β Automated monitoring with Airflow
- π Advanced compliance frameworks (SOC 2, PCI DSS)
- π Custom security policies and rules
- π Integration with SIEM platforms
- π Mobile application
- π Multi-tenant architecture
- π Advanced threat detection
- π Security orchestration and automation
- π Machine learning-based anomaly detection
Built with β€οΈ by the Cloud Security Team