Cloud security has spent years controlling what can get in. What about what gets out?

Most teams know what is exposed in their cloud, but struggle to answer a simple question: where are our workloads actually connecting out to?
‍
CloudFence gives you visibility and control over workload communications without agents, firewall VMs or forcing traffic through an inspection point.

CloudFence fills a unique gap in cloud security. Getting real visibility into cloud network communications has always been difficult. CloudFence gives us that visibility, while also learning the normal behavior of each workload so we can detect when something changes. They combine that with identity behavior monitoring which is especially relevant as AI workloads become more prevalent.

Brendan P.
Director of DevSecOps, Customer Engagement Technology company
The GAP

You controlled the way in. But threats don't always come through the front door.

With supply-chain attacks and compromised identities, threats don’t always require an exposed inbound path. What matters is knowing when a workload starts behaving differently and connecting to destinations it never has before.
‍
CSPM and CNAPP find exposure and misconfigurations, but don't establish how each workload normally communicates.
Traditional firewalls provide control, but require traffic redirection and added infrastructure, while still lacking the cloud context to know whether a workload’s communication is expected.

CloudFence takes a different approach.

How it works

No agents. No firewalls.
We use the cloud logs you already have.

Step #1

One read-only role. No traffic changes

CloudFence connects to your existing cloud network, DNS and identity logs through a read-only role - without changing how your traffic flows.
Step #2

Know every workload by its behavior

CloudFence turns the raw logs into a behavioral footprint for each workload: who it communicates with, where it connects, the path it takes, and what its identity normally does.
Step #3

Know the moment something changes

New destination. New communication path. New IAM action. CloudFence detects each change against what's normal for that workload in your environment.
SMARTER DETECTION

Less noise. More context around what changed

CloudFence evaluates changes against the context around them: the destination's reputation and category, whether it appears across other workloads, the workload's history, and related network and identity activity, to surface only the changes that deserve attention.

What teams are uncovering with CloudFence
AI workloads were connecting to destinations the team wasn't aware of

A large healthcare company with a significant cloud footprint across AWS and GCP wanted to understand where its cloud-deployed LLM workloads were communicating. CloudFence surfaced outbound destinations the security team wasn't expecting and aware of.

Staging workloads started communicating with production

While baselining workload communications for an insurance company with ~800 workloads on AWS, CloudFence detected staging workloads unexpectedly communicating with production.

S3 traffic suddenly took a different path

At a customer running on AWS, workloads normally reached S3 through VPC endpoints. CloudFence detected when some started going through a NAT Gateway instead, the destination hadn't changed, but the path had.

Finding unused access across 8,000+ Security Group rules, automatically

A large technology company needed to understand actual usage across more than 8,000 Security Group rules in AWS and remove unused access.

CloudFence maps observed communications against the rules allowing them, and gave the DevSecops team the evidence and the confidence to remove unused rules without causing a single production outage.

‍

A workload was bypassing the expected security inspection path

A cybersecurity company running on Azure expected workload traffic to pass through its centralized inspection hub.CloudFence detected a workload connecting directly instead, revealing a communication path the security team wasn't expecting.

CloudFence gives us real-time visibility into our cloud network activity and consistently identifies unusual behavior early enough for us to act. Its IAM role behavior analysis also gives us clear insight into access patterns, helping us strengthen our overall security posture.

Nelson W.
Director of Cyber Security, Healthcare company

For years I've talked with people about using VPC flow logs to limit security groups to only used ports on workloads, and finally Mounira REMINI and CloudFence have done it. I suggest checking out their solution if you've got someone dedicated to network and/or identity security in the cloud, they've made things very actionable from a practitioner over categories point of view.

James Berthoty
Founder & Analyst, Latio Tech

With CloudFence, we finally have clear, real-time visibility into our cloud network traffic. It helps us baseline normal activity, spot anomalies early, and close critical blind spots — a vital layer in our cloud security strategy.

Pushpak K.
InfoSec & Cloud Security Manager, Healthcare company

CloudFence gives us a streamlined way to gain network visibility across VPCs and accounts and detect anomalies with added detection rules for what is outside the baseline.
The initial setup was incredibly easy, the CloudFence team assisted with onboarding, and we were up and running in a matter of minutes.

Bryan S.
CTO, MSSP company

CloudFence fills a unique gap in cloud security. Getting real visibility into cloud network communications has always been difficult. CloudFence gives us that visibility, while also learning the normal behavior of each workload so we can detect when something changes. They combine that with identity behavior monitoring which is especially relevant as AI workloads become more prevalent.

Brendan P.
Director of DevSecOps, Customer Engagement Technology company

Want to know where your workloads are connecting?

Move beyond static rules and legacy network appliances in the cloud. Visualize workload communications, control egress traffic, detect behavioral deviations, and remove unused access - all  natively from your cloud logs