Skip to content
About

Built because nobody could answer a simple question.

Can this server reach that database? On a multi-provider estate, answering it honestly means reading four consoles, resolving nested groups by hand, and reasoning about NAT on a whiteboard.

The mission

Network security policy has become the largest body of undocumented, unowned configuration in most organizations. It accumulates across a decade, across vendors, across people who have left, and nobody can say with confidence what it permits today.

Cloud Patrol exists to make that body of configuration legible. Not summarized, not scored by a model, but actually resolved and answerable, with the evidence attached so an engineer can disagree with it and check.

The bet is that determinism is a feature. Security teams do not need another tool with an opinion. They need one that can show its work.

  • No model decides access

    Policy evaluation is deterministic code. A language model may narrate a result the engine produced; it never produces one. If a vendor cannot tell you which is which, assume the worse case.

  • Uncertainty is an answer

    When a control on the path cannot be evaluated, the verdict says so. The alternative is a confident answer resting on a gap, which is the failure mode that gets people breached.

  • Evidence or it did not happen

    Every verdict names the control, the rule, the result, the reason, and the raw configuration it came from. A number you cannot check is not a finding, it is an assertion.

  • Under-report rather than invent

    Where the analysis has limits, it misses findings instead of manufacturing them. A false finding costs an operator a rule that was doing work, and costs us their trust.

The team

Cloud Patrol is built by a small engineering team with a background in network security and infrastructure. Rather than list invented executives and stock headshots, this section stays empty until there are real people to name.

If you want to know who you would be working with, ask on the demo call and you will meet them directly.

Come and try to break it.

The most useful conversations we have are with engineers who arrive sceptical and bring a rulebase they think will confuse it.