Skip to content

Data & Cloud Security (dw-security)

The Data & Cloud Security agent unifies two jobs that usually live in two consoles: data security posture (DSPM) — discovering and classifying sensitive data such as PII, PHI, PCI, and secrets, and scoring the risk it carries — and cloud security posture (CSPM) — scanning for misconfiguration, public exposure, weak encryption, exposed secrets, and over-privileged identities.

What makes it an agent rather than another scanner is what happens after a finding. It ranks findings and routes each one to the agent that can act: remediation such as an access revocation goes to the Data Access & Governance agent, and active threats go to the Incidents agent. You ask a question in plain language; you get a ranked answer and a path to the fix.

  • Sensitive-data discovery and classification. Finds where PII, PHI, PCI data, and secrets live in your estate and classifies what it found.
  • Data risk scoring. Scores the risk each finding carries, so the queue starts with what matters rather than a flat list.
  • Cloud misconfiguration and public-exposure scanning. Checks posture for misconfiguration, public exposure, and weak encryption.
  • Exposed-secrets and over-privilege detection. Flags exposed secrets and over-privileged identities as posture findings.
  • Ranked findings, not raw dumps. Findings come back ordered by risk, in a form you can act on from your terminal.
  • Routing to the fix. Remediation routes to Data Access & Governance (for example, a revoke); active threats route to Incidents. The security agent hands off; the receiving agent’s governed write path applies.
  • AWS Security Hub backend. Cloud posture findings can be pulled from a connected AWS Security Hub — the one live posture backend wired today.

“Where does PII live in my estate, and which of it is highest risk?”

“Scan my cloud posture for public exposure and weak encryption, ranked by severity.”

“Are any identities over-privileged for the data they touch?”

“Take the top finding and route it — who fixes it, and what’s the proposed action?”

  • AWS Security Hub — the live backend for cloud posture findings.
  • Warehouses and catalogs — Snowflake, BigQuery, Databricks and the other catalog connectors give the swarm the estate context that findings are ranked and routed against.
  • Identity and alerting systems are covered in the connector catalog.

The agent starts in 🟡 Evaluation on built-in sample data — a realistic estate with plausible findings you can discover, rank, and route end to end before any credential exists. It earns 🟢 Connected per system through a passing live test. See Verify your setup.

  • What this agent is: agentic unification and routing of DSPM + CSPM findings. What it is not: a replacement for a dedicated scanner — we do not claim scan parity with tools like Wiz or BigID. If you run one of those, this agent complements it by putting findings where your agents already work.
  • It surfaces findings; it does not enforce in production. Fixes go through the receiving agent’s governed, approval-gated write path — the security agent itself never mutates your systems.
  • One live posture backend is wired today (AWS Security Hub). The other capabilities run on sample data until their systems are connected and verified.
  • Routing quality depends on which agents and systems are connected: a revoke can only be proposed where Data Access & Governance has a connected target.