For DevSecOps
CIS benchmark compliance,built into the platform you run.
CISGuard scans Kubernetes clusters and container hosts alongside traditional infrastructure, forwards every drift event to your SIEM and webhooks, and exports SARIF that drops into your pipelines, so compliance evidence comes from the platform team without slowing it down.
- Kubernetes-nativeKubernetes, AKS, EKS and OpenShift benchmarks with the same agent as your hosts
- SIEM forwardingSyslog, CEF, JSON over HTTPS, Azure Log Analytics, Grafana Loki
- SARIF exportCoverage and results in the format CI/CD and code-scanning tools read
- Signed webhooksEvery drift event posted with an HMAC-SHA256 signature
The job to be done
What DevSecOpss actually need from compliance tooling.
DevSecOps teams are increasingly the front-line owners of compliance evidence, because the evidence comes from infrastructure they provision. The friction is that traditional compliance tooling assumes a long manual review cycle that does not fit modern delivery pace. CISGuard fits the platform instead: scheduled scans with blackout windows cover Kubernetes clusters, container hosts, cloud accounts and virtual machines with one agent and one set of benchmarks; every drift event is forwarded to the SIEM and webhook endpoints your operations team already watches; and results export as SARIF, JSON and CSV so they land in the pipelines and dashboards you already have. The compliance team gets continuous evidence. The platform team gets fast, structured feedback. Both stop treating each other as overhead.
What you get
What you get with CISGuard.
Kubernetes and container scanning
API-server scanning for Kubernetes, AKS, EKS and OpenShift, plus the Docker benchmark for container hosts. Cloud-native workloads scan with the same tooling as traditional infrastructure.
SIEM and webhook event forwarding
Every drift detection forwards over seven SIEM transports and HMAC-signed webhooks. Splunk, Microsoft Sentinel, QRadar and ArcSight accept the events natively.
Pipeline-ready exports
SARIF 2.1.0, JSON and CSV exports of framework coverage and control results, so evidence lands in the pipelines, dashboards and GRC tools you already run.
Scheduled scans with blackout windows
Cron-scheduled scans per benchmark, blackout ranges for change freezes and release periods, and on-demand scans whenever you need them.
Straight answers
Honest answers to common pushback.
- “Compliance scanning will slow our pipeline”
Scans run on their own schedule against live infrastructure. Exports land in the pipeline as SARIF without adding a build step.
- “Our infrastructure is ephemeral, traditional scanners can't keep up”
CISGuard scans on schedule and on demand, with per-scan evidence retained for audit history.
- “We use cloud-native and Kubernetes, not VMs”
The CIS Kubernetes, AKS, EKS, OpenShift and Docker benchmarks are first-class, not retrofitted.
- “Compliance teams want reports, we want machine-readable data”
CISGuard has both. Compliance gets framework coverage reports. Platform gets SARIF, JSON, CSV and signed webhooks.
Frequently asked
DevSecOps questions, answered directly.
How does CISGuard fit into a CI/CD pipeline?
CISGuard exports scan results and framework coverage as SARIF 2.1.0, the format GitHub, GitLab, Azure DevOps and code-scanning dashboards read natively, alongside JSON and CSV. Drift events are forwarded to your SIEM and to signed webhooks, so a pipeline or an automation can react to a regression the moment it is detected.
Does CISGuard cover Kubernetes and container workloads?
Yes. CISGuard implements the CIS Kubernetes Benchmark with API-server scanning using a bearer token and CA certificate, plus the AKS, EKS and OpenShift benchmarks and the Docker benchmark for container hosts. Clusters are assessed alongside Windows, Linux and cloud accounts in the same dashboard.
How does drift detection forward to our SIEM?
Every drift event (a configuration regression between scans) emits a structured event over syslog UDP, TCP or TLS, CEF, JSON over HTTPS, Azure Log Analytics or Grafana Loki, in parallel to every destination you enable. Splunk, Microsoft Sentinel, QRadar and ArcSight consume the events natively.
Can we schedule scans around change freezes?
Yes. Scan schedules are cron-based per benchmark, with blackout windows for change freezes and release periods when a schedule should be skipped. On-demand scans can be triggered at any time from the dashboard.
Will CISGuard work with our existing observability and ticketing tools?
Alerts route to email and to HMAC-signed webhooks, so any system that accepts an HTTP request, including ticketing and chat tools, can receive them. Failed deliveries are retried and kept with the failure reason so an operator can resend. The platform is designed to fit a modern platform-engineering stack, not to require its own tooling.
Ready for a DevSecOps-led executive briefing?
Our compliance engineers will walk through CISGuard calibrated to your role, your audit scope and your infrastructure.