Back to Blog
July 28th, 2026

Announcing LimaCharlie Cloud Security: a CNAPP built on the detection and response engine you already run

Picture of Christopher Luft
Christopher Luft

Co-founder and COO

blog post header image

When a cloud security tool finds an over-permissioned identity, the finding goes into a dashboard. When your EDR sees that same identity's credential used on an endpoint, that goes into a different system. Connecting the two is your job, and it usually costs you an export pipeline, a pile of webhooks, and a SOAR license.

For service providers the problem compounds: cloud security platforms are priced for the end enterprise, sold in opaque billing units, and carry entry floors that make a resellable midmarket offering nearly impossible to build. Analyst commentary has been blunt about the result, describing CNAPP pricing that has ballooned past what most teams can absorb.

LimaCharlie Cloud Security, generally available July 28, takes a different starting point. It is a cloud-native application protection platform built directly in LimaCharlie, which means every finding it produces is a native event in the same detection and response engine that already runs endpoint fleets, ingests telemetry, and executes response for security teams and MSSPs around the world. There is no separate detection SKU and no integration project. The rules, outputs, and automation you already operate work on cloud findings from day one.

Cloud Security is already running in customer environments today, and we intend to keep building it the way we built everything else: in the open, with the people who operate it.

What ships today

LimaCharlie Cloud Security covers the four CNAPP pillars across GCP, AWS, and Azure, and gives you:

  • Cloud posture management with rules written as real detections. Every posture rule is readable, forkable, and editable, with per-rule evidence and remediation guidance. Nothing is a black box.

  • Identity and entitlement analysis built as a full identity graph, with access classified by actual capability rather than role bindings, and non-human and AI-agent identities modeled as first-class node types.

  • Attack-path analysis that chains exposure, exploited-in-the-wild vulnerabilities, identity relationships, and sensitive data into single paths with blast radius attached, so one pivot closes an entire path rather than one finding at a time.

  • AI security posture management including AI service inventory, posture rules for AI workloads, attack paths for publicly exposed AI endpoints, and OWASP LLM and NIST AI RMF catalogs out of the box.

Vulnerability findings arrive with CVSS, EPSS, and CISA KEV enrichment, consistent with how Vulnerability Reporting already works across LimaCharlie EDR fleets.

Findings are events

The architectural decision that separates Cloud Security from the rest of the category is simple to state. Every CNAPP on the market has an API you can use to read its findings. In LimaCharlie, findings do not sit behind an API waiting to be read. They land in your tenant's event stream the moment they are produced, alongside endpoint telemetry and every other source you ingest.

That means a cloud misconfiguration can trigger the same detection logic, routing, and automation as a process event on an endpoint. You can write one rule that watches for a high-risk cloud finding, correlates it with activity you are seeing elsewhere in the environment, and routes the result to a case, a channel, or a downstream system. Detection is not an add-on to posture. It is the substrate the posture engine is built on.

For teams that practice detection-as-code, this is the CNAPP that speaks your language natively. For everyone else, it means one system where the category norm is three.

Built for service providers from the first commit

Cloud Security inherits LimaCharlie's multi-tenant architecture rather than adding tenancy as a feature. Each client's cloud findings land in that client's own event stream, managed through the same APIs and infrastructure-as-code workflows MSSPs already use to run endpoint operations across hundreds of tenants.

This matters because no incumbent CNAPP has an economic model a service provider can resell at midmarket price points. Cloud Security is priced the way everything in LimaCharlie is priced: transparently, and in the open. It is $150 per organization per month, published for everyone rather than quoted per deal, and every organization can start with a free 14-day trial covering up to two cloud providers. Across a category where visible entry floors start at $7,000 a month and most vendors will not publish a price at all, that is the difference between cloud security as a quoting exercise and cloud security as a line item an MSSP can put on every proposal.

"Service providers have been asking us for years why cloud security is the one category they cannot build a practice on. The answer was always economics, not technology. Cloud Security is built on the same multi-tenant infrastructure our MSSPs already run their operations on, and it is priced so they can actually sell it." Maxime Lamothe-Brassard, co-founder and CEO, LimaCharlie

Getting started with LimaCharlie Cloud Security

  1. Sign up through the dedicated Cloud Security onboarding and start your 14-day trial

  2. Connect to your provider

  3. Findings begin arriving as events; your existing rules and outputs apply immediately

  4. Explore the identity graph and attack paths from your dashboard

LimaCharlie will be at Black Hat USA, Booth 5917, August 4 through 6, with live demos and the Build a Headless SOC workshop on August 5.

This is cloud security as infrastructure, not as a six-figure appliance. As you put it to work, we would value your read on what to build next to make this the CNAPP your team actually wants to operate.