
Co-founder and COO

July was the month LimaCharlie became a cloud security platform. On July 28 we launched LimaCharlie Cloud Security, a full CNAPP built on the detection and response engine you already run, and the web app crossed to 6.0 to carry it. Around that launch, three more web app releases (5.12.0, 5.13.0, 5.14.0) and four sensor releases (5.3.1 through 5.3.4) landed: the console went multilingual, vulnerability management matured into a full reporting workflow, and the sensor picked up TLS 1.3 and cloud-driven lifecycle management.
This is the largest single expansion of the platform we have ever shipped. LimaCharlie Cloud Security is a CNAPP that lives inside the same detection and response engine as everything else — no separate tool, no integration project, no six-figure opaque quote. It covers the four CNAPP pillars:
Cloud posture management with readable, editable detection rules, per-rule evidence, and remediation guidance.
Identity analysis with a full identity graph where access is classified by actual capability — and AI agents are first-class node types.
Attack-path analysis that chains vulnerabilities, identity relationships, and sensitive data into single paths with blast-radius assessment.
AI security, including an AI service inventory, posture rules for AI workloads, and OWASP LLM / NIST AI RMF catalogs.
Because findings arrive enriched with CVSS, EPSS, and CISA KEV data and land in your tenant’s event stream as native events, the same rules, outputs, and automation you use for endpoints apply to your cloud estate on day one — and MSSPs inherit the multi-tenant architecture for managing findings across hundreds of clients. Pricing is transparent: $150 per organization per month, with a free 14-day trial covering up to two cloud providers.
The console side of the launch shipped as web app 6.0.0 (with a 6.0.1 follow-up) — a major version bump that brings inventory, findings, the identity graph, and attack path exploration into the web app.
Web app 5.12.0 delivered full localization of the console and the Grid app in English, Español, and 日本語 — roughly 4,200 user-facing strings across 60 feature namespaces, with a Language Switcher in User Settings that persists per device. The work continued through the month: 5.13.0 and 5.14.0 localized the extension catalog (Artifact, binlib, reliable-tasking, EPP, exfil, atomic-red-team, hayabusa, and dozens more) across all nine supported locales. Adding future languages now requires only a new locale folder.
Vulnerability management got sustained attention across all three minor releases. The Sensor Vulnerabilities tab gained an Export report menu with five formats — PDF, HTML, Markdown, CSV, and Excel — each including a KPI summary strip, top remediation recommendations aggregated by package and fix version, and the full findings table. 5.13.0 added a Vulnerable Packages tab with a package drawer listing live affected hosts, a “Group by application” toggle that collapses per-CVE rows to one line per application, and a server-generated remediation-plan CSV. Per-host tables now show sortable First Detected and installed Version columns, marking the start of the remediation clock. The org-level dashboard was redesigned around a compact posture strip, and the CVE detail gained a cleaner CVSS metric card and an EPSS percentile meter.
The per-sensor experience was rebuilt across the month. Sensor Overview now uses a grouped-card layout — identity, network, and system details in distinct sections with inline status chips — and moves Seal and Isolate controls into the page header while preserving the full pending/cancel state machine. Sensor Analytics became a responsive card-grid dashboard with a single shared time-range selector, and the EPP status page was redesigned as a proper status dashboard. The sensor sub-page tables (Autoruns, Drivers, Packages, Users, Services, Processes, and more) migrated to the modern table component with sortable headers and truncation tooltips.
5.13.0 revamped the Platform Logs audit tab with sensor, date-range, and event-type filters, client-side origin and identity search, bidirectional infinite scroll, and a row detail panel with a scrollable JSON viewer of the raw record. The REST API section was redesigned around a compact definition card with hover-to-copy on API Root, OID, and Org JWT, with the three API key tables moved behind a segmented switcher.
5.14.0 transformed the flat ~120-row permission list into collapsible resource groups with per-group read and write bulk toggles — and privileged permissions like apikey.ctrl and billing.ctrl now require individual granting rather than riding along with a bulk select. The outputs listing moved to a modern sortable table with new Test Transform and Test Template modals for server-side testing of expressions against sample events before saving, and a WebSocket output destination is now creatable from the UI. Artifacts got the same Detections-style table treatment, and a new Org Overview page shows your organization as a high-level diagram.
While a paginated query runs, the query console status line now shows a live percent-scanned figure, with a hover tooltip breaking down batch, event, and data counts — and cancelled searches are correctly labelled “Cancelled” rather than “Complete!”. Search exports now offer two paths: “Visible columns” mirroring the table view, and “All fields” exporting every flattened field from every event so nested details are never silently dropped from spreadsheets.
Three adapters picked up meaningful new options. The Microsoft Defender adapter accepts an optional Endpoint field targeting Enterprise, GCC, GCC High (L4), or DoD (L5) cloud environments. The SentinelOne adapter gained site_ids and account_ids fields to scope ingestion to a single tenant of an MSP console, plus a collect_agents toggle that pulls all in-scope endpoints as sensors immediately rather than waiting for telemetry. The Entra ID adapter exposes an optional streams parameter for selecting risk detections, sign-ins, and audit logs.
The sensor shipped four releases this month. 5.3.1 introduced TLS 1.3 support for the sensor’s cloud connection (with automatic TLS 1.2 fallback), shell commands that run as a specific user rather than with sensor privileges, and configuration-driven USB Data Loss Prevention managed centrally from the cloud. 5.3.2 and 5.3.3 hardened the TLS work — fixing compatibility with SSL-inspection proxies, pinned-certificate trust, and RSA-PSS signature schemes — and added cloud tasking for sensor upgrade and uninstall, version pinning, and per-boot identifiers and MAC address reporting. 5.3.4 closed out the month with a recursive registry listing command, fixes for corrupted macOS kernel-acquisition process events, Windows Event Log collection that resumes where it left off after a restart, and a Windows MSI uninstall that fully removes sensor identity so reinstalls enroll fresh.
This is a small slice of what shipped in July. For the complete feature list and every bug fix across web app 5.12.0, 5.13.0, 5.14.0, and 6.0, read the full release notes on Docs.