Secure AI Agent · Cloud Posture

AI applied to your cloud configuration

A specialist configured to audit your environments' configuration, prioritize what represents real risk, and prepare remediation within your company's rules.

Companies that trust UPX

  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO

Capabilities

What the Cloud Posture Agent can do

Main areas of work for the Cloud Security Posture AI Agent in your operation.

Configuration audit

Compares current configuration with your company's security policy.

Public exposure

Identifies resources reachable from outside that should be restricted.

Broad permissions

Flags roles and policies more permissive than the function requires.

Real-risk prioritization

Orders findings considering exposure, sensitive data, and criticality.

Drift tracking

Flags when an environment moves away from the defined baseline.

Remediation plan

Prepares the step-by-step fix for the team to assess.

Skills

Capabilities that compose the specialist

Skills add specific capabilities to the Secure AI Agent according to the processes it needs to execute.

Configuration audit
Compares the environment's current state with the defined policy.
Exposure analysis
Identifies what is reachable from outside and should not be.
Remediation plan
Organizes the prioritized fix with a step-by-step.
How it works

From configuration to remediation plan, with review at every step

Connect your environments, define what the agent can do, and let the audit happen within your company's limits.

01

Connect your cloud environments
The agent works with read access.Connect AWS, Azure, Google Cloud, or Cloudflare with read permission so the Secure AI Agent has access only to what it needs to audit the configuration.

02

Ask for the work
Talk to the agent in natural language.Request an account audit, a public exposure review, or the remediation plan through the available channels. The agent understands the context, applies the configured skills, and follows your company's policy.

03

The agent flags. The team fixes.
From finding to fix, with control.The agent queries, compares, and prepares the plan within the defined permissions. Changing a resource, adjusting policy, and opening a change window stay with the environment owner.

Integrations

Connected to the environments where your infrastructure runs

The Cloud Security Posture AI Agent can query your environments' configuration and run tasks in the systems your team already uses.

  • AWS
  • Microsoft Azure
  • Google Cloud
  • Cloudflare
  • Wiz

Flow

What goes in, what the agent does, and what comes out

From raw configuration to a remediation plan, following your company's rules and permissions.

Inputs

  • Account configurationJSON
  • Resource inventoryList
  • Security policyDOC

Processing

Secure AI Agent

Processing the task

  • Read
  • Compare
  • Prioritizerunning
  • Prepare
Skill appliedPolicy verified

Output

Completed

Plan prepared

  • Exposures flagged
  • Findings prioritized by risk
  • Fix ready for review

Control

You define how far the Agent can act

Different actions can operate with different autonomy levels, always within your company's rules.

  1. 1

    Query

    Reads the configuration and answers with the resource reference.

  2. 2

    Prepare

    Prioritizes findings and organizes the remediation plan.

  3. 3

    Request review

    Waits for validation from the environment owner.

  4. 4

    Execute

    Performs the action within the defined limits.

Levels are configured per type of action, according to each company's policy. Changing resources, adjusting policy, and opening change windows always stay under human approval.

Get started

Put a Secure AI Agent to work.

Start on the platform or choose the plan that fits the pace of your operation.

Security and compliance

Security that can be verified.

Certifications and attestations

  • SOC 2 Type II
  • ISO 27001

UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.

Privacy and regulation

LGPD
Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
Zero Data Retention
A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
Retention and deletion
The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.

Frequently asked questions

Common questions about the Cloud Posture Agent

What teams usually ask before putting an agent to audit the cloud.

  • Does the agent change cloud configuration?

    Not by default. Changing a resource, adjusting policy, or opening a port stay under human approval. The agent audits, prioritizes, and prepares the plan; execution depends on the environment owner.
  • Is this a penetration test?

    No. The agent audits the declared configuration in your environments, with read access. It does not exploit flaws or run attacks to prove a gap.
  • What does prioritizing by real risk mean?

    The ordering considers whether the resource is exposed, what kind of data it holds, and how critical it is to the operation — not just the nominal severity of the finding in a catalog.
  • Which providers does it cover?

    The agent works in the environments your company already uses, such as AWS, Azure, Google Cloud, and Cloudflare. Permissions define which accounts it can query and where it can execute actions.
  • Is our cloud configuration used to train models?

    No. Content processed by Secure AI Agents is not used to train UPX models or third-party models.
  • Can we audit what the agent did?

    Yes. Every action is logged: what was queried, what was proposed, when, in which system, and under which permission. The history stays available for review and auditing.
  • How long does it take to go live?

    It depends on the number of accounts and your company's policy. The starting point is connecting one environment with read access, then expanding the scope as results come in.

Secure AI Agent

Bring a Secure AI Agent to your cloud

Talk to our specialists and see how to adapt this AI Agent to your processes, systems, and needs.