TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: Kexa.io – Open-Source IT Security and Compliance Verification

81 pointsby patrick4urcloud16 days ago
Hi HN,<p>We&#x27;re building Kexa.io (<a href="https:&#x2F;&#x2F;github.com&#x2F;kexa-io&#x2F;Kexa">https:&#x2F;&#x2F;github.com&#x2F;kexa-io&#x2F;Kexa</a>), an open-source tool developed in France (incubated at Euratech Cyber Campus) to help teams automate the often tedious process of verifying IT security and compliance. Keeping track of configurations across diverse assets (servers, K8s, cloud resources) and ensuring they meet security baselines (like CIS benchmarks, etc.) manually is challenging and error-prone.<p>Our goal with the open-source core is to provide a straightforward way to define checks, scan your assets, and get clear reports on your security posture. You can define your own rules or use common standards.<p>We are now actively developing our SaaS offering, planned for a beta release around June 2025. The key feature will be an AI-powered security administration agent specifically designed for cloud environments (initially targeting AWS, GCP, Azure). Instead of just reporting issues, this agent will aim to provide proactive, actionable recommendations and potentially automate certain remediation tasks to simplify cloud security management and hardening.<p>We&#x27;d love for the HN community to check out the open-source project on GitHub. Feedback on the concept or the current tool is highly welcome, and a star if you find it interesting helps others discover the project! If the upcoming AI-powered cloud security agent sounds interesting, we&#x27;d be particularly keen to hear your thoughts or if you might be interested in joining the beta (~June 2025).<p>thank you !!

8 comments

ziddoap16 days ago
Looks interesting, and I&#x27;ll be diving into it a bit deeper, but I just wanted to mention that this quote:<p>&quot;<i>even non-experts can guarantee the security of their cloud environments</i>&quot;<p>Even though I understand that this is part of a marketing blurb, not a literal guarantee, it was an immediate yellow-flag for me. No tool can possibly <i>guarantee</i> the security of my cloud environment, so please don&#x27;t imply&#x2F;say your tool can. It reminds me of shady VPN companies guaranteeing my security by providing me with &quot;military-grade encryption&quot;.<p>To be abundantly clear, I am <i>not</i> saying that this product is shady or anything -- I have not had the time to evaluate it in the depth needed -- but statements like that make the rest of the pitch an uphill battle. For me, at least.
评论 #43850065 未加载
mrbluecoat16 days ago
An admittedly superficial comment: what is your logo supposed to be? A mouse? Reminds me of that famous young&#x2F;old optical illusion: <a href="https:&#x2F;&#x2F;www.braingle.com&#x2F;brainteasers&#x2F;26745&#x2F;old-or-young-woman.html" rel="nofollow">https:&#x2F;&#x2F;www.braingle.com&#x2F;brainteasers&#x2F;26745&#x2F;old-or-young-wom...</a><p>Great job on the tool, by the way. Anything to improve the security posture of companies is a good thing!
评论 #43846142 未加载
stego-tech16 days ago
I’m always a fan of automated compliance and vulnerability management tooling - looking forward to giving this a spin at some point.<p>One bit of UX feedback: your “Offers” page isn’t rendering correctly on my iPhone (14 Pro) device. The text isn’t wrapping, graphics don’t seem to be scaling, and the columns are misaligned.<p>Once the current network rebuild is done, I’m looking forward to rolling this and Wazuh to try out both.
jmpavlec16 days ago
FYI seems like multiple typos in the GitHub description that shows at the top (not in the readme)<p>Quoting it here:<p>&gt; Kexa&#x27;s simple rules (Open Source) make it easy to monitoring and manage alerting of your entire cloud. With various monitoring and alerting options, instant and detailed alerts, easy-to-deploy and low in infrastructure costs, in turns complexity into simplicity.
gitroom16 days ago
this kinda stuff is right up my alley, love when folks make it easier to cut through all the security noise
sontek16 days ago
Can you give a brief explanation of the benefits of your policy engine over using cloud custodian?
评论 #43850315 未加载
zufallsheld16 days ago
Does this work without your SaaS component? Can I run it air-gapped?
shooker43516 days ago
Wow, very cool. Would this replace a Vanta or complement it?
评论 #43849012 未加载
评论 #43847642 未加载