Skip to main content
CloudArq
scopeaws
stancecomplementary
auditread-only
comparison · aws · native tools

CloudArq and AWS-native security tools: how they fit together

AWS-native tools give you first-party signals from inside your account. CloudArq is an independent, agentless, read-only external audit that adds the exact fix for each finding, one report mapped to eight compliance frameworks, a dedicated AI-workload lens, and cost-waste detection. This page is an honest look at where each fits — the native tools are legitimate and you should keep running them.

Updated 2026-07-20 · ~9 minute read

167
read-only checks in one audit
7
compliance frameworks mapped
0
agents installed
0
credentials stored
the short version

It's not either/or

AWS-native security services are first-party, deeply integrated, and continuous — they live inside your account and watch it around the clock. CloudArq is a different shape: an independent audit that connects from the outside through a read-only IAM role, runs 192 checks across security, cost, and AI workloads, and returns one report where every finding carries a copy-paste fix and its framework control mappings. The most useful posture comes from running both — native tools for the always-on runtime signal, CloudArq for the periodic, independent, remediation-first audit.

aws-native · what each one is

The AWS-native tools, described honestly

Each of these is a legitimate, well-built AWS service. Here is what each one categorically is — no scoring, no "better/worse."

AWS Security Hubfinding aggregation

Aggregates and normalizes security findings from AWS security services into one place, and runs automated checks against security standards.

Amazon GuardDutythreat detection

A threat-detection service that continuously analyzes AWS logs and telemetry to surface suspicious or potentially malicious activity.

AWS Configconfiguration history

Records the configuration of your AWS resources over time and evaluates them against rules, giving you a configuration history and change timeline.

AWS Trusted Advisorrecommendation checks

Provides cost, security, and service-limit recommendation checks.

AWS IAM Access Analyzerexternal-access analysis

Analyzes resource policies to identify resources shared with an external entity, and helps you validate IAM policies.

AWS Budgetsspend alerts

Lets you set custom cost and usage budgets and alerts you when actual or forecast spend crosses a threshold you define.

cloudarq · what it adds on top

What an independent audit adds

These are the things CloudArq brings to the table alongside your native signals — not instead of them.

01

An independent, agentless external perspective

CloudArq audits from outside your account through a read-only IAM role and an ExternalId — no agents to install and nothing that runs on your workloads. It never stores your credentials, application data, database contents, or S3 objects.

02

The exact fix with every finding

Each finding ships with a copy-paste CLI command or Terraform block and the evidence pointer to prove it. The audit is read-only and never auto-fixes — it hands you the remediation steps and you decide when to apply them.

03

One report, mapped to eight frameworks

The same read-only audit groups its findings by the control IDs of eight compliance frameworks, so a single encrypted-at-rest gap can evidence several frameworks at once. A scanner shows posture; it does not certify or guarantee compliance.

04

A dedicated AI-workload lens

A view over the same audit surfaces Amazon Bedrock and AgentCore risk from control-plane configuration — model-invocation logging, guardrail parity, agent execution-role blast radius — read-only, never touching the agent data plane.

05

Cost waste alongside security

The audit also checks for idle and oversized resources — idle NAT gateways, unattached EIPs, oversized EC2/RDS, gp2 volumes, AI spend on Bedrock — with per-resource estimates computed live from AWS metadata. No hard spend cap; detection plus the fix.

fit

A workflow that uses both

Let the native tools do what they are built for — continuous threat detection with GuardDuty, configuration history with Config, finding aggregation with Security Hub, spend alerts with Budgets. Run CloudArq on a schedule as the independent audit that turns posture, AI-workload risk, and cost waste into a single, framework-mapped list of findings, each with the exact remediation step. When CloudArq flags something, you fix it and your native tools keep watching. Nothing here overlaps in a way that makes you pick one.

product · output

One audit, spanning posture, AI, and cost

audit · findings · one reportillustrative example
Critical1High2Medium2
posture
Security group 0.0.0.0/0 on SSH (22)
sg-0example · eu-north-1
fix →
posture
RDS instance not encrypted at rest
db-example-orders
fix →
ai
Bedrock model-invocation logging off
bedrock · eu-central-1
fix →
cost
Idle NAT gateway (< 1 GB / 30d)
nat-0example · eu-west-1
fix →
posture
No alarm on root-account login
cloudwatch · eu-north-1
fix →

Security, AI-workload, and cost findings in one read-only pass — each with a copy-paste CLI / Terraform fix and its framework control mapping.

faq

Frequently asked

01Does CloudArq replace AWS Security Hub or GuardDuty?
No — they are complementary. AWS Security Hub aggregates and normalizes security findings from AWS services into one place, and Amazon GuardDuty continuously analyzes AWS logs and telemetry to surface suspicious activity. Both run inside your account. CloudArq is an independent, agentless, read-only external audit that adds the exact remediation step for each finding, one report grouped by eight compliance frameworks, a dedicated AI-workload lens, and cost-waste detection. Keep the native tools for continuous runtime signals and use CloudArq as the periodic audit-and-fix layer on top.
02How is CloudArq different from a native posture check?
CloudArq connects through a read-only IAM role with an ExternalId — no agents, and it never stores your credentials, application data, database contents, or S3 objects. It runs 192 checks in one audit, groups the findings by eight compliance-framework control IDs, and ships a copy-paste CLI or Terraform fix with every finding. On top of that it carries a dedicated AI-workload lens over Amazon Bedrock and cost-waste checks — so posture, AI risk, and spend land in the same report.
03Is CloudArq read-only? Does it change my AWS account?
Yes, the audit is read-only and CloudArq never auto-fixes. It detects an issue and gives you the exact remediation steps; you decide when to apply them. The connection is a read-only IAM role plus an ExternalId, data is encrypted with AES-256-GCM at rest, and CloudArq is EU-hosted in Helsinki.
04Do I still need AWS-native tools if I run CloudArq?
Yes — keep them. Amazon GuardDuty gives you continuous threat detection, AWS Config records a configuration history and change timeline for your resources, and AWS Budgets alerts you when spend crosses a threshold. Those are always-on signals living inside your account. CloudArq is a periodic, independent external audit plus a remediation and framework-mapping layer, not a runtime monitor — the two fit together rather than compete.
05Where does AI-workload coverage fit in?
CloudArq carries a dedicated AI-workload lens on the Max tier that reads Amazon Bedrock and Bedrock AgentCore control-plane configuration — encryption keys, network mode, IAM execution roles, and logging settings — read-only, never the data plane that holds agent conversations. It flags things like model-invocation logging left off or an agent execution role with a wildcard action. See the AI Workload lens page for the full breakdown.
06Which tier maps all eight compliance frameworks?
The Max tier maps all eight frameworks; the Pro tier maps four (CIS, SOC 2, ISO 27001, GDPR); and the free Starter tier runs the core check set without the framework grouping. Framework coverage per tier is defined by the pricing source of truth, not this page — see the pricing page for current tiers and prices.

See the audit next to your native signals

CloudArq is an agentless AWS CSPM — read-only, independent, and remediation-first. Run it alongside your AWS-native tools and see 192 checks, eight framework mappings, an AI-workload lens, and cost waste land in one report.

More context: what agentless CSPM means, how the read-only connection works, the AI Workload lens, and the cost checks.