
Features
Continuous compliance monitoring
Automated daily scanning of GCC 2.0 cloud resources for compliance with Singapore Government IM8 Reform. Findings are assessed against the controls defined in each subsystem's System Security Plan (SSP), with results reflecting the Risk Materiality Level (RML) (Low-Risk, Medium-Risk, or High-Risk) and set of controls applicable to each system.
Consolidated secuity posture view
CloudSCAPE findings surface in the Security Centre on Console, giving agencies a consolidated view of security posture and IM8 Reform compliance across their cloud accounts.
Attack Mapper
Analyses AWS Identity and Access Management (IAM) configurations to identify dangerous permission combinations across users, groups, roles, and policies that could lead to privilege escalation or lateral movement within the environment.
Finding workflow management
Allows users to categorise non-compliant findings based on their current state to help manage remediation efforts and track progress. Users can add notes to capture follow-up actions and justifications, and bulk update related findings to manage them efficiently at scale.
APIs
Provides APIs for programmatic access to platform data, including IM8 compliance and Attack Mapper findings. Agencies can retrieve this data and integrate it into their own reporting and analysis workflows without manual exports.
Roadmap
AI-Assisted Remediation
Turns supported security findings into review-ready fixes for Terraform code. CloudSCAPE uses an AI agent to generate fixes for the misconfigured resources and raises a Merge Request in the agency's SHIP-HATS GitLab project, which developers review, adjust if needed, and merge. This shortens the path from finding to fix while keeping agencies in control over what enters their codebase.
Last updated 11 Aug 2026
Thanks for letting us know that this page is useful for you!
If you've got a moment, please tell us what we did right so that we can do more of it.
Did this page help you? - No
Thanks for letting us know that this page still needs work to be done.
If you've got a moment, please tell us how we can make this page better.

A Monitoring Component That Protects Your Systems Deployed on GCC 2.0