CloudFence
CloudFence provides an agentless behavioral cloud security platform for AWS and Azure that builds per-workload baselines from native cloud logs to detect deviations, enforce least privilege, and monitor egress traffic, selling via annual workload-based subscriptions to enterprise cloud security teams and CISOs.
- Company typePrivate
- Founded-
- HeadquartersSeattle, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What CloudFence does
CloudFence is a privately held cloud security vendor that sells an agentless behavioral detection platform for AWS and Azure environments. The company, founded by Mounira Remini (CEO), Arnaud Fauvel (CTO), and Asen Bozhilov (Founding Lead Engineer), operates with a small team of approximately ten employees and is incorporated in Delaware with a Seattle office address on file. Its platform ingests native cloud logs—AWS VPC Flow Logs, Azure NSG Flow Logs, AWS CloudTrail, and DNS query logs—through a customer-created read-only IAM role, and uses that telemetry to build per-workload behavioral baselines that surface deviations in real time. The product is organized around four named capabilities: Runtime Behavioral Baselines, Usage-Based Least Privilege Enforcement, Egress Traffic Control & DNS Monitoring, and a Cloud Network Map that visualizes workload communication across accounts, VPCs, and regions.
The underlying technology is positioned as complementary to, rather than competitive with, CSPM/CNAPP (which the company characterizes as configuration-focused) and SIEM (which it characterizes as rule-engineering-heavy). Instead, CloudFence emphasizes behavioral detection on egress and east-west traffic, automated security group hardening driven by hit-count and last-used timestamps, identity behavior monitoring, and custom Guardrails for policy enforcement. The company also markets use cases addressing C2 traffic detection, supply chain attack exfiltration, and AI-agent workload monitoring. CloudFence does not position itself as an inline blocker; its native integrations allow it to trigger response actions through existing cloud controls such as security groups and firewalls.
Commercially, CloudFence operates a sales-led, demo-driven go-to-market motion: the website's primary calls-to-action are "Book a demo" and "Watch a 3-min demo," and the pricing model is a flat annual subscription scaled by the number of workloads with active interfaces generating traffic, with unlimited seats for security and operations teams. Target buyers are cloud security teams, CISOs, and DevSecOps practitioners managing multi-account, multi-VPC AWS/Azure estates, with named case-study evidence in healthcare (AIDA Healthcare) and from individual InfoSec practitioners. The company publishes a blog and thought-leadership articles on cloud security topics, and distributes solely through direct sales with no apparent self-serve or product-led motion. No funding rounds, partnerships, acquisitions, or institutional investors are disclosed in available material.
CloudFence firmographics
Firmographics- Name
- CloudFence
- Legal name
- CloudFence Inc.
- Website
- https://cloudfence.com
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- CloudFence provides an agentless behavioral cloud security platform for AWS and Azure that builds per-workload baselines from native cloud logs to detect deviations, enforce least privilege, and monitor egress traffic, selling via annual workload-based subscriptions to enterprise cloud security teams and CISOs.
- Ownership category
- akta.pro rank
CloudFence industry classification
Industry- Product category
- Cloud Network Security
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (51821)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Attack Detection & Response for Cloud/SaaS (SOC for Cloud) (HDADAGAJ)
- akta.pro secondary industries
- Cloud Network Security (Microsegmentation, Cloud Firewall) (HDADADAH), DevSecOps, Cloud Security Automation & Policy-as-Code (HDABAHAM), Cloud Security & Compliance Services (BPAEACAG)
Keywords
Where CloudFence is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
CloudFence business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Annual Subscription (Workload-based): CloudFence charges a flat yearly fee based on the number of workloads with active interfaces generating traffic. This model provides cost predictability, eliminates surprises, and scales with the customer's actual environment. Integration and hosting are fully managed, with unlimited seats for security and operations teams.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Flat yearly subscription based on active workloads |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
CloudFence product offering
Product offeringCore offering
CloudFence is an agentless behavioral cloud security SaaS platform that ingests native cloud logs (AWS VPC Flow Logs, CloudTrail, Azure NSG Flow Logs, Route 53 DNS logs) via a read-only IAM role to build per-workload behavioral baselines. It detects deviations in real time, monitors egress traffic, enforces usage-based least-privilege on security groups and IAM, and surfaces command-and-control and supply-chain attack indicators without requiring agents or traffic mirroring.
Product overview
CloudFence is a behavioral cloud security platform that provides agentless, AI-driven visibility and threat detection for cloud network and identity. The platform consists of four core capabilities: Runtime Behavioral Baselines (builds per-workload behavioral baselines from cloud-native logs for real-time deviation detection), Usage-Based Least Privilege (evaluates runtime traffic and identity activity against security group and IAM configurations to enforce least-privilege), Egress Traffic Control (analyzes outbound activity across accounts and VPCs with domain classification and newly-observed destination detection), and Cloud Network Map (visual real-time map of workload communications across regions and accounts). These capabilities address three primary use cases: Detection of Behavior Deviations, Suspicious Outbound Communications Control, and Security Group Hardening. The platform is powered by native cloud logs (VPC Flow Logs, DNS logs, CloudTrail, Azure NSG Flow Logs) requiring no agents or traffic mirroring. CloudFence offers a 3-step process: Authorize (create read-only IAM role), Ingest (process logs and build behavior baselines), and Secure (receive alerts and optimize policies). Pricing is a flat yearly fee based on workloads with active interfaces generating traffic.
Differentiator
Problem solved
Functional benefit
Products and services
- CloudFence Behavioral Security Platform Agentless, AI-driven SaaS platform for behavioral cloud security that ingests AWS VPC Flow Logs, CloudTrail, Azure NSG Flow Logs, and Route 53 DNS logs to build per-workload behavioral baselines, detect deviations in real time, monitor egress traffic, enforce usage-based least privilege, and visualize workload communications. Sold as a flat annual subscription scaled by workloads with active interfaces, targeting cloud security teams, CISOs, and DevSecOps buyers running production AWS and Azure environments.
Quantifiable outcome
- Reduces security group rule audit time from weeks to minutes through automated hit-count and last-used timestamp analysis
- +4 more outcomes
Companies that use CloudFence
Customer profileNamed customers2 records
Segments3 records
Ideal customer profiles2 records
CloudFence technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability4 records
Feature6 records
CloudFence partnerships and signals
Strategic signalScale indicators2 records
Recent moves4 records
Expansion highlights5 records
CloudFence competitors and assessment
Company assessmentEmerging players
- Aqua Security: Cloud-native application protection platform focused on container and Kubernetes security, with runtime detection and behavioral monitoring. Adjacent overlap on runtime behavioral detection in cloud workloads, particularly in containerized environments.
- Sysdig: Cloud security and observability platform with runtime threat detection, Falco-based behavioral monitoring, and CSPM capabilities. Overlaps with CloudFence on cloud runtime behavioral detection and least-privilege enforcement use cases.
- Ermetic (now part of Tenable): Cloud infrastructure entitlement management and security platform with posture, identity, and behavioral detection capabilities. Overlaps with CloudFence on IAM least-privilege enforcement and behavioral monitoring in cloud environments.
Direct peers
- Lacework: Cloud security platform using behavioral analytics and machine learning to detect anomalies across AWS, Azure, GCP, and Kubernetes. Comparable in its behavioral baselining approach to cloud workload activity, though broader in scope.
- Wiz: Cloud security platform offering CNAPP capabilities including workload protection, posture management, and increasingly runtime/behavioral detection across AWS, Azure, GCP, and OCI. Most direct competitor in the cloud security posture and detection category, now expanding into the behavioral detection space that CloudFence targets.
- Orca Security: Agentless cloud security platform providing posture management, workload protection, and threat detection across multi-cloud environments. Comparable to CloudFence in its agentless architecture and coverage of behavioral and network signals in cloud workloads.
- Upwind: Cloud runtime security platform focused on egress monitoring, behavioral detection, and runtime threat prevention in cloud workloads. Closely aligned with CloudFence's egress and behavioral baseline approach, addressing similar buyer personas in cloud security.
Broad incumbents
- Microsoft Defender for Cloud: Native cloud security posture management and workload protection suite for Azure and AWS, increasingly adding behavioral detection capabilities. Bundled with Azure consumption and a major incumbent pressure point for CloudFence's Azure-targeted deployments.
- CrowdStrike Falcon Cloud Security: Cloud workload protection and posture management integrated into CrowdStrike's broader endpoint and identity security platform. Competes on runtime detection and behavioral analytics in cloud environments, with significantly larger enterprise distribution and installed base.
- Palo Alto Networks Prisma Cloud: Broad incumbent CNAPP suite covering CSPM, CWPP, CIEM, and runtime defense across major cloud providers. Overlaps with CloudFence on behavioral anomaly detection, network policy analysis, and least-privilege enforcement, but as part of a much larger portfolio.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
CloudFence social profiles
Digital presenceCloudFence financial estimates
Financial estimateRevenue estimate
Valuation estimate
CloudFence leadership team
Management profileNumber of profiles
Profiles3 records
CloudFence funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CloudFence M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CloudFence
What does CloudFence do?
CloudFence is an agentless behavioral cloud security SaaS platform that ingests native cloud logs (AWS VPC Flow Logs, CloudTrail, Azure NSG Flow Logs, Route 53 DNS logs) via a read-only IAM role to build per-workload behavioral baselines. It detects deviations in real time, monitors egress traffic, enforces usage-based least-privilege on security groups and IAM, and surfaces command-and-control and supply-chain attack indicators without requiring agents or traffic mirroring.
Is CloudFence a public or private company?
CloudFence is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was CloudFence founded?
CloudFence was founded in -1. It employs 1 to 10 people.
Where is CloudFence based?
CloudFence is headquartered in Seattle, United States, in the North America region.
How does CloudFence make money?
One revenue line is on record: annual Subscription (Workload-based).
Who are CloudFence's main competitors?
Emerging players on record are Aqua Security, Sysdig and Ermetic (now part of Tenable). Direct peers are Lacework, Wiz, Orca Security and Upwind. Broad incumbents are Microsoft Defender for Cloud, CrowdStrike Falcon Cloud Security and Palo Alto Networks Prisma Cloud.
Does CloudFence have an API?
No public API is recorded for CloudFence.
What industry is CloudFence in?
CloudFence's product category is Cloud Network Security. Its primary akta.pro industry code is HDADAGAJ, Attack Detection & Response for Cloud/SaaS (SOC for Cloud), with a secondary code of HDADADAH, Cloud Network Security (Microsegmentation, Cloud Firewall). Its NAICS code is 51821 and its SIC code is 7372.