Platform capabilities
Everything you need to secure
your cloud posture
From first scan to audit-ready compliance report — Nexora covers the full lifecycle of cloud security posture management.
Deep Huawei Cloud coverage, one console
Connect your Huawei Cloud environment with read-only credentials. Nexora's background scan engine checks 80+ security controls across 16 resource types, surfacing misconfigurations in near real time. AWS, Azure, and GCP support is on the roadmap.
- ECS & CCE — Compute instance and container security configuration
- IAM — User policies, MFA enforcement, key rotation, privilege review
- OBS — Object storage bucket ACLs, encryption, public access
- VPC & Security Groups — Network exposure, unrestricted inbound/outbound rules
- RDS & DCS — Database encryption, backup retention, access controls
- WAF, ELB & HSS — Web application firewall, load balancer TLS, host security
- CBR, EVS & DMS Kafka — Backup policies, volume encryption, messaging security
- Logging & Monitoring — CTS tracker, LTS log retention, alarm coverage
Active Cloud Connections
Huawei Cloud — Production
ap-southeast-1
82
Healthy
Huawei Cloud — Staging
cn-north-4
67
Warning
Compliance Report — ISO 27001
78%
Compliance score
Audit-ready compliance, automatically
Stop manually mapping findings to compliance controls. Nexora does it for you — continuously tracking your posture against ISO 27001 and other frameworks, so you're always audit-ready.
- ISO 27001:2022 — full annex A mapping
- NIST 800-53 — comprehensive control coverage
- SOC 2 Type II mapping
- Thai BOT IT Circular — built for SEA financial sector
- Thai PDPA — data protection compliance
- Historical trend tracking
Findings that tell you what to fix first
Not all misconfigurations are equal. Nexora scores findings by severity, exploitability, and blast radius — so engineers spend time on what matters, not on noise.
Severity scoring
CVSS-based risk scores
Remediation guidance
Step-by-step fix instructions
Assignment
Assign to team members
Suppression
With justification & expiry
Evidence
Attach proof of fix
Audit trail
Every change logged
OBS bucket ACL allows public read
Root account MFA not enabled
Security group allows SSH from 0.0.0.0/0
CTS tracker logging disabled
ECS instance IMDSv1 enabled
Admin
Full platform access, billing, and org management.
Cloud Engineer
View findings, assign remediation, track resolution.
Compliance Officer
Compliance dashboards, reports, audit evidence.
Partner
Read-only access to client org data for MSSPs.
Enterprise SSO and RBAC
Nexora is built for enterprise from day one. Role-based access control with four purpose-built roles, and SSO via WorkOS means you can plug into Okta, Azure AD, or any SAML-compatible provider in minutes.
- WorkOS SSO — Okta, Azure AD, Google Workspace
- SAML 2.0 and OIDC support
- Org-level and environment-scoped permissions
- Immutable audit log
See it live in your cloud
Book a 30-minute demo and we'll walk through a real scan of your environment.