Hex Security is now ParameterWe're at Black Hat USA 2026

Parameter

Backed by Y Combinator

Your cloud mapped like an attacker sees it

Agents inventory every resource across AWS, Google Cloud, and Azure, trace real attack paths, and open the Terraform fix before you've finished your coffee.

Secure your cloud

See first findings in 24 hours

Built by the team that secured:

Apple
Google
Microsoft
U.S. Department of Defense
T-Mobile
Henkel
Epic Games
AT&T
Yahoo

[ how it works ]

01

Inventory

Connect a read-only role and agents map every resource, identity, and trust relationship across your accounts. No agents to install, no performance hit.

02

Detect

Instead of matching rules, agents reason about how misconfigurations chain together, tracing real attack paths from the internet to your data.

03

Remediate

Every finding ships with its proven blast radius and a Terraform patch, opened as a pull request against your infrastructure-as-code.

[ why parameter ]

Signal, not noise.Only what an attacker can reach.

Most cloud tools hand you everything and wish you luck. Parameter raises only what an attacker can actually exploit.

One platform, one queue

Misconfigurations, IAM risk, and exposed data in a single prioritized view. No duplicate alerts, no tool sprawl.

Ranked by exploitability

Findings ordered by what an attacker can actually reach, not by CVSS averages.

Agentless in minutes

A secure, read-only API connection. First findings the same hour.

[ scanners ]

Your cloud, the way an attacker sees it.Every path they’d take.

Posture reasoned about, not rule-matched

Agents read your configuration the way an attacker would, chaining network exposure, IAM trust, and data access into real attack paths.

Replaces

Wiz
Orca Security

94%

less noise than rule-based CSPM tools.

1,482

resources mapped in a single connected account.

15 min

from connecting an account to first findings.

[ coverage ]

Every cloud.Every blind spot.

Connect your accounts and agents map every resource and role across your clouds, then trace the real paths an attacker would take to your data.

AWS

EC2, S3, IAM, Lambda, RDS, and 100+ services.

Google Cloud

GCE, GCS, service accounts, and workload identity.

Azure

VMs, storage accounts, Entra ID, and key vaults.

Kubernetes

Clusters, workloads, RBAC, and network policies.

IAM & identity

Roles, trust relationships, and escalation paths.

Data stores

Public buckets, snapshots, secrets, and leaked keys.

[ FAQ ]

Frequently asked questions

Start testing today.

A URL and credentials is all it takes.

First findings land within 24 hours.