August 2026 Summaries
3 posts from Prowler
Filter
Month:
Year:
Post Summaries
Back to Blog
Prowler’s managed MCP Server connects a Prowler Cloud account to AI assistants such as Claude Code, allowing users to query real cloud-security scan data conversationally rather than navigating compliance dashboards. It supports CIS Benchmarks across nine environments, including AWS, Azure, GCP, Kubernetes, Microsoft 365, Google Workspace, GitHub, Oracle Cloud, and Alibaba Cloud, and can also analyze more than 70 other frameworks such as PCI-DSS, SOC 2, ISO 27001, HIPAA, and DORA. After configuring Claude Code with a personal Prowler API key, users can identify scanned providers, retrieve the latest scan’s compliance overview, inspect failed requirements and associated findings, and obtain resource-specific remediation guidance or available automated fixer scripts. The workflow is read-only until users elect to remediate through their own cloud credentials or infrastructure-as-code repositories, with suggested safeguards including human approval, dry runs, preference for durable IaC changes, and verification through a new scan. Failed findings can alternatively be sent to Jira for team tracking, while the post notes that automated benchmark results do not replace broader audit work where frameworks include manual requirements.
Aug 12, 2026
2,341 words in the original blog post.
Prowler Data Security is presented as a cloud-based Data Security Posture Management platform designed to trace sensitive data across application code, cloud infrastructure, identities, AI agents, Amazon Bedrock roles, and Model Context Protocol tools. It combines deterministic code analysis, cloud data discovery and classification, IAM and attack-path analysis, and bounded AI-assisted reasoning to identify how PII, credentials, health data, payment data, and custom sensitive fields can reach logs, storage, prompts, vector stores, APIs, and agent-accessible tools. The platform emphasizes correlating isolated findings into complete exposure paths, such as customer data logged to an S3 bucket that can be accessed by an AI agent or MCP tool, then recommending remediation in code, IAM policies, cloud configurations, or tool scopes. Its Lighthouse AI feature uses redacted metadata and security evidence to investigate risks conversationally while avoiding storage or disclosure of raw sensitive values. Built on open-source components including Microsoft Presidio and Kingfisher, Prowler Cloud aims to help organizations prioritize and fix the underlying causes of sensitive-data exposure as AI systems increasingly expand access to cloud resources.
Aug 05, 2026
2,933 words in the original blog post.
AWS Nitro Enclaves are increasingly used to secure sensitive data such as LLM weights and cryptographic keys on AWS, yet until recently, no tool could verify if these enclaves were configured securely. Prowler has introduced 11 new checks that provide security posture coverage for confidential computing workloads on AWS, addressing the lack of visibility into how these enclaves are deployed and configured. These checks operate through standard AWS APIs and log sources, without requiring direct access to customer infrastructure, to detect potential misconfigurations like debug mode, which could compromise security. The inclusion of these automated checks provides organizations with evidence-producing posture validation, essential for certifying confidential AI workloads on AWS, and maps to 23 compliance frameworks, making these findings audit-ready. Prowler's solution highlights the importance of continuous assessment and remediation guidance to ensure that sensitive data remains protected within attested enclaves, offering a comprehensive approach to managing confidential computing security on AWS.
Aug 03, 2026
2,810 words in the original blog post.