Cloud Security
In-depth guides and analysis on cloud security from the Safeguard engineering team.
100 articles
One Shared Deploy Credential Is Forty Pipelines' Worth of Blast Radius
Set up once, when there was one service. Forty pipelines later, every one of them still uses it, and it can deploy to production, which means it can read the secrets and infrastructure of everything it touches.
Your Terraform State Is a Secrets Store With a Build Artefact's Access Control
The database password, the generated private key, the API token an output exposed. You did not put them there directly. Terraform did, because it needs the full attributes of everything it manages to plan the next change.
The Kubernetes Token Nobody Asked For
Every pod gets a token that authenticates to the API server, whether the application inside it ever calls the API or not. It sits there anyway, readable by anything that can read a file in the container, because the default is on.
Your Free Tier Is Compute You Hand to Strangers
That is the point of it, and it is also a standing offer to everyone who wants compute, a clean network position or storage for a purpose you did not intend. The abuse is rarely sophisticated.
Encryption at Rest Protects Against Roughly One Thing
It is on every security page, it is true, and it covers someone taking the physical disk. Every other way your data gets read happens through a path where it is already decrypted, because the encryption is transparent by design.
Autoscaling Turned the Attack Into an Invoice
Every request was served, no alerts fired, the dashboards stayed green. The properties that made your infrastructure resilient are what made the attack work, and the only symptom arrives weeks later on a bill.
A Presigned URL Is a Capability You Minted Without Thinking About It
Anyone holding the string can do what it permits, with no identity check, until it expires. Every mistake is a variation of one thing: handing out more capability than intended, for longer than intended.
Comparing confidential VM offerings across major cloud pr...
A practical comparison of confidential virtual machines across Azure, AWS Nitro Enclaves, GCP confidential compute, and more -- real strengths, real limitations, no marketing gloss.
Cloudflare November 18 2025 Outage: A Bot Management Feature File Doubled in Size
A ClickHouse permissions change caused Cloudflare's Bot Management feature file to balloon past a hard-coded proxy limit, taking the core network down for two hours and ten minutes.
Best cloud workload protection platforms (CWPP)
An honest, no-hype comparison of leading cloud workload protection platforms — evaluation criteria, real vendor tradeoffs, and where supply chain security fits in.
Catching Terraform Misconfigurations Before They Ever Reach Apply
Trivy replaced tfsec in 2023 and Checkov ships thousands of policies — here's how to wire open-source Terraform scanners into CI/CD before terraform apply runs.
Insecure defaults in Azure ARM templates: a pre-deployment scanning guide
Azure Resource Manager templates don't enforce TLS 1.2 or block public blob access by default — here's how to catch it before terraform apply's Azure cousin ever runs.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.