Compliance & security
automated by AI.
Gertin AI gives your security team five purpose-built AI engines — IAM analysis, cloud scanning, SOC2 evidence, log summarization, and threat intelligence — through a single API that runs entirely inside your AWS account.
Five engines. One unified API.
Each engine is purpose-built for a distinct compliance workflow and callable through a single OpenAI-compatible REST API.
IAM Policy Analyzer
Risk score, privilege escalation paths, and compliance mapping in under 3 seconds.
/v1/compliance/iam/analyzeCloud Misconfiguration Scanner
CIS Benchmark checks for S3, EC2, RDS, VPC, CloudTrail, and KMS resources.
/v1/compliance/cloud/scanSOC2 Evidence Assistant
PASS/FAIL verdicts, auditor narratives, and gap lists ready for Type II audits.
/v1/compliance/soc2/evidenceAI Log Summarizer
CloudTrail, GuardDuty, and VPC logs distilled into structured security findings.
/v1/compliance/logs/summarizeThreat Explanation Copilot
CVEs, IOCs, and MITRE techniques explained for executive, analyst, or technical audiences.
/v1/compliance/threat/explainOpenAI-Compatible API
Drop-in `/v1/chat/completions` endpoint with streaming — routed to AWS Bedrock. No code changes needed to integrate.
/v1/chat/completionsYour data never leaves
your AWS account.
Every byte of compliance data — IAM policies, log files, cloud configurations, security alerts — is processed entirely within your VPC. AI inference runs through AWS Bedrock using IAM role-based access. Gertin AI never sees your data.
Zero data egress — all AI inference runs inside your VPC via AWS Bedrock
Deploys to ECS Fargate, EKS, or EC2 in under 15 minutes with CDK
Immutable audit log of every compliance check, stored in Amazon RDS
Prometheus metrics and CloudWatch dashboards included out of the box
Your AWS Account
Your Applications
Existing security & compliance tools
Gertin AI Gateway
ECS Fargate · Rate limiting · Audit log
AWS Bedrock
Claude 3.5 · Titan Embeddings · No egress
Data Layer
Amazon RDS · ElastiCache · CloudWatch
Built for security practitioners
Security Engineering
- Pre-deployment IAM least-privilege gates
- Automated misconfiguration detection in CI/CD
- Real-time threat contextualization for on-call
Compliance & Audit
- SOC2 Type II evidence generation and gap analysis
- PCI-DSS 4.0 and HIPAA control mapping
- Audit-ready narratives in minutes, not days
Security Operations
- Alert triage and CVE explanation for analysts
- Log analysis across CloudTrail, GuardDuty, VPC
- Incident response acceleration with AI context
Deploy in 15 minutes.
No data leaves your cloud.
Subscribe through AWS Marketplace or direct. Your CDK stack provisions everything — VPC, ECS, RDS, Redis, ALB, Route 53 — with one command.
14-day free trial · No credit card required