Home/Answers

Answers

How do I check whether a cloud security finding is valid?

Cloudeval brings a security finding together with the resource, source and available evidence you need to investigate it. Open Security & Compliance and Resources, inspect the native rule and evaluated property, and compare the result with the source. Resolve missing inputs before suppressing a finding or changing infrastructure.

Open reportsRead the guide
Security findings with severity, confidence and evidence reference columns

Where Cloudeval is a strong fit

Understand the architecture and its dependencies

Explore architecture and dependency views, then inspect a resource and its properties.

Explore the diagram workflow

Connect a finding to the resource and evidence

Investigate supported findings alongside source context, resource details and coverage.

Investigate a finding

Ask AI questions with project context

Ask about resources and report findings using the context already in your project.

See project-aware AI investigation

Carry the review into your team's workflow

Use CLI/MCP workflows and export diagrams or available report evidence for your team.

Explore review exports
AI Guide

Turn a diagram into a guided investigation

When a written answer is not enough, AI Guide walks through the architecture or dependency view, highlights the resources under discussion, and keeps the explanation, evidence, and next check together.

Personas adjust the emphasis for executive, architecture, security, or operations reviews. They do not change the available project evidence.

See how AI Guide works
Cloudeval Playground Architecture view with AI Guide entry point and a generated resource diagram
Real Playground capture. A guide explains available project evidence; it does not prove runtime traffic, health, or ownership.

What you need

  • A security finding and its affected resource.
  • Access to the evaluated template or collected snapshot.

What you get

  • A trace from the native rule to the evaluated property.
  • A rerun or an explicit unresolved evidence gap.

Trace the finding before changing infrastructure

  1. 1Open Security & Compliance and select the finding you need to investigate.
  2. 2Identify the affected resource and compare its properties with the template or collected snapshot.
  3. 3Retain the source scanner, native rule ID and file or line reference when supplied.
  4. 4Check whether missing parameters, unresolved references or incomplete collection could change the conclusion.
  5. 5Correct the source or missing context, rerun the same check, and record the new result before closing the finding.
Report controls for inspecting evidence and sharing review context

Keep the original rule beside the mapped control

A canonical control groups related observations for review. The native rule identifies the check that produced a finding. Preserve both when supplied; a shared control label does not mean two scanners executed identical tests. Severity, confidence and configured gate impact also answer different questions.

Cloudeval provides context for investigation; it does not guarantee that scanner false positives are eliminated. A static CloudFormation check cannot prove live access or traffic.

Not assessed, not selected and failed collection are not passing results. If a source reference is missing, leave the conclusion unresolved until you can inspect the evidence.

Frequently asked questions

No. Confidence helps prioritize investigation. Verify the evaluated property, source and rule before accepting a risky change.
Not automatically. The configured gate policy determines the merge-related outcome; inspect the actual run and gate result.
Keep the original finding, corrected source revision, scanner or assessment context and rerun result so another reviewer can follow the change.

Further reading

Cloudeval documentation

  • Review findings
  • Reports and exports
  • Evaluation coverage
CloudevalCloudeval AI

AI Agents Engineered for Cloud. Visualize, understand, and optimize your cloud infrastructure with intelligent automation.

Made in India 🇮🇳 for the world! 🌍❤️

Follow Us

Get started

  • Features
  • Pricing
  • Changelog

Resources

  • Blog
  • Documentation
  • Support

Legal

  • Terms & Conditions
  • Privacy Policy
  • Refund Policy
  • Delivery Policy

Company

  • About Us(Soon)
  • Contact Us
  • Careers(Soon)
CloudevalCloudeval AI

AI Agents Engineered for Cloud. Visualize, understand, and optimize your cloud infrastructure with intelligent automation.

Made in India 🇮🇳 for the world! 🌍❤️

Follow Us

Get started

  • Features
  • Pricing
  • Changelog

Resources

  • Blog
  • Documentation
  • Support

Legal

  • Terms & Conditions
  • Privacy Policy
  • Refund Policy
  • Delivery Policy

Company

  • About Us
  • Contact Us
  • Careers
Cloudeval AICloudeval AICloudeval AI
NewMCP + CLI: run Cloudeval from your terminal and IDE.
CloudevalCloudeval
Home
Features
PricingDocsMCP + CLINewRoadmapChangelog
Logo
  • Home
  • Features
  • Pricing
  • Docs
  • MCP + CLINew
  • Roadmap
  • Changelog

Socials

  • Twitter
  • LinkedIn
  • GitHub
  • Discord