runred.ai connects your application source code with live GCP infrastructure context — discovering critical exposures, verifying every patch automatically, and generating audit-ready compliance logs. Zero manual effort.
The Reality
Traditional scanners operate in isolation. They read code. They don't know that your
Cloud Run service is exposed to allUsers,
that there is no VPC connector, or that a compromised parameter hits a Cloud SQL instance
with no authorised networks restriction. runred does.
Live Simulation
Capabilities
Static analysis fused with live GCP infrastructure data — IAM bindings, network topology, Cloud Run ingress rules — to accurately score real-world risk, not theoretical risk.
Every proposed fix is validated by an automatically generated integration test that first confirms the exploit, then confirms the patch closes it. No patch ships unverified.
Every scan, finding, exploit test, and patch is written to an immutable audit trail in Cloud Logging — pre-formatted for NIS2, SOC2 Type II, and ISO 27001 evidence requirements.
Integration
runred.ai operates as an extension of your developer agent environment. No separate security toolchain. No context switching. It runs where code is written, using the GCP credentials already in scope.
Authorise runred against your GCP project. Read-only IAM access. No infrastructure changes required.
Trigger on commit, PR, or ad-hoc. runred scans your codebase and correlates findings against live GCP topology.
Review the verified patch proposal. Confirm. The audit log is written automatically to Cloud Logging.
Compliance Coverage
Compliance is an outcome, not a checklist. Every runred pipeline run generates traceable, timestamped evidence mapped to the specific control requirements auditors expect.
Open to all engineering teams running production workloads on GCP. Particularly useful if your organisation is subject to NIS2, SOC2, or ISO 27001 audit requirements.
You're on the list.
We review applications manually and will reach out when we open your slot.
No credit card required. Enterprise NDA available on request.