TrustOnCloud
@trustoncloud
Followers
248
Following
107
Media
80
Statuses
185
TrustOnCloud provide cloud control catalogs for each Cloud service; based on threat models, audit-ready, and always up-to-date.
Joined January 2021
๐๐ฟ๐ถ๐ป๐ด ๐ฐ๐ผ๐ป๐๐ถ๐๐๐ฒ๐ป๐ฐ๐, ๐๐ฝ๐ฒ๐ฒ๐ฑ, ๐ฎ๐ป๐ฑ ๐ฐ๐น๐ฎ๐ฟ๐ถ๐๐ ๐๐ผ ๐ฒ๐๐ฒ๐ฟ๐ ๐ป๐ฒ๐ ๐ฐ๐น๐ผ๐๐ฑ ๐๐ผ๐ ๐ผ๐ป๐ฏ๐ผ๐ฎ๐ฟ๐ฑ. When youโre asked to support a new cloud provider, the challenges stack up quickly. Each platform has its own controls, compliance rules, and
0
0
0
๐๐ฐ๐ฐ๐ฒ๐น๐ฒ๐ฟ๐ฎ๐๐ถ๐ป๐ด ๐๐ ๐๐ฒ๐ฎ๐๐๐ฟ๐ฒ ๐ฅ๐ผ๐น๐น๐ผ๐๐๐ ๐ช๐ถ๐๐ต๐ผ๐๐ ๐๐ผ๐๐ฒ๐ฟ๐ป๐ฎ๐ป๐ฐ๐ฒ ๐๐ฎ๐ฝ๐: How one product team got AI features security-approved without the usual red tape. A global systemic bank was ready to ship new AI features on Amazon Bedrock, but security
0
0
1
5/ Your security depends on research that doesn't trust a single source. โ See how our research provides weekly updates to our threat models: https://t.co/WfhEPzgNYl
#CloudSecurity #ThreatIntelligence #GoogleCloud #BigQuery #CybersecurityResearch
trustoncloud.com
Discover how TrustOnCloud revolutionizes cloud security. Our platform seamlessly unites cloud, security, and development teams, promoting efficient and secure cloud service integration. Explore our...
0
0
1
4/ While we worked with Google Cloud to restore the BigQuery dataset, our research continued uninterrupted because we'd already built redundancy into our research process. Multiple data sources. Continuous validation. Automated gap detection.
1
0
1
3/ Here's the deeper problem we uncovered: #GCP has no single, reliable source for all release notes. Some services only publish to individual doc pages. Others appear in aggregate feeds but not in BigQuery. And some, like Valkey, don't appear in any programmatic feed at all.
1
0
0
2/ For security teams relying on this feed, that meant weeks of blind spots: no visibility into Memorystore Cluster updates, Valkey releases, or Firestore MongoDB compatibility changes.
1
0
0
๐จ Our research team found something concerning in Google Cloud. GCPโs BigQuery release notes dataset hadnโt been updated since October 16th. ๐งต๐
1
0
1
A lean cloud team expanded from AWS to GCP. โก Audited workloads in GCP in under 6 months ๐ฏ Unified security across both clouds ๐ No consultants, no chaos See how they did it ๐ https://t.co/NRUcxBDqKA
#CloudSecurity #MultiCloud #TrustOnCloud
0
0
1
๐ โBefore TrustOnCloud, every new cloud service felt like a security gamble. Now, we say yes with confidence and ship faster.โ - Executive Director, Public Cloud A Fortune 500 turned security bottlenecks into growth: โก๏ธ 70% faster onboarding ๐ฏ Controls mapped to threats ๐งฉ
0
0
2
Check out the blog by Bryce Johnson, CISSP ๐ https://t.co/YqBTsPy2zO
#cloudsecurity #gcp #policyascode #opensource
trustoncloud.com
Google Cloud Platform (GCP) custom organization policy constraints are a powerful extension of standard organization policies. While built-in organization policy constraints can cover many common...
0
0
1
Think of it as policy-as-code leveled up. Instead of relying only on defaults, you can encode your orgโs best practices directly into GCP: closing misconfig gaps before they turn into incidents.
1
0
1
๐ In this post, youโll learn: โ
YAML samples for Cloud SQL, GKE, BigQuery & more โ
Why built-in controls arenโt enough โ
How to codify best practices as enforceable policy
1
0
0
๐จ Misconfigs are still the top cause of cloud breaches. Built-in GCP org policies donโt cover every gap. We just open-sourced custom constraints to help teams lock down environments with granular, preventative controls. https://t.co/YqBTsPy2zO
1
0
1
๐ง๐ต๐ฒ ๐ผ๐ป๐ฒ ๐๐ฟ๐ถ๐ฐ๐ธ ๐๐ต๐ฎ๐ ๐บ๐ฎ๐ธ๐ฒ๐ ๐๐๐ฆ ๐ฏ๐ฒ๐ป๐ฐ๐ต๐บ๐ฎ๐ฟ๐ธ๐ถ๐ป๐ด ๐ณ๐ผ๐ฟ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐๐๐ฟ๐ฒ ๐ณ๐ฒ๐ฒ๐น ๐น๐ฒ๐๐ ๐บ๐ฎ๐ป๐๐ฎ๐น. Mapping to the CIS Microsoft Azure Foundations Benchmark can feel like a checklist chore, especially when your cloud environment
0
0
1
Using RCP in OpenSearch: Odd fit or a glimpse of the future? Read more: https://t.co/KduoRO0Ty7
0
1
1
Defining Cloud Security Controls w/ Tyson Garrett ๐ง60-sec clip on the โSecurity You Should Know podcastโ by the @cisoseries. Listen now: https://t.co/9qMsc34fpI
#CloudSecurity #CISOSeries #ThreatModeling #CloudControls #SecurityArchitecture
0
0
0
Making Cloud Threat Modeling Executable Tyson Garrett recently sat down with #SafetyDetectives to share how teams can move beyond static frameworks and bring threat modeling into real engineering workflows. Read now: https://t.co/o9wWua5SRC
0
1
1
TrustOnCloud named a Sample Vendor for Threat Modeling Automation in four 2025 Gartnerยฎ Hype Cycleโข reports: https://t.co/KlxTmTWVeu
0
1
1
๐งUnderstanding Cloud Dataflows: 60-sec clip from Security You Should Know @cisoseries Listen now:โถ๏ธ https://t.co/9qMsc34fpI
#CloudSecurity #CISOSeries #ThreatModeling
0
1
1
๐๏ธSecurity You Should Know: Our CTO Tyson Garrett joins Derek Fisher (Temple University) & Davi Ottenheimer (Inrupt) to discuss hidden #Cloud & #SaaS risks + how to tackle them. Listen now:๐ง https://t.co/9qMsc34fpI
#CloudSecurity #CISO
0
1
1