| Primary focus | Cloud infrastructure, runtime, identity | Application-layer posture | Evidence for release decisions |
| Core question | What is exposed and active in the cloud? | What application risks exist? | Does evidence satisfy policy? |
| Input | Cloud APIs, workload telemetry, identity logs | Scanner, repo, CI, agent signals | Qualified evidence from existing tools |
| Output | Exposure list, runtime alerts, posture score | Prioritized findings and posture score | Proceed, Stop, Escalate, Require authorization |
| Evidence model | Runtime observation, configuration state | Correlation, context, risk rank | Corroboration, freshness, policy version |
| Remediation proof | Configuration change, workload update | State tracked in posture | Validated fixes, not just ticket closure |