Discovery from the inside
Alongside external scanning, Active Focus integrates directly with your cloud providers — Microsoft Azure, AWS, Google Cloud, Hetzner, Digital Ocean and others. The integration is deliberately low-risk: you share a read-only security role with River Security, granting just enough access to enumerate resources and nothing that can change them. From there we continuously enumerate what is actually deployed in your environment.
Instead of guessing at your cloud footprint from the outside, we get a direct, authoritative view of what exists and how it changes — without holding any write access to your cloud. It also reaches what would otherwise stay hidden: internal assets that are never meant to be exposed to the internet, across multi-cloud setups or “just someone else’s server somewhere in the world.” And where external scanning is still the right tool, it surfaces the shadow IT and unmanaged cloud accounts spun up outside central governance — the clouds nobody told security about.
Why this beats the attackers
A threat actor scanning from the outside only sees an asset once it is exposed and discoverable. Our inside view means we often see a new or changed asset first — the moment it deploys — so we can assess it and be first to any vulnerability, not the second or third. That shrinks the window between “something new went live” and “someone tested it” to as close to real time as possible, which is exactly the window attackers rely on.
Working this closely with customers lets us turn that speed into stronger, more resilient cloud environments — tested continuously, from the inside out, before anyone else gets the chance.
