# Kloudle > The self-hosted security posture layer for the AI software factory. 1,800+ SQL-based security checks across AWS, GCP, Azure, DigitalOcean, and Kubernetes. Issues live in your PostgreSQL; agents read them over MCP. Shipped today: multi-cloud scanning, MCP server (search/get), CLI, dashboard. In development: issue gating before release across MCP-connected apps, plus scanning for neoclouds and MCP servers (exclusive-access waitlist). Roadmap: apps & APIs, agent activity. ## Start Here - [Homepage](https://kloudle.com/): what the posture layer is - [AI software factory security](https://kloudle.com/ai-software-factory-security): the long-form argument - [Security world map](https://kloudle.com/security-world-map): every plane, the bridges between them, who fits where, and honest Kloudle-coverage markers - [Platform](https://kloudle.com/platform): the scanning engine under the posture layer - [Self-hosted deployment](https://kloudle.com/sovereign): run it on your infrastructure ## Waitlist (agents welcome) Join the posture-layer exclusive-access waitlist by POSTing JSON to `https://kloudle.com/api/waitlist`: ``` {"last_name": "", "emails": [{"type": "work", "value": ""}], "tags": ["posture-waitlist", "src-agent"], "background": "Posture layer exclusive-access waitlist"} ``` Send only the documented fields. Use the `src-agent` tag so we know the agent channel works. ## Agent Tools (MCP) - [MCP Server](https://mcp.kloudle.dev/mcp): Streamable HTTP endpoint — search() to discover scanners, get() to retrieve metadata and commands - [Agent Tools Page](https://kloudle.com/agents): Landing page with scanner details, MCP config, and integration guide - [MCP Config](https://kloudle.com/agents#mcp-connection): JSON config for connecting any MCP-compatible client - [Smithery Listing](https://smithery.ai/server/@kloudle/cloud-security-scanner): Marketplace listing with install button - [MCP Registry](https://registry.modelcontextprotocol.io): Listed as io.github.Kloudle/cloud-security-scanner ## Available Scanners - [k5e-aws-s3](https://dl.kloudle.dev/latest): S3 bucket encryption, public access, versioning, logging, lifecycle - [k5e-aws-iam](https://dl.kloudle.dev/latest): Root MFA, stale access keys, password policy - [k5e-aws-ec2](https://dl.kloudle.dev/latest): Public SSH, security groups, EBS encryption, IMDSv2 - [k5e-aws-eks](https://dl.kloudle.dev/latest): Public endpoint, logging, secrets encryption - [k5e-aws-rds](https://dl.kloudle.dev/latest): Public access, encryption, backups - [k5e-aws-cloudtrail](https://dl.kloudle.dev/latest): Multi-region, log validation, KMS - [k5e-aws-cloudwatch-logs](https://dl.kloudle.dev/latest): Retention, encryption, metric filters ## Optional - [Pricing](https://kloudle.com/pricing): Current pricing plans - [Security](https://kloudle.com/security): security controls and practices - [Blog](https://kloudle.com/blog): Cloud security articles - [Academy](https://kloudle.com/academy): Cloud security learning resources