frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: PolicyCortex – AI agent that autonomously remediates cloud misconfigs

https://policycortex.com
1•policycortex•1h ago

Comments

policycortex•1h ago
I've spent 12 years in DoD/DoE environments watching the same failure mode: a storage bucket gets misconfigured, five different tools alert on it, and it takes three days to fix because every tool detects but none of them acts. PolicyCortex is my attempt to build the tool that actually closes the loop.

What it does

PolicyCortex is an autonomous cloud engineer. When it detects a violation -- say, a publicly accessible Azure Storage account -- it doesn't just fire an alert. It authenticates with Azure via managed identity or service principal, analyzes the configuration, disables public blob access, creates a private endpoint, updates the associated NSG rules, verifies encryption is enabled, runs a compliance check, and generates an audit trail. That full 8-step sequence completes in under 3 minutes. No human touch required -- unless you want it.

The "safety sandwich" / Gated Mode

The thing I was most careful about: any write operation requires explicit human approval before execution. The AI agent (we call it Xovyr) does all the analysis -- proposes the remediation steps, calculates blast radius, explains business and security impact -- then pauses and waits. A human reviews, approves, and then it executes.

I'm calling this the "safety sandwich" internally. Autonomous analysis + human-gated writes + autonomous execution post-approval. The goal is to get the cognitive load off engineers without removing their override authority. This feels like the right default for anything touching production infrastructure.

Technical architecture (current state)

- Policy engine evaluates resources against a ruleset (currently 155 Azure governance checks). Violations are scored by an AI layer for confidence. Auto-remediation only triggers at 85%+ confidence; lower-confidence findings surface for human review.

- Remediation actions call Azure Resource Manager APIs, Azure Storage Management APIs, and Azure Network Management APIs directly -- not a wrapper around the CLI. Each action is idempotent and logged.

- Audit trail is generated as a byproduct of every operation: timestamp, caller identity, before/after state, API response codes. This is what feeds our ATO evidence packs (CMMC L2/L3, NIST 800-171, FedRAMP Moderate).

- FinOps module polls Azure Cost Management APIs on a configurable interval for real-time anomaly detection and 30/60/90-day forecasting.

- AI Observability tracks LLM API spend for teams running models in Azure (OpenAI, etc.).

Honest about stage

Pre-revenue. Azure-only today. AWS is next. We have design partners but no paying customers yet. The autonomous remediation piece works in controlled environments; I'm being careful about hardening it before pushing for wider production use.

The hardest problems so far: (1) making the AI's remediation reasoning auditable enough that a compliance officer will trust it, and (2) handling blast-radius edge cases where "fix the misconfiguration" has unintended downstream effects on dependent resources.

What I'd love feedback on

- What would make you trust an AI agent to hold write permissions in your production cloud? - How are you handling the ATO evidence problem today? - Anyone solved the "policy as code + real-time enforcement" problem in a way they're happy with?

Demo and more at https://policycortex.com. Happy to answer technical questions here.

-- Leonard (founder, 12 yrs DoD/DoE, Dallas TX)

Secure Snake Home (SSH)

https://snake.eieio.games
1•fratellobigio•34s ago•0 comments

How AI Is Turbocharging the War in Iran

https://www.wsj.com/tech/ai/how-ai-is-turbocharging-the-war-in-iran-aca59002
1•JumpCrisscross•5m ago•0 comments

Anthropic and The Pentagon

https://www.schneier.com/blog/archives/2026/03/anthropic-and-the-pentagon.htmll
1•benwen•6m ago•0 comments

British Columbia makes daylight saving time permanent

https://text.npr.org/nx-s1-5741076
1•bvanderveen•6m ago•0 comments

Will the U.S. confirm that aliens exist before 2027?

https://kalshi.com/markets/kxaliens/aliens/KXALIENS-27
1•pinkmuffinere•8m ago•0 comments

Metrics Make Us Miserable

https://www.derekthompson.org/p/how-metrics-make-us-miserable
1•gmays•9m ago•0 comments

Best Music Distributors in 2026

1•anonyxbiz•15m ago•0 comments

Pushing and Pulling: Three Reactivity Algorithms

https://jonathan-frere.com/posts/reactivity-algorithms/
1•frogulis•22m ago•0 comments

Science Fiction Is Dying. Long Live Post Sci-Fi?

https://www.typebarmagazine.com/science-fiction-is-dying-long-live-post-sci-fi/
2•KittenInABox•22m ago•0 comments

On the road to C4 rice: Advances and perspectives

https://onlinelibrary.wiley.com/doi/full/10.1111/tpj.14562
1•lawrenceyan•27m ago•0 comments

The Intelligence Monopoly Is Over

https://www.spatialintelligence.ai/p/the-intelligence-monopoly-is-over
1•beauzero•27m ago•1 comments

Why can't you just ask AI to find you a trading edge? You can now

https://github.com/augiemazza/varrd
1•varrd1•27m ago•1 comments

Cloud VM benchmarks 2026: performance/price for 44 VM types over 7 providers

https://devblog.ecuadors.net/cloud-vm-benchmarks-2026-performance-price-1i1m.html
3•dkechag•35m ago•0 comments

Human brain cells on a chip learned to play Doom in a week

https://www.newscientist.com/article/2517389-human-brain-cells-on-a-chip-learned-to-play-doom-in-...
3•doener•44m ago•0 comments

The San Francisco lunch that launched Silicon Valley 70 years ago

https://davidlaws.medium.com/the-san-francisco-lunch-that-launched-silicon-valley-70-years-ago-3b...
2•DavidLawsCHM•45m ago•0 comments

NexusMods (game modding application for Linux) code repo is now read-only

https://github.com/Nexus-Mods/NexusMods.App
1•wingmanjd•47m ago•1 comments

ClawPurse Micropayment Ecosystem

https://clawpurse.ai/
2•TheTikiCow•49m ago•0 comments

Ask HN: Last time you wrote code?

2•blinkbat•51m ago•1 comments

What's the deal with distributed SYN DOS attacks

2•xmddmx•52m ago•0 comments

PressPuzzler AI Crosswrod Puzzle Maker

https://presspuzzler.com/
1•aidevguy•52m ago•0 comments

Blocking a common brain gas reverses autism-like traits in mice

https://www.psypost.org/blocking-a-common-brain-gas-reverses-autism-like-traits-in-mice/
3•geox•58m ago•1 comments

MuJS: Lightweight JavaScript interpreter for embedding in other software

https://mujs.com
2•linkdd•1h ago•0 comments

I don't know if my job will still exist in ten years

https://www.seangoedecke.com/will-my-job-still-exist/
4•nomdep•1h ago•0 comments

AI Powered Exploit Kit

https://github.com/Ed1s0nZ/CyberStrikeAI
1•jwally•1h ago•0 comments

Hitchhiker's Guide to Hitchhiking

https://www.mikokacki.me/blog/hitchhikers-guide-to-hitchhiking
1•samiczy•1h ago•0 comments

Show HN: Scalisos – A privacy-first, ad-free passport photo layout tool

https://scalisos.com
2•theborat•1h ago•0 comments

My chief of staff, Claude Code

https://twitter.com/jimprosser/status/2029699731539255640
2•mji•1h ago•6 comments

White House Unveils President Trump's Cyber Strategy for America

https://www.whitehouse.gov/articles/2026/03/white-house-unveils-president-trumps-cyber-strategy-f...
2•campuscodi•1h ago•0 comments

Patel gutted FBI counterintelligence team tasked with tracking Iranian threats

https://www.cnn.com/2026/03/03/politics/patel-fbi-national-security-division-firings-iran
12•doener•1h ago•1 comments

My Dev Box Setup Script

https://rlafuente.com/posts/2026-3-7-my-dev-box-setup-script
1•andes314•1h ago•1 comments