DivvyCloud, now part of Rapid7, is a Cloud Security Posture Management (CSPM) solution that enables organizations to automate the detection and remediation of risks across multi-cloud environments. It provides complete visibility into cloud infrastructure, allowing security teams to continuously monitor for misconfigurations, compliance violations, and threats. DivvyCloud helps organizations enforce security policies, maintain compliance with frameworks like CIS and NIST, and reduce risk by automating remediation actions. By integrating with major cloud providers such as AWS, Azure, and Google Cloud, it ensures that security is not an afterthought but a fundamental part of cloud operations. Rapid7 enhances DivvyCloud's capabilities with its extensive security analytics and threat intelligence, enabling preemptive risk management. The platform is designed to help security teams stay ahead of attackers by identifying and mitigating risks before they become breaches.
Challenges It Solves
Misconfigurations in cloud infrastructure leading to security breaches
Lack of visibility across multi-cloud environments
Compliance violations and difficulty passing audits
Manual security processes that are slow and error-prone
Screenshots
Use Cases
Cloud Misconfiguration Management
Identify and remediate misconfigurations in cloud infrastructure to reduce risk.
Continuous Compliance Monitoring
Ensure cloud environments meet regulatory and industry compliance standards.
Threat Detection and Response
Detect potential threats in cloud environments and respond quickly.
Automated Security Operations
Automate security processes to improve efficiency and reduce manual intervention.
Pricing
Custom pricing — built for your team
DivvyCloud pricing is tailored to your organisation's size, integrations, and requirements. AiDOOS generates your proposal instantly — scoped & ready in seconds.
Free trial available — No credit card required. Full access to all features.
💡 Pricing insight from reviewers: DivvyCloud pricing is not publicly disclosed and typically requires contacting sales for a custom quote.
Key Features
Automated remediation
Automatically detects and fixes cloud misconfigurations
Multi-cloud visibility
Provides unified visibility across AWS, Azure, and Google Cloud
Compliance monitoring
Continuous compliance checks against standards like CIS and NIST
Security policy enforcement
Enforce security policies across cloud resources
Threat detection
Detect threats and suspicious activity in cloud environments
Automation and orchestration
Streamline cloud security operations with automated workflows
What Reviewers Say
What works well
Comprehensive cloud security posture management across multiple cloud providers
Automated remediation reduces manual effort and errors
Strong compliance monitoring capabilities
Common concerns
Pricing not publicly disclosed, requiring contact with sales
May have a learning curve for new users
Reviews
None
★★★☆☆
out of 5
By segment
Enterprise100%
A
Advance Software Engineer
"Great for cloud security and compliance"
It cuts down the work needed to keep my cloud setup secure and compliant. Gives better visibility and control over security. Nothing to complain about—I think it's great for managing cloud compliance. It's adaptable and helps us tackle security issues in the cloud.
I
IT Security Operations Engineer
"Good Potential, but Frustrating User Experience and Weak Integrations"
DivvyCloud gives you a single view of security across multiple clouds. It does a fair job at spotting configuration errors, and the insight-driven posture monitoring can catch common problems early. It supports a variety of cloud providers and works for keeping a basic security baseline. The main downside is how hard it is to use—the interface is confusing, sluggish, and even simple tasks like finding or filtering resources are a pain. After two years, I still struggle to get around efficiently. Vulnerability management is especially weak; it often lacks the evidence or context you need, so you waste time verifying alerts. False positives happen often, and the missing proof makes it worse. Integrations are minimal and not effective—stuff like MS Teams and Jira don't work well or are missing altogether. Exporting data has silly limits, making reporting a hassle. The posture insights are vague, and documentation is either lacking or requires you to search online. Overall, it's a tool with potential but brings more trouble than it solves. We wanted it to improve our security and streamline vulnerability handling, but it fell short on usability, lacked critical connections, and didn't give actionable info, especially for vulnerabilities. We're now looking for other options.
Reviewer Demographics
Top Industries
No data available
Company Size
No data available
Enterprise Readiness
SOC 2
ISO 27001
Identity & Access
SSO✓ SAML 2.0, Okta, Azure AD
RBAC✓ Role-based access control with custom roles and permissions.
Audit Logs✓
Data Security
At restAES-256
In transitTLS 1.2+
Key mgmtVendor-managed
SLA & Availability
Uptime SLA99.9%
RPO—
RTO—
Pen test—
Compliance & Portability
Data residencyUS, EU
Data export✓ CSV, JSON
Right to erasure✓ Supported
Integrations
AS
AWS Security Hub
Integrate AWS Security Hub findings into DivvyCloud for unified cloud security management.
Native< 1 hour⇄ Bi-directional⚡ AiDOOS Pre-wired
AZ
Azure Security Center
Connect Azure Security Center for consolidated cloud security posture management.
Native< 1 hour⇄ Bi-directional⚡ AiDOOS Pre-wired
GC
Google Cloud Security Command Center
Integrate GCP SCC to centralize vulnerability and threat findings in DivvyCloud.
Native< 1 hour⇄ Bi-directional⚡ AiDOOS Pre-wired
SN
ServiceNow
Sync DivvyCloud incidents to ServiceNow for automated ticketing and workflows.
Third_Party2-4 hours⇄ Bi-directional
JR
Jira
Create Jira tickets from DivvyCloud findings for remediation tracking.
Native< 1 hour⇄ Bi-directional
SL
Slack
Receive DivvyCloud alerts and notifications in Slack channels.
Native< 1 hour
OK
Okta
Use Okta for SSO and user provisioning in DivvyCloud.
Third_Party2-4 hours⇄ Bi-directional
KU
Kubernetes
Monitor Kubernetes clusters for misconfigurations and compliance within DivvyCloud.
Native2-4 hours⇄ Bi-directional
Governance & Compliance
EU AI Act
No data available
Data Processing Agreement
Data Processing Addendum DPA available
Sub-processors
Fully disclosed
Right to Erasure
✓ Supported
Change Notifications
No data available
NIST AI RMF
No data available
AiDOOS Managed Deployment
Deploy DivvyCloud in 72 hours
AiDOOS handles setup, CRM integration, SSO config, and user provisioning. Your team goes live — not your IT department.
12
Deployments
94%
Adoption rate
4.8/5
Post-deploy sat.
4-8 weeks
Time to value
Prerequisites
Active DivvyCloud subscription or credentials
Cloud provider accounts (AWS, Azure, GCP) with proper permissions
Administrative access to configure integrations
Outbound network access to DivvyCloud endpoints
Configuration Options
Single sign-on (SSO) integration with SAML 2.0
Configured cloud provider APIs for continuous monitoring
Customizable alerting policies and compliance frameworks
Integration with ticketing systems like ServiceNow and Jira
How DivvyCloud Compares
Product
AI & Analytics
Ease of Use
Enterprise Features
Pricing
Integrations
Mobile Experience
Quick Setup
Customer Support
Rating
Price/mo
D
DivvyCloud This product
Good
Good
Good
Fair
Good
Fair
Good
Good
—
$Custom/user
CH
CloudHealth Technologies
Good
Good
Good
Fair
Good
Fair
Good
Good
—
$Custom/user
PC
Prisma Cloud
Excellent
Good
Excellent
Fair
Excellent
Good
Good
Good
—
$Custom/user
QS
Qualys Cloud Security
Good
Good
Good
Fair
Good
Poor
Good
Good
—
$Custom/user
Virtual Delivery Center · A new delivery category
A Virtual Delivery Center for
DivvyCloud
Pre-vetted experts and AI agents in the loop, assembled as a delivery
pod. Pay in Delivery Units — universal pricing across roles,
seniority, and tech stacks. No hiring, no contracting, no procurement
cycle.
Plans from $2,000 — Starter Pack, 10 Delivery Units, 90 days
Refundable on unused Delivery Units, anytime — no questions asked
Re-delivery guarantee on acceptance miss
Pre-flight delivery sizing — you see the plan before you commit
DivvyCloud is a cloud security and compliance automation platform that helps organizations manage risk across AWS, Azure, and GCP. It provides continuous monitoring, policy enforcement, and remediation for misconfigurations and compliance violations.
How does DivvyCloud handle integrations?
DivvyCloud offers native integrations with major cloud providers and DevOps tools, as well as REST API and webhooks for custom integrations. Through AiDOOS, pre-wired integrations can be set up quickly for AWS Security Hub, Azure Security Center, and Google Cloud SCC.
Does DivvyCloud support SSO?
Yes, DivvyCloud supports SSO via SAML 2.0, allowing integration with identity providers like Okta and Azure Active Directory.
What compliance standards does DivvyCloud help with?
DivvyCloud provides compliance frameworks for standards such as CIS Benchmarks, NIST 800-53, PCI DSS, and HIPAA, automating checks and remediation.
Can DivvyCloud enforce policies in real-time?
Yes, DivvyCloud uses policy-as-code to continuously evaluate cloud resources and automatically enforce security policies, sending alerts and initiating automated remediation actions.
Is DivvyCloud easy to deploy?
With AiDOOS, DivvyCloud can be deployed in as little as 72 hours, with moderate complexity. It requires cloud provider credentials and admin access, but our team pre-configures standard integrations.