One practitioner, one honest scanner.
Plexavo is built and maintained by Kavee, a cloud security practitioner and security researcher. It exists because most small teams run everything on the cloud with nobody whose job is to watch it.
Kavee
I work in cloud and identity security, across AWS, Azure and GCP, and on Active Directory and hybrid identity. My day to day is a mix of hands-on security assessments, privilege-escalation and misconfiguration research, and reading a lot of policy documents so other people do not have to.
Most of the accounts I look at were not set up carelessly. They were set up by people with a product to ship and no security specialist on the team, and the defaults quietly added up. Plexavo is the tool I wanted to be able to hand those teams: something that finds the real problems, explains what an attacker would do with each one, and gives the exact fix.
It is open source on purpose. If a scanner tells you your account is fine, you should be able to read the check that decided that.
- Cloud
- AWS, Azure, GCP: IAM and RBAC, privilege escalation, exposed storage and network, logging and detection gaps.
- Identity
- Active Directory, Entra ID, hybrid identity, trust relationships and delegation.
- Research
- Misconfiguration patterns, attack-path analysis, turning findings into plain-English remediation.
How Plexavo is run.
Open source, AGPL-3.0
The detection logic is the repo, not a thin client around a closed API. Read it, run it, send a PR.
Zero telemetry
Nothing about your account or your scans is ever sent anywhere. It runs on your own credentials, locally.
Tested in the open
Every check has a published test matrix, and anyone who finds a genuine miss gets credited in the Hall of Bugs.
Get in touch
Questions, a missed finding, or an AWS account you want a second pair of eyes on. All of it is welcome.