Built for Azure. Only Azure.
Every rule, every resource type, every evidence record assumes one cloud. That assumption is the product.
The multi-cloud trade-off
A platform that covers three clouds evaluates what those clouds have in common. Provider-specific resource types and properties get shallower treatment, because depth in one cloud does not sell in the other two.
If your estate is entirely on Azure, that trade-off costs you twice: you pay for coverage you will never use, and you lose evaluation depth exactly where your regulator will look.
What single-cloud focus buys you
Property-level evaluation
Rules evaluate the actual ARM resource property, not an abstracted control. Expected value, actual value, result.
Managed Identity throughout
Managed Identity and Microsoft Entra External ID throughout. No stored credentials, no service principals to rotate, no secrets to leak.
Subscription as audit boundary
Frameworks certify a scope, and in Azure that scope is the subscription. Evidence is scoped to it and named for it.
Marketplace and MACC
Available through Azure Marketplace, so spend decrements your Microsoft Azure Consumption Commitment instead of opening a new procurement.
What this is not
This is not a security tool. It does not block, quarantine, patch, enforce, or remediate. It holds no write access to your estate and no code path exists that could be enabled to add one.
It reads the state of your subscriptions and turns that state into per-framework, per-subscription evidence, written once and retained for seven years. Whatever else you run to secure and govern your estate, keep running it. This answers a different question.