AI-powered security posture analysis for cloud infrastructure environments.
Analyzes your network topology, existing security tools, and compliance requirements to produce:
- Risk score (0-100) with overall risk level (Critical / High / Medium / Low)
- Security gaps table — color-coded by severity, sorted Critical first
- Hardening recommendations table — prioritized by urgency (Immediate / Short-term / Medium-term)
- 90-day action plan — phased remediation roadmap
- Export to Excel — 4-tab spreadsheet ready to share with stakeholders
Launch Cloud Network Security Advisor
- Open the live demo link above
- Enter your OpenAI or Anthropic API key or use Demo Mode
- Describe your network environment or load the sample scenario
- Select your current security tools and compliance requirements
- Click Analyze security posture
Built as part of the AI portfolio — a collection of AI-powered tools that automate real workflows from cloud infrastructure, networking & security, and telco domains.
This agent maps directly to security hardening work delivered at VMware Explore and VMUG, where the VCF Security Hardening session was recognized as a top session at VMware Explore Las Vegas 2023.
- Claude API (Anthropic) — claude-haiku-4-5
- OpenAI API - gpt-4o-mini
- Vanilla HTML / CSS / JavaScript — no frameworks, no dependencies
- SheetJS — Excel export
- Tabler Icons
The application separates environment discovery, risk scoring, gap analysis, recommendation generation, roadmap creation, and export. It does not scan infrastructure, validate implemented controls, remediate findings, or certify compliance.
Deterministic: score ranges, risk-level mappings, severity and urgency categories, output structures, roadmap phases, export layout, and demo values.
AI-generated: gap explanations, remediation recommendations, prioritization rationale, executive narrative, and roadmap details.
Current controls include required-input checks, structured severity categories, ordered risk and remediation tables, predefined roadmap phases, export formatting, and manual browser testing.
Security note: Do not enter production or long-lived API credentials into the public browser demonstration. Use Demo Mode for evaluation without a key.
Do not submit confidential architecture diagrams, credentials, IP addresses, vulnerability details, regulated data, or customer information. The application does not connect to cloud accounts, firewalls, SIEM, CSPM, or vulnerability-management platforms.
Current testing covers inputs, scenarios, score rendering, ordering, recommendation generation, spreadsheet export, and responsive behavior. Production use requires automated scoring, schema, prompt-regression, adversarial, evidence-validation, accessibility, and security testing.
This is not a formal security assessment. It does not validate actual control implementation or exploitability. Results depend on user-provided data, and compliance references do not establish compliance.
This project is provided for demonstration and educational purposes and does not constitute security, legal, regulatory, compliance, or risk-management advice.
Daniel Mazzini — Principal Architect & Senior TPM Cloud & Infrastructure · Pre-Sales & Services Portfolio · Telco · Automation LinkedIn