← Blog

Your scanner was never the problem.

The 150 days after it were.

Your scanner was never the problem.

There is a number on your dashboard that only goes up. You bought the scanner to find things, and it found them: 735 last quarter, in one account. Then somebody asked how many were closed, and the number that only goes up became your number.

Here is the part that never makes it into the QBR: 718 of the 735 were the same seventeen problems, counted again.

Your scanner was never the problem. The 150 days after it were.

In one sentence: Tamnoon is the self-healing engine for cloud exposures. It reads every finding from every scanner you run, gives it a verdict, closes what it can prove safe through your own change process, and declines the rest in writing, with the evidence.

What you actually bought

A scanner is built to find, and yours finds well. Detection takes seconds. A critical finding then takes a median of 150 days to heal, up from 128 last year, across 800 cloud accounts and ten CNAPPs (State of Cloud Remediation 2026). Nobody sold you the 150 days. They came with the seconds.

Every scanner ships a Remediate button. It can act on its own findings, in its own console, with no idea what the change touches or what depends on it. It cannot say no. So it stays off, and careful means manual.

And when you run two scanners, you get two truths. One says critical, the other says medium, the ticket says neither. Somebody has to decide, and it is usually the person who signed the purchase order.

The number nobody puts in the QBR

The queue does not grow because your team is slow. It grows because the same problem is counted again every time a scanner looks at it from a new angle. On average, 142 alerts trace back to one piece of work. The 735 in that one account were seventeen.

It also grows because the same findings keep coming back. Eight of them make up one alert in five, and the list barely changed from last year. Closed as tickets, reopened as drift, counted as new.

One alert in five is one of these eight.

The eight, by share of all alerts. State of Cloud Remediation 2026: 14.86M CNAPP detections, 800 cloud accounts, 10 CNAPPs. Tick the ones you have.

So the number that only goes up is mostly the number of times you have been told about the same thing. That is not a finding. That is a filing system.

One standard, whichever scanner found it

The engine reads every finding from every scanner you run, exactly as it is. It groups what belongs together and reads, read-only, what a careful engineer would read before touching anything: who uses it, what depends on it, who owns it, what changed last week.

Then every piece of work gets one of three answers. SAFE: the change is proven safe for this environment and runs through your own change process, rollback attached. RISKY: it cannot be proven safe, so it is declined in writing, with the evidence and a manual path for the owner. AWAITING DATA: one thing is missing, and it asks for it instead of guessing.

Your scanner keeps its job. It finds; Tamnoon answers. The finding closes in the console you already work in, confirmed by the rescan, and the written no goes on the record next to the yes.

Keep the scanner. Add the verdict.

For every scanner you run

The one-page version.

Judgment before action.

Here is your one-pager.

Download the PDF →

That did not go through. Try again, or write to [email protected].

For every scanner you run

The number that went down

One customer's quarterly reviews, four quarters running: 6,074 open findings to 2,041. Three times fewer, with the same scanners they had on day one. And 93% fewer new alerts arriving each quarter, because what heals once stays healed and the eight stop coming back. Single customer, not an average.

That is a QBR slide. The slide after it is the one auditors like more: every decline, in writing, with the evidence. A written no is work done too, and it is the only line on a remediation slide a board can actually check.

Ask any vendor. Including us.

Does it give a verdict on findings from every scanner we run, or only its own?

Show the full trail for one closed finding, rescan included.

Can our auditor read every change without a translator?

Bring the scanner with your worst backlog.

Watch mode is read-only. Thirty minutes to connect. Hours later you know what heals without you, what it declines, and why, on your real findings. The first thing you see is a refusal. Put that one in the QBR too.

Everyone automates the yes. We mastered the no.

Whoever finds it, Tamnoon answers it.

Notes from the Healing Gap.

Teardowns, CTF write-ups and field notes from the people who close cloud findings for a living.

You're subscribed.

That did not go through. Try again, or write to [email protected].

At most one email a month. Unsubscribe from any of them.