FortiCNAPP raises the alert. Tamnoon returns an answer, with its evidence.

Enrich and correlate Lacework FortiCNAPP alerts to provide deeper context, enabling more efficient remediation and clearer resolution of security issues.

No scanner to replace. No contract to end.
Nothing to install in production.

FortiCNAPP alerts, plus the context that decides them Safe
Risky
Awaiting data

FortiCNAPP found it in minutes. The finding is still open in month five.

53 percent of everything ever detected is still open. The State of Cloud Remediation 2026, 14.86M detections across hundreds of enterprise environments.

FortiCNAPP alone

FortiCNAPP plus Tamnoon

A compliance alert opens

Policy violated, remediation steps attached, queued

The finding

Investigated read-only, then rated

A composite alert forms

Seven or eight small signals correlated into one high-confidence alert

The finding

Read as evidence: the anomaly beside the misconfiguration it touched

Identical violations

One policy, one answer

The finding

Six buckets, three answers

Safe

Risky

Awaiting data

What cannot be proven safe

Stays open

The finding

Risky

Declined, with the reason attached

The safe ones

Wait for an engineer

The finding

Safe

Closed on your execution plane

After detection, three questions are left standing:

What stays open is the residue: the security group violation whose revoke command would cut live traffic, the composite alert whose supporting facts point at a misconfiguration nobody owns. Tamnoon reads the alert and its supporting facts, investigates read-only, and returns a verdict with the evidence attached, so the alert that took 8 signals to raise does not wait 8 weeks for an answer.

Is this fix safe here?

Who answers for it?

Will it stay closed?

A FortiCNAPP alert, after the engine has read it.

The queue carries the environment facts that decide the answer. The record carries the change, the owner, the rollback and where it lands in your ticketing.

RecommendationRevoke the overly permissive ingress rule safely
Made with Tamnoon
Environment
PROD
Exposure
Public
Encryption
True
Resource
Security Group
Crown jewel
1
Owner
J. Doe
ScannerSeverityFindingEnvironment factVerdict
FortiCNAPPCriticalCompliance alert: security group ingress open to an overly permissive scopeno matched traffic in 90 daysSafe
FortiCNAPPHighComposite alert: Potentially Compromised AWS Keys, supporting facts attached2 services, live trafficRisky
FortiCNAPPMediumCompliance alert: S3 bucket without default encryptionowner unresolvedAwaiting data
Create an initiative from this recommendation? AcceptReject
TMN-39548 · Security group ingress rule, unused scopeSafe to remediate
RecordEvidenceTicket
PriorityInvestigatedCloud providerAssetStatusLands in
Mediumread-only, 07:40AWSsg-payments-prod-036Safe
Jira

Read-only investigation runs before anything is proposed, and it is the evidence attached to whichever answer comes back. Identifiers on this page are fictional.

Three FortiCNAPP alerts. Three different answers.

TMN-39545FortiCNAPP
Compliance alert: ingress rule open to an overly permissive scope. Flow logs show no matched traffic in 90 days and no dependency on the rule.
Investigatedread-only, 06:47
Changerule revoked
Rollbackready before execution
Safeclosed 06:48

Closed at machine speed on your audit trail. The violation passes on reassessment.

TMN-39545
FortiCNAPP
Compliance alert: ingress rule open to an overly permissive scope. Flow logs show no matched traffic in 90 days and no dependency on the rule.
Investigated
read-only, 06:47
Change
rule revoked
Rollback
ready before execution
Safe closed 06:48

Closed at machine speed on your audit trail. The violation passes on reassessment.

TMN-39546FortiCNAPP
Identical policy, identical severity. This rule carries live traffic from two services, and the revoke command would cut both.
Investigatedread-only, 06:47
Dependents2 services, live
Changenot executed
Riskydeclined 06:48

Refused, with the reason. The change that would have caused the 3am page was refused at two.

TMN-39546
FortiCNAPP
Identical policy, identical severity. This rule carries live traffic from two services, and the revoke command would cut both.
Investigated
read-only, 06:47
Dependents
2 services, live
Change
not executed
Risky declined 06:48

Refused, with the reason. The change that would have caused the 3am page was refused at two.

TMN-39547FortiCNAPP
Compliance alert: S3 bucket without default encryption. The owning team cannot be resolved from tags or recent activity.
Investigatedread-only, 06:47
Ownerunresolved
Changenothing touched
Awaiting dataasked 06:48

A third answer, chosen. Ownership could not be resolved, so nothing was touched and the missing context was requested. It does not guess.

TMN-39547
FortiCNAPP
Compliance alert: S3 bucket without default encryption. The owning team cannot be resolved from tags or recent activity.
Investigated
read-only, 06:47
Owner
unresolved
Change
nothing touched
Awaiting data asked 06:48

A third answer, chosen. Ownership could not be resolved, so nothing was touched and the missing context was requested. It does not guess.

Identifiers fictional · one healed never travels without the declines beside it

Tamnoon reads FortiCNAPP findings.

Through the Lacework API, read access only. No scanner change, no re-scan, no second agent in production.

Tamnoon investigates before it touches anything.

Live traffic, usage, dependencies and ownership, all read-only.

Tamnoon executes through your change process.

Under your IAM policies, on your audit trail, with rollback defined first.

Tamnoon carries over when you switch.

Move scanners and every judgment already made comes with you.

Tamnoon executes through your change process, not around it.

Findings from your scanner, context from your cloud, changes on your execution plane.

What teams running FortiCNAPP ask first.

How is this different from self-healing infrastructure?
+

Self-healing infrastructure restores desired state: a pod restarts, an instance is replaced, a group scales back up. It is availability automation and it exercises no judgment about safety. Tamnoon heals the security posture instead: it investigates the finding in context, decides whether a change is safe to make at all, refuses what it cannot prove, and leaves the receipt behind. Restarting a pod is not the same as knowing which bucket must stay public.

How is this different from FortiCNAPP’s own remediation?
+

FortiCNAPP automates hygiene on its own findings. Tamnoon works on what remains after that. It investigates each alert read-only in your live environment, groups things together to increase efficiency of each action instead of going a single alert at a time, closes what it can prove safe through your own change process, declines what it cannot with the evidence why, and answers for the outcome.

What happens to composite alerts?
+

A composite alert is a story, and Tamnoon reads it as evidence. When Potentially Compromised AWS Keys arrives with its supporting facts, the posture questions underneath it, the unused key, the permissive policy, the unrotated secret, are investigated read-only and answered one by one. The behavioral response stays with your SOC, where it belongs.

Do we have to change our FortiCNAPP setup?
+

No. Tamnoon sits downstream of the FortiCNAPP you already run, reading alerts through the API with read access. Your policies, alert rules and channels stay exactly as they are. No scanner to replace, no contract to end.

We were burned by auto-remediation. Why is this different?
+

A tool that fires fixes blind is an autoimmune reaction: it attacks the body it is supposed to protect. Tamnoon starts from the opposite premise. Every fix is investigated read-only first, against live traffic, usage, dependencies and ownership. What it cannot prove safe it refuses, and the refusal ships with the evidence why. You were not wrong to pull the plug on a tool that could not tell you why a change was safe.

What do I tell my change advisory board?
+

They approve a change class, not a black box. Starting mode is SAFE-only: the engine closes only the class of change your board has approved, through your own change process, under your IAM policies, on your audit trail. Autonomy widens on evidence, class by class, and every decision leaves a record your auditor can read.

See the engine run against your own FortiCNAPP.

Read-only, in the first meeting. Live discrimination, a live refusal, and a live safe heal.