Stacklet
Cloud governance-as-code platform, built by the creators of the open-source Cloud Custodian project, that codifies and automates security, cost and compliance policy across multi-cloud environments.
Visit Website ↗ + Add to CompareOverview
Stacklet, founded in 2019 by Travis Stanfield and Kapil Thangavelu and based in Arlington, Virginia, commercializes Cloud Custodian, the open-source cloud governance-as-code project the founders originally created at Capital One. The Stacklet platform lets cloud, security and FinOps teams write policy-as-code rules that continuously scan AWS, Azure and Google Cloud resources for security misconfigurations, compliance drift and wasted spend, then automatically remediate or alert on violations. Because the underlying engine is open source and widely adopted independent of Stacklet’s commercial product, the company has built credibility with cloud engineering teams that might otherwise be skeptical of a proprietary governance tool.
The company has raised roughly $36.5 million to date, most recently a $14.5 million Series B in June 2024 led by SineWave Ventures with participation from Capital One Ventures, Foundation Capital and others — notable in that Capital One is both an investor and the origin point of the underlying Cloud Custodian technology. In 2026 Stacklet introduced Juno, an agentic AI layer intended to move customers from automated remediation toward more autonomous policy enforcement, and expanded coverage to govern AI-specific cloud resources such as Amazon Bedrock, Google Vertex AI and Azure AI Foundry.
Stacklet sits in the cloud security posture and governance space alongside larger CSPM vendors, differentiated by its open-source policy engine, developer-first policy-as-code approach, and focus on unifying security, cost and operational governance in a single rule framework rather than treating them as separate tools. At roughly 11-50 employees, it remains a small player relative to the CNAPP incumbents it competes against for enterprise cloud governance budget.
Innovation Matrix Assessment
Roughly $36.5M raised over three rounds since 2019, most recently a modest $14.5M Series B in June 2024; steady but not explosive capital velocity relative to peers in the broader cloud security posture management category.
Commercial layer built on Cloud Custodian, an open-source project with years of independent production use at large enterprises (including Capital One, where it originated), giving the underlying policy engine unusually mature real-world hardening for a company this size.
Capital One Ventures' continued participation as both strategic investor and original creator-turned-customer of the Cloud Custodian lineage is a credible signal, but the company remains small (11-50 employees) with limited public customer disclosure beyond case studies.
Policy-as-code governance unifying security, cost and compliance rules in one open, auditable framework is a genuinely different model from point CSPM tools; the 2026 Juno agentic layer pushes toward autonomous remediation rather than alert-only governance.
Efficacy claims (faster policy adoption, reduced cloud spend/risk) are drawn from vendor case studies and conference talks (FinOps X 2026); no independently audited efficacy benchmark was found.
Multi-cloud misconfiguration and governance sprawl remain a top driver of cloud breaches and wasted spend, and the expansion into governing AI cloud resources (Bedrock, Vertex, Azure AI Foundry) addresses an immediate, growing gap in most CNAPP tools.
Why CISOs Should Care
CISOs get a single, auditable policy-as-code framework spanning security, compliance and cost across AWS, Azure and GCP, built on an open-source engine their cloud engineers can inspect and extend rather than a closed black-box ruleset.
What Makes It Different
Unlike proprietary CNAPP suites, Stacklet's core detection and remediation logic is the open-source Cloud Custodian project, giving customers portability and transparency, with Stacklet's commercial value-add focused on fleet-wide management, reporting and (as of 2026) agentic autonomous enforcement via Juno.
The Matrix Verdict
57/100 — INCREMENTAL INNOVATOR
A credible, technically differentiated niche player in cloud governance with real enterprise validation via its open-source lineage, but small scale and modest funding relative to the CNAPP incumbents it competes against for budget.
Editorial Note: Claims vs. Verified Findings
Vendor-reported: Juno agentic layer capabilities and FinOps X 2026 positioning statements are drawn from company announcements and have not been independently benchmarked. Independently verified: funding amounts/investors (Business Wire), founding team and Cloud Custodian open-source origin (public GitHub project, Capital One Ventures involvement).
Sources
Alternatives to Stacklet
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…