
Identity-Driven Detection and Response for Cloud Production Environments
ClearVector builds an identity-driven detection and response platform for organizations running complex cloud production environments. Founded and led by CEO John Laliberte, the company argues that endpoint and network tools retrofitted onto production infrastructure address the wrong paradigm, and that the useful question is what an identity does after it authenticates. The product is aimed at detection and response teams, incident responders, and security leaders who need to demonstrate measurable reduction in breach impact across cloud accounts and pipelines.
At the core is an identity graph assembled from AWS CloudTrail and IAM logs, GitHub audit and Actions data, Okta and federated access records, and a lightweight in-workload sensor. The graph stitches provenance chains together, tying a GitHub pull request approval through an Actions workflow and an OIDC role assumption to the resulting API call and the person behind it. Detection models are fitted per role rather than to generic rules, so a production deployment role is profiled differently from a developer test account.
The sensor is written in Rust using eBPF, runs on Docker, containerd, Kubernetes, ECS, EKS, GKE and bare EC2 or GCE instances, and attributes interactive commands arriving over SSH, SSM or ECS exec. Patented CloudDVR technology retains a searchable 30 to 90 day activity history, and alerts reach Slack or Teams in natural language within seconds. Distinctive choices include one-click isolation spanning infrastructure and workload layers, and a private SaaS deployment that keeps the entire product inside customer-controlled AWS accounts. A $13 million Series A was announced in May 2025, led by Scale Venture Partners with Okta Ventures, Inner Loop Capital and Menlo Ventures.



