What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Exact split between the source-available components and the commercial platform: confirm against vendor licensing documentation
- Full provider and resource coverage of the query layer: verify against vendor documentation
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Mondoo is built on top of cnquery, an open-source query engine that exposes heterogeneous infrastructure through a uniform resource model. You ask questions like "return every instance whose security groups permit SSH ingress from anywhere", and the same syntax works whether the target is a cloud API, a Linux host over SSH, a container image, a Kubernetes cluster or a Terraform file on disk. Policies, written in a companion policy language, are collections of those queries with expected results, scoring and remediation guidance.
The commercial platform adds the parts a query engine alone does not give you: persistent asset inventory, scheduled scanning, policy distribution across fleets, exception handling and workflow, historical scoring and compliance reporting against benchmarks such as CIS. The same policy bundles run in CI against IaC, so the check applied to a live host matches the check applied to the code that builds it.
Where it fits
Mondoo spans the lifecycle deliberately. The CLI runs on a laptop or in a pipeline against Terraform and container images, while the platform runs continuously against cloud accounts, virtual machines and clusters. It is operated by security or platform engineering rather than application developers. The prerequisite is credential and network reach: to assess a host you need to get to it, and to assess a cloud account you need a sufficiently broad read role.
Strengths
- One query language across cloud APIs, operating systems, containers and IaC, so a control can be expressed once and checked at every stage.
- The query layer is genuinely useful outside of security policy, doubling as an ad hoc inventory and investigation tool.
- Policies as versioned bundles make it practical to distribute an organization-wide baseline and track drift from it.
- Open-source core means the query and policy logic can be inspected and run independently of the commercial platform.
Limitations
- The query language is another thing to learn, and the resource model has to be understood before you can write anything nontrivial.
- The source-available license on the platform components is not equivalent to a permissive open-source license, and the practical boundary between free and commercial functionality needs checking against current terms.
- Smaller ecosystem than the dominant CNAPP vendors, so third-party integrations, community policy content and hiring for existing skills are all thinner.
Who it suits
A good fit for platform and security engineering teams that think in terms of queryable infrastructure state and want the same control checked in code and in production. Less compelling for organizations that want a turnkey posture dashboard with minimal authoring, or for those already committed to a large CNAPP whose coverage overlaps heavily.
Used Mondoo? Recommend it under your own name and title.
Recommend this tool