How it works

How the audit works

We read every account in your organization using a role that is mechanically incapable of changing anything, and hand back a report you can forward to your auditor, your insurer, or your largest customer's security review.

01 — The problem

Every AWS account drifts. Yours has been drifting for years.

Not through negligence. Through velocity. A security group opened for a demo in 2023. A NAT gateway serving traffic nobody profiles. A bucket made public on purpose, by someone who has since left. An RDS snapshot from a migration that finished.

None of it shows up in a dashboard, because a dashboard shows you what you asked it to watch. The things that hurt are the things nobody thought to watch.

  • → You cannot name every account in your organization from memory.
  • → Nobody can say when CloudTrail was last verified as delivering.
  • → Your AWS bill grows faster than your traffic and nobody owns the gap.
  • → An enterprise prospect just sent a 90-question security questionnaire.
  • → The person who built the account left, and the runbook is their memory.
02 — Coverage

Four pillars. Named resources. No "consider reviewing your posture."

SECSecurity

  • Public S3 buckets, and whether they're public on purpose
  • Security groups open to the world, by port and by resource
  • IAM: stale keys, unused roles, over-broad policies, missing MFA
  • CloudTrail coverage, log file validation, delivery gaps
  • Encryption at rest across EBS, RDS, S3 and snapshots

NETNetworking

  • Which subnets are genuinely public, derived from route tables
  • VPC flow logs: present, absent, or delivering nowhere
  • NAT gateway placement and what it actually processed
  • Load balancer listeners, TLS policies and certificate expiry
  • Peering, endpoints and cross-AZ traffic paths

FINCost

  • Unattached EBS volumes and orphaned snapshots, in dollars
  • Idle load balancers, unused elastic IPs, forgotten environments
  • Previous-generation EC2 and RDS instances, and public IPv4 addresses nothing can reach
  • Savings Plans, Reserved Instances, right-sizing and Graviton — AWS's own Cost Optimization Hub recommendations, priced at AWS's own dollar estimate with commitment, term and payment option
  • Lifecycle gaps on log and backup storage
  • Savings kept strictly separate from spend merely located, and never double-counted against AWS's own recommendations

RELReliability

  • Single-AZ resources that were never meant to be
  • Backups configured, and backups actually running
  • Multi-region posture and real failure domains
  • Autoscaling, health checks and deployment safety
  • Service quotas you are quietly approaching

Every finding names the resource, the region and the account. Where something could not be assessed — missing permission, disabled service, unavailable API — the report says NOT ASSESSED rather than scoring it as a pass. A gap you know about is worth more than a clean number you can't trust.

The cost section states plainly what it did not price, every time. AWS's own Savings Plans, Reserved Instances, right-sizing and Graviton recommendations depend on your account having opted into Cost Optimization Hub — if it hasn't, the report says so instead of implying there was nothing to find. A handful of areas — CloudWatch Logs retention, S3 storage class and lifecycle waste, and data transfer beyond NAT gateway processing — aren't priced at all yet, and the report names each one outright. A low total should read as exactly what was measured, never as "nothing to fix."

03 — Access

Read-only access, enforced in code.

A limited IAM role and an API guard prevent changes to your account.

Reviewable role

Inspect or tighten the CloudFormation template before deploying it.

No secret access

Secret values, session tokens and credentials are blocked.

Revocable access

You generate the ExternalId. Delete the stack to revoke access; no access keys are issued.

Configuration only

No bucket objects, database rows or queue messages are read.

04 — How it runs

Five steps. About a week. Most of it is not your time.

  1. 01

    Scoping call

    Thirty minutes. How many accounts, which regions, who owns access, what you're actually worried about. You get a single fixed number at the end of it — not a range.

    30 min · your time
  2. 02

    You deploy a read-only role

    We hand you a CloudFormation template (or a StackSet for an organization). Your team reads it, your security team reviews it, you deploy it. We never hold a credential of yours.

    1–2 hrs · your team
  3. 03

    Collection

    Automated, read-only, and it produces a reproducible evidence file rather than a screenshot. The same evidence can regenerate the same report a year from now.

    ~30 min · automated
  4. 04

    Triage and narrative

    The slow part, and the part you're actually paying for. False positives filtered out, severity assigned by real exposure, business context added, and the findings ordered so that acting on the first six already pays for the engagement.

    Several days · our time
  5. 05

    Report and findings call

    You get the document and an hour to walk through it. Then you decide whether to fix it yourself or scope the work with us. The report is written so that either choice is genuinely open.

    1 hr · your team

Let's find out what's in there.