How it works
How the audit works
We read every account in your organization using a role that is mechanically incapable of changing anything, and hand back a report you can forward to your auditor, your insurer, or your largest customer's security review.
02 — Coverage
Four pillars. Named resources. No "consider reviewing your posture."
SECSecurity
- Public S3 buckets, and whether they're public on purpose
- Security groups open to the world, by port and by resource
- IAM: stale keys, unused roles, over-broad policies, missing MFA
- CloudTrail coverage, log file validation, delivery gaps
- Encryption at rest across EBS, RDS, S3 and snapshots
NETNetworking
- Which subnets are genuinely public, derived from route tables
- VPC flow logs: present, absent, or delivering nowhere
- NAT gateway placement and what it actually processed
- Load balancer listeners, TLS policies and certificate expiry
- Peering, endpoints and cross-AZ traffic paths
FINCost
- Unattached EBS volumes and orphaned snapshots, in dollars
- Idle load balancers, unused elastic IPs, forgotten environments
- Previous-generation EC2 and RDS instances, and public IPv4 addresses nothing can reach
- Savings Plans, Reserved Instances, right-sizing and Graviton — AWS's own Cost Optimization Hub recommendations, priced at AWS's own dollar estimate with commitment, term and payment option
- Lifecycle gaps on log and backup storage
- Savings kept strictly separate from spend merely located, and never double-counted against AWS's own recommendations
RELReliability
- Single-AZ resources that were never meant to be
- Backups configured, and backups actually running
- Multi-region posture and real failure domains
- Autoscaling, health checks and deployment safety
- Service quotas you are quietly approaching
Every finding names the resource, the region and the account. Where something could not be
assessed — missing permission, disabled service, unavailable API — the report says
NOT ASSESSED rather than scoring it as a pass. A gap you know about is worth
more than a clean number you can't trust.
The cost section states plainly what it did not price, every time. AWS's own Savings Plans,
Reserved Instances, right-sizing and Graviton recommendations depend on your account having
opted into Cost Optimization Hub — if it hasn't, the report says so instead of implying there
was nothing to find. A handful of areas — CloudWatch Logs retention, S3 storage class and
lifecycle waste, and data transfer beyond NAT gateway processing — aren't priced at all yet,
and the report names each one outright. A low total should read as exactly what was
measured, never as "nothing to fix."