Identity and access
Every IAM user, role and policy reviewed for least privilege. Long-lived access keys, unused credentials, over-broad wildcards and missing MFA are listed individually.
Fixed price · Fixed scope
We read your whole AWS account the way an auditor would, then hand you a written report that ranks every finding by risk and by the money it costs you each month. You get the fix list whether or not you hire us to apply it.
Built from the same checklist we used to close every compliance finding on a US healthcare platform during its SOC 2 certification.
What we do
Every IAM user, role and policy reviewed for least privilege. Long-lived access keys, unused credentials, over-broad wildcards and missing MFA are listed individually.
Security groups, network ACLs, public subnets and load balancers checked for anything reachable from the internet that should not be — including databases, admin ports and S3 buckets.
RDS and S3 encryption, backup retention, snapshot age and restore testing. We say plainly whether you could actually recover, not just whether backups exist.
CloudWatch alarms, log retention and what currently pages a human at 3am. Gaps where a failure would go unnoticed are called out.
Idle instances, oversized databases, orphaned volumes and snapshots, unattached IPs, and savings-plan opportunities — each with the monthly dollar figure attached.
Anything outside this list is quoted before we start it, never invoiced afterwards.
Timeline
You create a read-only IAM role for us. We never need write access for an audit, and the role is yours to delete the day we finish.
We work through the account service by service, against our own checklist built from real SOC 2 remediation work.
Findings are written up and scored. No raw tool output dumped on you — every finding is in plain language with the fix next to it.
We present the report, answer questions, and agree what matters most. You leave the call with a plan your team can execute alone if you want to.
Read-only, and only to AWS. We do not need database contents, customer data or your application source code to run the audit.
Then you have a written, dated statement that your account is in good shape — which is exactly what the security questionnaire in your next enterprise deal is going to ask for.
Yes. Most clients take the fix list and ask us to quote the top items. Those are priced separately so the audit stays honest.
Book a 20-minute call. Bring your AWS account, your compliance dashboard or your database version, and we will tell you what we would do and what it costs — on the call, not in a proposal two weeks later.
See the case studies behind this work →