IAM least privilege
Wildcard policies replaced with scoped ones, unused users and keys removed, MFA enforced, role assumption paths documented.
Fixed price · Fixed scope
Compliance tools are good at telling you what is wrong and no help at all in fixing it. We take your open infrastructure findings and close them — properly, with evidence attached — so your audit stops waiting on engineering.
We closed every Drata compliance finding for a US healthcare platform as part of its SOC 2 certification, on a live system serving clinical staff.
What we do
Wildcard policies replaced with scoped ones, unused users and keys removed, MFA enforced, role assumption paths documented.
Bastion hosts and open SSH ports replaced with AWS Systems Manager session access — logged, auditable, and no inbound ports at all.
Security groups and ACLs narrowed to what each service actually needs. Databases moved off public subnets where they are still exposed.
Encryption at rest and in transit verified across RDS, S3 and EBS; KMS keys rotated and scoped; SSL renewal automated so no certificate expires by surprise.
CloudTrail, CloudWatch alarms and log retention configured to the control's wording, with Lambda alerts where a human needs to know. Each control gets a screenshot or export the auditor can accept.
Anything outside this list is quoted before we start it, never invoiced afterwards.
Timeline
We go through every open finding with you and split them: ours to fix, yours to fix, and not applicable with a written reason the auditor will accept.
Everything that cannot affect production traffic goes first: policies, logging, alarms, retention, key rotation.
Network and access changes, each with a written rollback plan, applied in a window you approve. Nothing touches production without that plan existing first.
Evidence collected per control, the dashboard re-run, and a call to walk your team through what changed and why.
Most of what looks like 60 findings is 20 real problems repeated across resources, and the fixed price still holds. If it genuinely is more work, we tell you after triage on day 2 and quote the rest before continuing — never after.
Every production change has a written rollback plan before it is applied, and the risky ones run in a window you approve. That is how we work on a healthcare platform where downtime affects patient care.
Yes, and Secureframe. The controls underneath are the same; only the dashboard differs.
Book a 20-minute call. Bring your AWS account, your compliance dashboard or your database version, and we will tell you what we would do and what it costs — on the call, not in a proposal two weeks later.
See the case studies behind this work →