Cloud Configuration Posture
Your AWS, Azure, and Google Cloud configurations checked against your controls every month.
- Cadence
- Monthly
- Pricing
- Scoped to your environment after the assessment.
- Family
- Cloud and application
The problem
Cloud settings drift with every deploy. Public storage, open ports, and unused admin keys pile up between audits, and cost waste hides in the same places.
What you get
- Findings ranked by risk, with the exact resource and setting
- Waste findings: idle and oversized resources
- Fix tickets ready for your team
- A month-over-month view of open findings
How it works
Step 1: You create audit roles
Read-only roles in each account or subscription, scoped for security review.
Step 2: Agents check configurations
Settings compared against your controls and common benchmarks.
Step 3: An expert reviews every finding
Risk judged in context, false positives removed.
Step 4: You approve any change
Fix tickets or one-time approvals, with a separate credential you issue for each fix. Every approval is logged.
Access we need
- AWS: the
SecurityAuditmanaged policy in each account - Azure: the
ReaderandSecurity Readerbuilt-in roles - Google Cloud: the
roles/iam.securityReviewerandroles/cloudasset.viewerroles
What we never do
- We never change a resource ourselves. Fixes run with your approval and a separate credential you issue for that change.
- We never ask for broad read access such as
ReadOnlyAccesswhen a narrower role will do.
The full access model is on the security and trust page.
Related services
- WAF and Logging Posture Review
Coverage gaps at your edge and in your logs.
- Vulnerability SLA Tracking
Who owes which patch, and since when.
Questions about Cloud Configuration Posture?
Tell us what you run and what you need, and we will reply with next steps.