Skip to content
Second Key Security

Cloud Configuration Posture

Your AWS, Azure, and Google Cloud configurations checked against your controls every month.

Cadence
Monthly
Pricing
Scoped to your environment after the assessment.
Family
Cloud and application

The problem

Cloud settings drift with every deploy. Public storage, open ports, and unused admin keys pile up between audits, and cost waste hides in the same places.

What you get

How it works

  1. Step 1: You create audit roles

    Read-only roles in each account or subscription, scoped for security review.

  2. Step 2: Agents check configurations

    Settings compared against your controls and common benchmarks.

  3. Step 3: An expert reviews every finding

    Risk judged in context, false positives removed.

  4. Step 4: You approve any change

    Fix tickets or one-time approvals, with a separate credential you issue for each fix. Every approval is logged.

Access we need

  • AWS: the SecurityAudit managed policy in each account
  • Azure: the Reader and Security Reader built-in roles
  • Google Cloud: the roles/iam.securityReviewer and roles/cloudasset.viewer roles

What we never do

  • We never change a resource ourselves. Fixes run with your approval and a separate credential you issue for that change.
  • We never ask for broad read access such as ReadOnlyAccess when a narrower role will do.

The full access model is on the security and trust page.

Questions about Cloud Configuration Posture?

Tell us what you run and what you need, and we will reply with next steps.