Security & Compliance

    Cloud Security Audit

    When the first enterprise customer sends a security questionnaire, the gaps are usually the same three: long-lived keys in CI, IAM nobody has pruned since the seed round, and secrets living in environment files.

    Start with the audit

    No sales layer, no juniors. You meet the engineer before anything begins.

    // What is included

    What you get

    • IAM reviewed for standing privilege and unused access
    • Secrets, keys and their rotation state inventoried
    • Network exposure and edge controls checked from the outside in
    • Findings ranked by what an attacker or an auditor reaches first

    // How it runs

    The sequence

    1. 01

      Access

      Read-only role, scoped and revocable, with nothing changed.

    2. 02

      Audit

      Methodical pass across identity, secrets, network and logging.

    3. 03

      Report

      Prioritised written findings and a walkthrough call.

    // Stack

    • AWS IAM
    • AWS Secrets Manager
    • AWS WAF
    • AWS KMS
    • Amazon GuardDuty

    // Related work

    Where this has been done before

    Client names under NDA. The numbers are not.

    SOC 2-ready security hardening (NDA)

    • IAM rewritten to least privilege with credential rotation
    • Secrets moved to Secrets Manager with Lambda rotation
    • WAF and rate limiting in front of public endpoints

    Controls in place and documented for the SOC 2 audit

    All case studies

    // Questions

    Before you ask

    Talk to the engineer who would do the work

    A 20 minute call. You describe your setup, you get an honest read on whether this helps, and the top risks worth looking at first.

    See pricing