Cloud & infrastructure review

A benchmark tool tells you which settings differ from a baseline. We tell you which of those actually chain into someone reading your customer database — and which are noise you can safely deprioritise.

Scope

What we actually test

Reviewed with read-only access to the account, and validated from the outside where the rules of engagement allow.

Identity & privilege escalation

IAM users, roles, policies and trust relationships mapped into a graph, then walked for escalation paths — iam:PassRole chains, over-broad assume-role trusts, and wildcard permissions nobody intended to grant.

  • IAM privesc
  • PassRole
  • Trust policies

Exposed storage & data

Buckets, blobs, snapshots, AMIs and database instances checked for public exposure, over-broad ACLs, and unencrypted data at rest.

  • S3 / GCS / Blob
  • Public snapshots

Metadata service reachability

Whether an SSRF anywhere in your estate reaches the instance metadata service, and whether IMDSv2 is enforced rather than merely available.

  • SSRF → IMDS
  • IMDSv2

Network segmentation

Security groups, NACLs, firewall rules, peering and exposure of management planes — including services listening on the internet that were meant to be internal.

  • Segmentation
  • Exposed services

Secrets & key management

Secrets in environment variables, user-data scripts, container images, CI configuration and source history, plus key rotation and KMS policy review.

  • Key sprawl
  • CI secrets

Logging & detection

Whether CloudTrail, audit logs and flow logs are enabled, retained and actually alerting — tested by performing noisy actions and checking what you saw.

  • Detection gaps

Every engagement ships with

  • Executive summary written for leadership
  • Technical report with reproducible proof-of-concept for every finding
  • CVSS v3.1 vectors and a plain-English business-impact narrative
  • Prioritised, concrete remediation guidance
  • Same-day alerting on anything critical
  • Live debrief with your engineering team
  • Free retest of every finding within 90 days
  • Signed attestation letter for auditors and customers

FAQ

Questions about this service

What access do you need?

A read-only role — SecurityAudit and ViewOnlyAccess on AWS, or the equivalent on GCP and Azure. Anything beyond read-only is agreed explicitly in writing and scoped to a named test window.

Is this just a CIS benchmark scan?

No. Benchmarks are a starting point and we run them for coverage, but the value is in the manual work: turning a list of misconfigurations into the specific paths that lead from an internet-facing foothold to your data.

Do you test Kubernetes?

Yes — RBAC review, workload identity, pod security, network policy, and escape paths from a compromised container to the node and then to the cloud account.

Next step

Find out what an attacker would find.

Tell us what you have built. You get a reply within one business day, an NDA, and a free 30-minute scoping call with the person who will do the testing.