More than 30 automated security checks against your AWS environment: IAM hygiene, public exposure, encryption, logging, root-account habits, and RDS. It takes about an hour. You get a scored report with prioritized findings and a plain-English executive summary you could hand to someone non-technical.
I keep meeting teams running real workloads on AWS who have never had a proper security review. Not because they don't care. Because the one or two people who own AWS are already buried.
So I built something to make it easy. It runs automatically, it needs an hour and a read-only role, and it tells you where you actually stand.
Why free? Because most companies I talk to don't know what they don't know. Once you can see the gaps, we can talk about whether you want a hand fixing them, or not. Either way you keep the report.
The same checks I run against the accounts I manage. Every finding comes back scored, so you know what to deal with first.
Users, roles, stale access keys, MFA posture, and how the root account is being used. The first place anyone looks.
S3 buckets, security groups, and internet-reachable resources. The things that are open without anyone deciding they should be.
Encryption at rest across storage and databases, plus the volumes and snapshots that quietly never got it turned on.
CloudTrail, AWS Config, and whether anything is actually being retained. This is the part you need on the day something goes wrong.
Public accessibility, encryption, and backup configuration on your managed databases. Added since the first version of this scan.
GuardDuty, Security Hub, and AWS Config: whether they're switched on, and whether anyone would see it if they fired.
An overall score plus every finding ranked, so the list reads as a backlog rather than a wall of warnings.
A plain-English executive summary written for someone non-technical, so you can send it upward without translating it first.
You give me a read-only role in the account you want looked at. Read-only means exactly that: the scan reads configuration and changes nothing.
I run the checks and put the results together. You get the scored report and the executive summary back.
Then it's your call. If you want to talk about the findings, we talk. If you'd rather take the report and fix things yourself, that's a fine outcome too, and the report is yours either way.
The free scan is automated and broad. When it turns up something that needs a person looking at it, these are the next steps.
Automated checks only go so far. The full audit adds the manual review, the evidence, and a written report you can hand to an auditor or a customer.
02Holds the line after the findings are fixed. I manage the account so the same things don't come back next quarter.
Tell me roughly how many AWS accounts you're running and what's in them. I'll come back with what I need to run the scan and when you'll have the report.