Find the AWS risks that actually deserve engineering time.
Free 30-minute intro call, no commitment. You get a fixed price before any paid work starts. Your team's time: a 30-minute kickoff and a 30-minute walkthrough; we do the rest.
- From $495
- Fixed scope and fixed price, agreed in the free intro call
- 1 to 2 weeks
- From kickoff to the report walkthrough with your team
Each finding checked by hand against the running account
| Severity | Finding | Resource | Validation |
|---|---|---|---|
| critical | EC2.19 Security groups should not allow unrestricted access to ports with high risk | sg-0b7f3c9e (orders-db) | Exploitable |
| critical | IAM.6 Hardware MFA should be enabled for the root user | Account 4821-0937-5520 | Confirmed |
| high | S3.8 S3 general purpose buckets should block public access | prod-invoices-export | Confirmed |
| high | IAM.1 IAM policies should not allow full "*" administrative privileges | DeployerPolicy | Confirmed |
- Found
- TCP 5432 open to 0.0.0.0/0
- Owner
- Platform team
- Effort
- 15 minutes
Sample account, checked against real AWS Security Hub controls.