Services / Cloud security review

A read-only posture review of your AWS, Azure or Google Cloud accounts: identity, public exposure, encryption, logging and guardrails.

Cloud accounts drift. A storage bucket made public for an afternoon, an access key belonging to a former contractor, a security group opened "temporarily" two years ago.

With read-only access we review every account, subscription or project in scope and tell you what is exposed, who can do what, and which gaps to close first.

iam — ci-deploy
$ aws iam get-policy-version …/ci-deploy{  "Effect": "Allow",  "Action": "*",  "Resource": "*"} ✕ CI user is full admin · access key 912 days old
When you need this
  • Your product runs on AWS, Azure or Google Cloud
  • Several teams or contractors have had access over time
  • A client asks how their data is protected in your cloud
  • Before a launch, a funding round or an audit
Coverage

What we test

The exact scope is agreed in writing before we start. This is what a typical engagement covers.

01

Identity & access

  • Over-privileged users, roles and service accounts
  • Long-lived access keys and unused credentials
  • MFA on root and administrator accounts
  • Cross-account and third-party trust
02

Public exposure

  • Storage buckets, snapshots and images open to the internet
  • Databases and admin services reachable from anywhere
  • Security groups and firewall rules allowing 0.0.0.0/0
03

Data protection

  • Encryption at rest and in transit
  • Key management and rotation
  • Secrets handling in code, variables and parameters
  • Backup and snapshot protection
04

Logging & detection

  • Audit trails (CloudTrail, Azure Activity Log, Cloud Audit Logs) enabled and retained
  • Alerting on risky changes
  • Provider threat-detection services
05

Network design

  • VPC / VNet layout and private subnets
  • Egress control
  • Peering, VPN and private endpoints
06

Kubernetes & managed services

  • EKS, AKS and GKE cluster configuration
  • Managed database settings
  • Serverless function permissions
Deliverables

What you receive.

  • Findings per account and region, ranked by severity
  • A list of every internet-exposed resource we found
  • IAM risk summary: who can do what, and what should change
  • Prioritised remediation plan with the exact console or CLI steps
Standards we work to
  • CIS AWS Foundations
  • CIS Azure Foundations
  • CIS Google Cloud Foundations
  • Provider well-architected security guidance
Before we start

What we need from you

  • A read-only role, such as AWS SecurityAudit, Azure Reader + Security Reader, or GCP Viewer + Security Reviewer
  • The accounts, subscriptions or projects in scope
  • A technical contact who knows why things are set up the way they are

Never send passwords or keys by email. We set up a secure channel once the scope is agreed.

Often combined with

Related services.

Let's strengthen your security — get in touch.

Araval · Technologies
Email us
  1. 01Tell us what you need and by when
  2. 02We reply with questions or a written scope
  3. 03You get a fixed quote before any work starts
Discuss your scope