Service 06, included in your subscription
Cloud configuration review
We review cloud environments for exploitable misconfiguration, not just noisy benchmark drift, and prioritise the paths that could expose data or control.
What we test
IAM & privilege
Over-permissive roles, escalation paths, federation and service accounts.
Storage exposure
Public buckets, blobs, snapshots, backups and sensitive data paths.
Network boundaries
Security groups, firewall rules, private access and exposed management planes.
Logging & detection
Audit logging, alert coverage, retention and investigation readiness.
Workloads
Container, Kubernetes, serverless and metadata service risk.
Secrets handling
Environment variables, CI/CD exposure, key rotation and unsafe sharing.
What you get
A report your auditor and your engineers both understand
Executive summary, per-finding reproduction steps, severity-rated remediation guidance and retesting included once you have fixed the issue.
Book a callFAQ
Common questions
Do you need admin access?
No. We normally request scoped read-only access so configuration can be reviewed without changing resources.
Can you review Kubernetes?
Yes. We review managed Kubernetes posture, RBAC, network policy, secrets and exposed services.
Can you provide infrastructure-as-code recommendations?
Yes. Where useful, we include practical remediation guidance for Terraform or other infrastructure-as-code workflows.