A misconfigured S3 bucket doesn't send an alert. A security group that's had 22/tcp open to the world since a debugging session two years ago doesn't either. Both just sit there until someone finds them — you, or someone else. That's the whole case for the cloud security audit: a bounded, flat-fee way to be the one who finds it first.

The cloud security audit landing page, showing a sample Prowler scan output with a critical MFA finding and several high/medium severity issues
Sample scan output from the audit's own landing page — root account MFA, public S3, an over-permissive security group, a stale IAM key.

The engines, not a black box

Every audit runs on industry-standard, open-source tooling — the same scanners enterprise security teams actually run, not a proprietary checker nobody can inspect:

  • Prowler for account and configuration checks, mapped to the CIS AWS Foundations Benchmark and AWS's own Foundational Security Best Practices
  • Trivy for container and OS image vulnerabilities
  • Checkov and Snyk for Infrastructure as Code — catching a misconfiguration in Terraform before it's ever applied

Then comes the part a scanner can't do: every finding gets read in the context of your actual account, and told to you as what genuinely matters for a team your size — not a 200-line PDF of noise where three critical items are buried under a hundred informational ones.

Three steps, five business days

1. Grant access, or share your report

A scoped, read-only IAM role — or if you already have Prowler, Security Hub, or pentest output sitting around, send that over instead and skip straight to the review.

2. Run the scan, or review the findings

Every check runs against CIS AWS Foundations and AWS's own best practices. An existing report gets read line by line, not skimmed.

3. Get the prioritized roadmap

A report back within 5 business days — every finding tagged critical, high, medium, or low, with the "why it matters" written out for each one, not just a severity label.

The four places a breach actually starts

The audit is structured around the chain an attacker actually follows, not a checklist for its own sake:

PointWhat it looks like
Public entry pointAn open port, a public bucket
Misconfig or leaked secretThe finding that gets skipped
Excess permissionsAn over-broad IAM role
Sensitive dataThe actual breach

One weak link at any of these four points is enough. The audit — and remediation, if you want it — covers all four, not just the easiest one to scan for.

Pricing

TierPriceWhat you get
Discovery call$5030 minutes, if you're not sure yet
Full audit$350–$1,000 flat feeQuoted on the call — production account(s), all enabled regions, or a specific framework (CIS Controls, SOC 2, ISO 27001) if that's your target. Container/OS image scanning and source-repo secrets/IaC scanning available too.

50% to start, 50% on delivery. Full refund if the report finds nothing actionable — same risk-reversal as the cost audit. If you already have findings — from this audit, a report you brought, or a framework you're closing gaps against — remediation is billed hourly ($50–$75/hr) and scoped after you see the results, with no redundant re-audit charged.

Read-only, always

Only Describe / List / Get calls during the audit. Every fix ships as reviewed steps for you (or remediation) to run — nothing gets auto-remediated without sign-off. For a security audit specifically, that matters more than for almost any other kind of engagement: the last thing you want is a "security fix" that silently changes production behavior.

Find out what's actually exposed before someone else does. Book the $50 discovery call, or go straight to the full audit.

📢 Have questions or feedback? Drop a comment below or connect with me on Twitter/X@spysood!