All features Cloud · AWS

CSPM for every connected AWS account

168 checks across IAM, S3, EC2, CloudTrail, KMS and VPC — public exposure, weak IAM and misconfiguration flagged continuously, per account.

Get started Run a free scan
168AWS checks
6services
Peraccount
aws-security-posture 50
S3S3 exposurePASS
IAMIAM hygieneCHECK
NETWNetworkFAIL
LOGGLoggingPASS
What we check

168 checks across every corner of the account

An agentless scan reads each connected AWS account through a read-only role and runs 168 checks — a 150-check baseline, a 12-check Foundational Security Best Practices gap pack, and a 6-check resource-hygiene pack (unattached security groups, idle Elastic IPs, orphaned volumes and interfaces, unused IAM roles, idle load balancers) — flagging public exposure, weak or over-privileged IAM, and misconfiguration.

IAM & identity

Root-account MFA and access keys, console users without MFA, unrotated and unused keys, AdministratorAccess attached straight to users, wildcard and privilege-escalation policies, cross-account trust missing an external ID, and IAM Access Analyzer coverage.

S3 & storage

Publicly accessible buckets, Block Public Access gaps, missing server-side encryption, versioning, access logging and lifecycle rules — plus object-lock, MFA-delete and replication posture for compliance-critical data.

EC2 & compute

Security groups open to 0.0.0.0/0 on sensitive ports, unencrypted volumes and snapshots, and the RDS, Lambda, ECS and EKS workloads running alongside — from public function URLs to privileged containers.

CloudTrail & KMS

Multi-region trail coverage, log-file validation, GuardDuty and AWS Config enablement, and KMS key management — so nothing meaningful happens in the account without an encrypted, auditable record.

VPC & network

Default security groups and network ACLs left wide open, missing VPC flow logs, and internet-facing exposure — the network paths an intruder would actually move through.

FSBP gap pack

A 12-check pack that closes the highest-impact holes in AWS Foundational Security Best Practices — Security Hub and Access Analyzer enablement, AWS Backup vault locks, SSM Patch Manager, WAF web ACLs, DynamoDB, Macie and Inspector.

Network & data-flow diagram

Every VPC, subnet, gateway, firewall and data store, auto-drawn into the network and data-flow diagram PCI DSS 1.2.3 / 1.2.4 (and CMMC, ISO 27001, SOC 2, HIPAA) require — generated from the live scan and exportable as SVG for auditors.

How it connects

A read-only role, then it runs itself

Connecting an account is a one-time CloudFormation deploy — no agent to install, no keys to hand over, and no write access anywhere in your environment.

Read-only cross-account role

One CloudFormation stack creates a scoped SBCMSP-CSPM-ReadOnly role — SecurityAudit plus CloudTrail read-only, assumed under a unique external ID. Paste the role ARN and the account is connected. No stored keys, no agent, no write permissions.

Continuous re-scan

Once connected, the account is re-scanned on a schedule with the same zero footprint. Each scan tracks what is new and what has been resolved since last time, so both drift and fixes surface on their own.

Unified findings

AWS findings land in the same queue as every other source — ranked by real-world risk, paired with AI remediation guidance, mapped to your compliance frameworks, and folded into cross-surface attack paths.

Part of one platform

Cloud exposure, in the context of everything else

AWS posture never sits in its own console. Every finding is correlated with your Windows, Linux and macOS endpoint agents and your M365 / Entra identity data on one platform — so a public bucket or an over-privileged role becomes a named step in a real attack path, not an isolated ticket.

  • Correlated with endpoint & M365 / Entra
  • Findings become steps in named attack paths
  • KEV / EPSS-ranked, real-world severity
  • Paired with AI remediation, mapped to 10 frameworks
See the full platform
82
+27 pts
projected after top fixes

Run your first scan free

See a client’s real posture in minutes — then unlock all 1,692 checks.