Skip to main content

Automated AWS audit

A full audit of your AWS account, delivered within the hour.

Ten domains analysed with read-only access - security, costs, resilience, network, IAM… You get detailed reports, a prioritised remediation plan and a summary ready for your executive committee.

audited domains
10
per audit, billed by AWS
299 USD
read-only IAM role
100%
hosted in Paris
eu-west-3

Coverage

What we analyse

Every audit covers all ten domains, across the regions you choose. Security is assessed against AWS Foundational Security Best Practices and the CIS AWS Foundations Benchmark v3.0.

  • Inventory

    Map of your resources (EC2, RDS, Lambda, S3, DynamoDB…) and tagging quality.

  • Security

    Compliance with AWS Foundational Security Best Practices v1.0.0 and the CIS AWS Foundations Benchmark v3.0.0.

  • FinOps

    Cost optimisation: Cost Explorer, Reserved Instances, Savings Plans, Compute Optimizer.

  • Well-Architected

    The six pillars of the AWS Well-Architected Framework, with Trusted Advisor and AWS Config.

  • Resilience

    Backups, disaster recovery, multi-AZ deployments, RTO and RPO objectives.

  • Network

    VPCs, subnets, routing, peering, VPN, Transit Gateway, NACLs and security groups.

  • Web security

    CloudFront, ALB, API Gateway, WAF, Shield, HTTP headers, TLS and certificates.

  • IAM

    Users, roles, policies, MFA, access key age and excessive privileges.

  • Containers and serverless

    ECS, EKS, Lambda and App Runner: configuration, exposure and best practices.

  • Secrets and encryption

    KMS, Secrets Manager, key and secret rotation, encryption at rest.

How it works

Four steps, no agent to install

  1. Subscribe

    Subscribe on AWS Marketplace. Billing goes through your AWS account.

  2. Authorise

    Deploy a read-only IAM role, protected by a unique External ID, with CloudFormation in two minutes.

  3. Configure

    Pick the regions to audit and, if you wish, a DAST scan of your public endpoints.

  4. Receive

    Deliverables arrive by email, usually within 30 to 60 minutes.

Deliverables

What you get

One deliverable per audience: engineering teams, the CISO and the executive committee.

  • 10 detailed reports

    One Word and PDF report per domain, naming the affected resources and the actions to take.

  • Attack scenarios

    Attack chains that combine findings from several domains, to prioritise what matters.

  • Action plan

    A remediation plan and a P0/P1/P2 Excel file to track the fixes.

  • Board summary

    A 5-page narrative summary and a 19-slide deck for leadership.

Pricing

Simple pricing

AWS Audit

299 USD per audit

  • One AWS account, the regions of your choice
  • All ten audit domains
  • OWASP ZAP DAST scan included (option)
  • All deliverables: reports, action plan, summary, board deck
Subscribe on AWS Marketplace

Applicable taxes extra, billed by AWS.

Our commitments

  • Read-only IAM role, revocable at any time
  • Data processed and stored in France (eu-west-3, Paris)
  • Audit artefacts deleted automatically after 7 days
  • Billed by AWS, no subscription, no commitment

Ready to audit your AWS account?

Subscribe on AWS Marketplace, deploy the read-only role and get your reports within the hour.