AWS Audit
Frequently asked questions
Questions asked before subscribing, and the most common issues with their solutions.
Before you subscribe
Do I need to install an agent in my account?
No. The audit only uses a read-only IAM role, which you deploy in two minutes with CloudFormation and can delete at any time.
What data leaves my account?
The configuration and metadata of your resources (inventory, IAM policies, network, aggregated costs). Collectors do not read the content of your buckets, databases or application logs. Everything is processed in Paris (eu-west-3) and deleted after 7 days.
Can I audit several AWS accounts?
Yes: one audit covers one AWS account. Deploy the role in each account and launch one audit per account; each audit is billed.
What language are the reports in?
Reports are currently written in French.
What happens if the audit fails?
An audit is metered once the reports have been generated, just before the email is sent. If it fails before that step, it is not billed. Contact support to relaunch it.
How am I billed?
By AWS, on your AWS Marketplace invoice: USD 299 per audit, with no subscription and no commitment.
Troubleshooting
IAM role validation fails after the stack deployment
Most common causes:
- The CloudFormation stack isn't yet in
CREATE_COMPLETEstatus - wait 30 seconds and retry. - The ARN you entered is not the one of the created role. Grab it from the stack's Outputs tab, key
RoleArn. - The stack was deployed in a different region than expected. The IAM role is global, but the stack must exist.
- The External ID was changed. Redeploy the stack with the exact value displayed at the previous step.
I haven't received the email with the reports
The email is sent from audit@aws.silamir.com when the audit completes (about 1 hour after launch). If you don't see it:
- Check the Spam and Junk folders.
- Ask your IT department to allow the domain
aws.silamir.com(SPF/DKIM/DMARC are configured). - Double-check that the email entered during onboarding is correct.
The report download links no longer work
Deliverables are kept for 7 days, then deleted automatically. Each download link expires after 10 minutes: request a new code from the download page to get a fresh one. Contact support to relaunch an audit.
My audit seems stuck - how long should it take?
A full audit takes on average 30 to 60 minutes depending on the number of regions selected and the size of your estate. If you haven't received anything after 90 minutes, contact support with the audit ID provided at the end of the form.
Which AWS regions are covered?
20 commercial regions are offered at the configuration step (Europe, North America, Asia Pacific, South America): select those where you have resources. Opt-in regions, GovCloud and China are not covered.
What permissions are granted to the IAM role?
Read policies only:
- AWS managed policies:
ReadOnlyAccess,Billing,AWSSupportAccess. - Read access to Cost Explorer, Security Hub, Compute Optimizer.
- No permission allows creating, modifying or deleting your resources.
ReadOnlyAccessalso allows reading some data andAWSSupportAccessallows opening support cases: Silamir collectors only use configuration APIs and never open a support case.
The role is protected by a unique External ID: only the Silamir account presenting this secret identifier can assume it (protection against the confused deputy attack).
How do I delete the IAM role after the audit?
Open the CloudFormation console in your account, select the stack SilamirAuditRole, and click Delete. Deletion takes a few seconds and revokes access permanently. You can redeploy the stack later to run a new audit.
The DAST scan failed or found nothing
The DAST scan (OWASP ZAP, passive baseline or active full mode) is optional and auto-discovers the public endpoints (CloudFront, API Gateway, ALB) of the audited account. If no endpoint is exposed, the scan finishes with no alert. A DAST failure does not interrupt the audit: other reports are produced normally.
My AWS Marketplace subscription is not recognised
After subscribing on AWS Marketplace, you are redirected to the portal with a token in the URL. If detection fails, close the tab and restart the flow from your AWS Marketplace console (Manage subscriptions → Silamir Audit AWS product → Set up your account). If the problem persists, contact support.
Stuck? Contact support
If your issue isn't listed above or the suggested fix doesn't work, reach our team at cloud@silamir.com.
To help us diagnose, please include if possible: the audit ID, your AWS account ID, the timestamp of the issue, and a description of the error.