AWS Audit
How the audit works
From subscription to reports, an audit runs in five stages. You stay in control of access from start to finish.
1. Subscribe on AWS Marketplace
You subscribe to the offer from AWS Marketplace, which then redirects you to this portal. You enter your company and the technical contact's email address, which you confirm with a 6-digit code sent by email. Deliverables will be sent to that address.
2. Deploy the IAM role
The portal opens the CloudFormation console of your account with a prefilled template. The stack creates the
SilamirAuditReadOnlyrole, which only the Silamir production account can assume, and only by presenting the unique External ID generated for you. You then paste the role ARN into the portal, which checks access.3. Choose regions and DAST scan
You select the regions where your resources live. The DAST scan is optional: baseline mode (passive, up to 20 targets) or full mode (active, with attack payloads, up to 10 targets). Targets are discovered automatically (CloudFront, API Gateway, ALB); an authorisation statement is mandatory.
4. Collection and analysis
Ten collectors read your account configuration in parallel. The data is then analysed by Anthropic Claude models invoked through Amazon Bedrock, using European inference profiles. The analysis produces the domain reports, attack scenarios, remediation plan and summary. Automated checks verify that the reports are consistent with the collected data.
5. Delivery
You receive an email from
audit@aws.silamir.com, usually 30 to 60 minutes after launch. Downloads are protected by a code sent to the verified address; each download link expires after 10 minutes. Artefacts are deleted automatically after 7 days.
After the audit
Delete the SilamirAuditRole CloudFormation stack to revoke access immediately. You can redeploy it for your next audit.
Ready to audit your AWS account?
Subscribe on AWS Marketplace, deploy the read-only role and get your reports within the hour.