It is not permitted to change your account. That's enforced in code.
"Read-only" is not a promise in a contract — it is an interceptor sitting under every single AWS API call the tool makes.
Read more →Independent · not an AWS reseller · 3 pilot engagements open
AWS audit/Landing zones/Remediation & retainer
Neither does your team — not because they're careless, but because nobody has ever measured it. We read every account in your organization using a role that is mechanically incapable of changing anything, and hand back a report you can forward to your auditor, your insurer, or your largest customer's security review. Every finding in it has been checked by both of us.
Every screen below comes from a sample report that cloud-audit 0.20.0 generated against fictional accounts. None of it is a client result.
The executive view puts money, exposure and safe fixes on the first screen. It also states exactly what was inspected — and what was not — so a low finding count can never masquerade as good coverage.
If nothing else gets done, these do. Exposure first, then the safe changes that carry money — each item tagged with how risky the fix is and how long it should take.
Severity is only one dimension. Each item carries the affected resource, business consequence, remediation, change risk and estimated effort. Your team can turn the report into tickets without translating consultant language first.
Safe now means no downtime and reversible. A window means a brief interruption. A decision means only your team knows the intent. The matrix shows how much of the work anyone can pick up on Monday.
One row per issue, sorted by money, each tied to a named check. A saving is money that stops when you act; located spend is money the audit found and priced but cannot promise to remove — so the two totals sit side by side and are never summed.
Controls in place out of the controls the audit could assess, one block per control, per pillar. The same evidence file regenerates the same scores, so the next audit shows exactly what moved.
When a permission is missing or a region is disabled, the area is listed as not inspected instead of being counted as clean. Absence of findings there is not evidence of good configuration.
The organization view exposes systemic gaps across accounts before the Terraform scope is finalized. Landing Zone itself is delivered as a repository you own; this audit is the input that shows which controls must be standardized and where exceptions exist.
"Read-only" is not a promise in a contract — it is an interceptor sitting under every single AWS API call the tool makes.
Read more →Every finding names the resource, the region and the account.
Read more →You get the document and an hour to walk through it. Then you decide whether to fix it yourself or scope the work with us.
Read more →Each one makes the next one quotable. You can stop after any of them, and the first one is built to be worth its fee even if you never speak to us again.
Read-only. One week. A document you own.
Every account, every enabled region, measured against the AWS Well-Architected pillars. You get a self-contained HTML report: what was inspected, what to do first, every finding tied to a named resource with a concrete remediation — and, unusually, an explicit list of what could not be checked.
From $2,500 fixed
Empty account in. Defensible account out.
Plain Terraform — no Control Tower, no Terragrunt, no framework you have to learn. CloudTrail, SCPs, Block Public Access, EBS encryption by default, GuardDuty, Access Analyzer, budgets. Delivered as a repository you own, with no ongoing dependency on us.
Fixed Quoted at scoping
Fixing what the audit found.
The audit produces a scope line — "18 findings safe to apply, 3.7 hours" — which is already a proposal. Take it in-house and do it yourself, or hand it back to us as a fixed-scope sprint. Either outcome is fine; the report was built to work both ways.
Retainer $2,000–4,000/mo
Senior DevOps / SRE · Córdoba, AR
Eight years running production cloud infrastructure.
DevOps / SRE Engineer · Argentina
Six years across AWS, Azure and GCP.
Thirty minutes, no deck. You describe the estate, we tell you what we'd check and what it costs — one number, not a range. If it isn't worth doing, we'll say that too.