Skip to content

Free · No obligation · Read-only

Find out what your AWS account is really costing you

Two audits, both free. One tells you where your money is going to waste. The other tells you where you are exposed. You get the full executive report whether or not you go on to work with us.

Free assessment

AWS security audit

Over 2,300 automated checks across every region in your account, mapped to SOC 2, ISO 27001, GDPR, CIS and NIST - with a risk score, a prioritised fix list, and a 90-day roadmap.

Automated checks
2,304Automated checks
Resources audited
418Resources audited
AWS regions covered
4AWS regions covered
Compliance frameworks mapped
5Compliance frameworks mapped

What we typically find

  • CriticalA security group exposing all 65,535 ports to the public internet, with a directly reachable instance behind it.
  • CriticalCloudTrail disabled across every region - meaning a breach would leave no forensic evidence at all.
  • CriticalA dormant administrator account holding an access key unrotated for over 800 days.
  • HighGuardDuty and Security Hub disabled everywhere, so cryptomining or data exfiltration would go unnoticed.
  • HighEBS encryption off by default and S3 Block Public Access not set at the account level.

A recent audit returned 34 critical and 153 high findings against a 76/100 risk score. The critical items were resolvable in under four hours of engineering effort.

Free assessment

AWS cost optimisation audit

We find the spend that buys you nothing - idle gateways, ancient snapshots, addresses attached to no machine - and confirm each one against live usage rather than estimating.

Cost issues identified
157Cost issues identified
High-severity findings
58High-severity findings
Confirmed quick wins
5Confirmed quick wins
Typical payback period
Week 1Typical payback period

What we typically find

  • HighAn idle NAT gateway provisioned but carrying no traffic, billed every month for serving nothing.
  • HighSnapshots over 700 days old with no lifecycle policy, accumulating silently month over month.
  • HighElastic IPs allocated but attached to no running instance, plus stopped instances still billing for storage.
  • HighInstances running consistently below 5% CPU - over-provisioned for the workload they actually carry.
  • MediumNo VPC endpoints for S3 or DynamoDB, routing internal traffic through a paid NAT gateway unnecessarily.

A recent audit confirmed recoverable waste worth roughly $1,385 a year, every dollar of it removable in week 1 without a single code change or minute of downtime.

How it works

Four steps, about a week end to end

No lengthy onboarding and no commercial conversation until you have the report in your hands.

  1. 01

    You grant read-only access

    A scoped IAM role with the AWS-managed SecurityAudit and ViewOnlyAccess policies. Nothing more. You can revoke it the moment we finish.

  2. 02

    We run the assessment

    Over 2,300 automated checks across every region you use, then manual review by an engineer to separate the findings that matter from the noise.

  3. 03

    You get the executive report

    A written report with quantified findings, quick wins your team can action immediately, and a 90-day roadmap. Yours to keep either way.

  4. 04

    We walk you through it

    A 45-minute call with the engineer who ran the audit. Ask anything. There is no obligation to engage us afterwards.

How we work

What you can hold us to

Read-only, always

Every finding is confirmed from read-only credentials. We never modify your environment during an assessment - not one setting.

Confirmed, not estimated

We report what we can demonstrate against live usage. Anything we could not confirm is listed separately as an observation.

Security and cost together

The two overlap more than people expect. An idle NAT gateway is wasted spend and a network exposure - one fix, double the value.

Yours to keep

The report is yours whether or not you hire us. Quick wins are written so your own team can action them without our help.

Teams who have already had one

  • Cylogy
  • EazyBot
  • Red Wire Services
  • EnigmaPlus
  • Simpler Media Group
  • Astrolabe Analytics
  • PADI Systems
  • Tipedia
  • Simply Analytics
  • Tatango
  • AnswerDash
  • Ravenna Solutions

Both audits, no charge

Tell us which one you want - or take both. Read-only access, a written report, and a call with the engineer who ran it. Nothing else attached.