Free · No obligation · Read-only
Find out what your AWS account is really costing you
Two audits, both free. One tells you where your money is going to waste. The other tells you where you are exposed. You get the full executive report whether or not you go on to work with us.
Free assessment
AWS security audit
Over 2,300 automated checks across every region in your account, mapped to SOC 2, ISO 27001, GDPR, CIS and NIST - with a risk score, a prioritised fix list, and a 90-day roadmap.
- Automated checks
- 2,304Automated checks
- Resources audited
- 418Resources audited
- AWS regions covered
- 4AWS regions covered
- Compliance frameworks mapped
- 5Compliance frameworks mapped
What we typically find
- CriticalA security group exposing all 65,535 ports to the public internet, with a directly reachable instance behind it.
- CriticalCloudTrail disabled across every region - meaning a breach would leave no forensic evidence at all.
- CriticalA dormant administrator account holding an access key unrotated for over 800 days.
- HighGuardDuty and Security Hub disabled everywhere, so cryptomining or data exfiltration would go unnoticed.
- HighEBS encryption off by default and S3 Block Public Access not set at the account level.
A recent audit returned 34 critical and 153 high findings against a 76/100 risk score. The critical items were resolvable in under four hours of engineering effort.
Free assessment
AWS cost optimisation audit
We find the spend that buys you nothing - idle gateways, ancient snapshots, addresses attached to no machine - and confirm each one against live usage rather than estimating.
- Cost issues identified
- 157Cost issues identified
- High-severity findings
- 58High-severity findings
- Confirmed quick wins
- 5Confirmed quick wins
- Typical payback period
- Week 1Typical payback period
What we typically find
- HighAn idle NAT gateway provisioned but carrying no traffic, billed every month for serving nothing.
- HighSnapshots over 700 days old with no lifecycle policy, accumulating silently month over month.
- HighElastic IPs allocated but attached to no running instance, plus stopped instances still billing for storage.
- HighInstances running consistently below 5% CPU - over-provisioned for the workload they actually carry.
- MediumNo VPC endpoints for S3 or DynamoDB, routing internal traffic through a paid NAT gateway unnecessarily.
A recent audit confirmed recoverable waste worth roughly $1,385 a year, every dollar of it removable in week 1 without a single code change or minute of downtime.
How it works
Four steps, about a week end to end
No lengthy onboarding and no commercial conversation until you have the report in your hands.
- 01
You grant read-only access
A scoped IAM role with the AWS-managed SecurityAudit and ViewOnlyAccess policies. Nothing more. You can revoke it the moment we finish.
- 02
We run the assessment
Over 2,300 automated checks across every region you use, then manual review by an engineer to separate the findings that matter from the noise.
- 03
You get the executive report
A written report with quantified findings, quick wins your team can action immediately, and a 90-day roadmap. Yours to keep either way.
- 04
We walk you through it
A 45-minute call with the engineer who ran the audit. Ask anything. There is no obligation to engage us afterwards.
How we work
What you can hold us to
Read-only, always
Every finding is confirmed from read-only credentials. We never modify your environment during an assessment - not one setting.
Confirmed, not estimated
We report what we can demonstrate against live usage. Anything we could not confirm is listed separately as an observation.
Security and cost together
The two overlap more than people expect. An idle NAT gateway is wasted spend and a network exposure - one fix, double the value.
Yours to keep
The report is yours whether or not you hire us. Quick wins are written so your own team can action them without our help.
Teams who have already had one
- Cylogy
- EazyBot
- Red Wire Services
- EnigmaPlus
- Simpler Media Group
- Astrolabe Analytics
- PADI Systems
- Tipedia
- Simply Analytics
- Tatango
- AnswerDash
- Ravenna Solutions
Both audits, no charge
Tell us which one you want - or take both. Read-only access, a written report, and a call with the engineer who ran it. Nothing else attached.