Cloud security review
Most cloud breaches are identity problems wearing an infrastructure costume. We start at IAM and work outwards until we can draw your blast radius.
- duration
- 10–20 working days
- team
- 2 reviewers, 1 architect
- retest
- Included, 90 days
identity
Roles, trust policies, federation, service accounts, and every path that quietly leads to admin.
data
Storage exposure, encryption posture, backup access, and cross-account sharing nobody remembers approving.
network
VPC design, egress, private connectivity, and the security groups that were opened 'temporarily'.
pipeline
CI/CD credentials, runner isolation, artefact signing, and dependency provenance.
everything below, on every engagement
Read-only, scoped, and time-limited. We will help you build the role and revoke it with you at the end.
penetration testing
Time-boxed, scoped testing of a system you already have, graded against exploitability rather than a scanner's opinion.
red teaming
An objective-led simulation of a real adversary, run against your detection and response rather than against a checklist.
application security
Design review, threat modelling and code-level testing embedded with the team building the thing.
scope a cloud security review
Tell us what the system does and who relies on it. We will come back with a scope, a price and a date, usually within two working days.
