Existing accounts

Already running in the cloud? We fix what is there.

We assess the accounts you run today, move your team onto single sign-on, clear the security findings, and bring what was built by hand into code. You end up with less risk and a cloud you can show to an auditor or a customer, and we agree the scope with you in writing first.

Price
From $15,000
We fix the price once we agree the scope.
Clouds
AWS, Azure, Google Cloud

When teams call us

Your findings are piling up

Security Hub, Defender for Cloud, or your compliance tool shows a long red list, and nobody on your team has time to work through it.

Customers or auditors are asking

An enterprise customer sent a security questionnaire, or a SOC 2, ISO 27001, or HIPAA audit is coming, and your cloud is not ready to show.

You want the risk down

Maybe you had a scare, or you know one leaked key could expose everything. You want the gaps closed before something happens.

Your cloud was built by clicking

People share administrator logins, access keys sit on laptops, and nobody is sure what is logged or encrypted.

What we fix

Here is the usual scope, in plain words first and then exactly what we change. Your assessment decides which parts apply to you.

Move everyone onto single sign-on

We replace shared logins and personal access keys with sign-in through your identity provider, and we do it without locking anyone out.

  • Credential cleanup. We find every IAM user and shared credential and retire them.
  • Clear roles. We map IAM Identity Center, Microsoft Entra ID, or Cloud Identity groups to roles.
  • Keyless pipelines. We rotate out long-lived access keys and move your pipelines to OIDC.
  • Root protection. We lock down root and break-glass access and document how to use it.

Clear the findings backlog

We work through the red list from your security tools by risk, not by count, and we make sure each fix stays fixed.

  • Your existing tools. We start from Security Hub, Defender for Cloud, Security Command Center, or your compliance tool.
  • Risk first. We rank failed CIS and foundational best-practice controls by exposure.
  • Biggest holes first. We close public buckets, open SSH and RDP, and unencrypted volumes and databases before anything else.
  • Honest exceptions. When you accept a risk, we write down why instead of hiding the finding.

Make the audit trail complete

We connect every account to one audit trail that the people making changes cannot edit.

  • Central logging. Organization-wide audit logs flow to a separate log account or workspace.
  • Your retention rules. We set retention and immutability to what your auditor asks for.
  • Resource history. We record configuration changes across accounts.

Bring console-built resources into code

We bring what was built by clicking under Terraform, so your team reviews the next change instead of guessing at it.

  • Import first. We import your existing resources into Terraform, starting with the security-relevant ones.
  • Reviewed changes. A pipeline runs a plan on every pull request.
  • Drift detection. We catch manual changes before they cause surprises.

Evidence you can show

When an auditor or a customer's security team asks, you show them the settings instead of describing them.

  • Mapped controls. We map controls to the framework you name, whether SOC 2, ISO 27001, HIPAA, or PCI DSS.
  • Real exports. You get exports of your access, logging, and encryption settings.
  • A change record. Your pull request history shows every change we made.

How the work runs

  1. 1

    Free call

    Tell us what you run, what is failing, and what is driving the work.

  2. 2

    Assessment

    With read-only access, we take an inventory, pull the findings, and write a fix list ranked by risk.

  3. 3

    Fixed scope

    We agree which accounts, which findings, and which framework if any, and price it in writing before we change anything.

  4. 4

    Fix as code

    Every change goes through a pull request, hits non-production first where you have it, and lands in windows your team agrees.

  5. 5

    Evidence and handover

    You get the control mapping, the exports, and the code, and we walk your team through it.

We plan every change so your systems keep running, and riskier changes go in windows your team agrees. If something falls outside the agreed scope, we quote it separately instead of adding it quietly.

We build everything in your own cloud provider environment. Your provider bills you directly for usage, including security services like threat detection and logging, and that is separate from our fee.

Frameworks we map your cloud to

When an audit or a customer review is part of the picture, we map the cloud settings to the framework you name and make them easy to show. Your auditor issues any certificate, and your policies, training, and vendor reviews stay with you.

Customer security reviews
SOC 2, ISO 27001
Healthcare
HIPAA
Payments
PCI DSS
Security standards
NIST CSF, CIS Benchmarks

We work with US-based companies. If your company is outside the US, we can still help through an engagement agreement written for you, and we follow the laws and frameworks that apply to you, such as GDPR.

Book a free call

Tell us what you run, what your findings are, and what is driving the work, whether that is an audit, a customer, or risk you want gone. We reply within one business day.

Starting fresh instead? We build new foundations from $8,500. Once we finish, our managed cloud operations can keep everything in shape.

Request

Existing accounts