Your cloud is probably fine.
Probably is the problem.
We read your AWS, Azure, GCP and Kubernetes estate the way somebody attacking it would, write down what we found and how we proved it, and stay on it until it is fixed. Every finding comes with the evidence, the fix and an honest estimate of what the fix costs you.
The deployment role can assume every other role in the account
arn:aws:iam::4471xxxx9002:role/ci-deployA production database answers on the public internet
rds:eu-west-2:orders-primary · sg-0a91xxxx4eSeven months of application logs are stored unencrypted and never expire
s3://acme-app-logs-prodWorked examples, written against invented accounts. Client findings never leave the client.
Four pieces of work, and the last one is the reason for the first three
An audit that ends at a report has moved nothing. The whole engagement is built around the fixes actually landing, which is why the retest is included rather than sold separately.
Cloud security assessment
A full read of the estate against 312 controls, then a manual pass over everything the controls cannot see — the trust relationships, the leftovers, the thing that was temporary in 2023.
How an assessment runsPenetration testing
External, internal and cloud-native. We try the paths a real attacker would try, from the position they would actually start in, and we write down the ones that worked.
Scopes and rulesCompliance readiness
ISO 27001, SOC 2, PCI DSS and UK GDPR mapped onto what your estate actually does, so the evidence comes out of the platform rather than out of a spreadsheet.
Frameworks we map toRemediation and retest
The part most reports skip. We sit with your engineers, fix the findings in priority order, and retest each one so the close is evidenced rather than asserted.
How the fix worksSix steps, and four of them are yours to check
Nothing here happens without you seeing it first: you create the access, you set the window, you get the findings as we confirm them rather than in one delivery at the end.
A 45-minute call and a list of accounts. We tell you what we would look at, what it costs and what we would need — before anything is signed.
A read-only role you create, scoped to the audit, with an external id and an expiry. You can revoke it in one click and we will notice within the hour.
Automated collection across every account and region, including the ones nobody mentioned on the call. This part is machine work and it takes about a day.
The part that takes the time. Every candidate finding is reproduced by hand, and anything we cannot reproduce is dropped rather than downgraded.
Findings with evidence and fixes, a prioritised backlog your team can work straight from, and a two-page summary written for the person who signs things.
Included, not an upsell. We come back to each closed finding and prove it is closed, and the report gets a second dated column.
This is a finding. All of it.
Not a summary of one. Every finding in a Safebox2 report is written out like this, because a finding without its evidence is an opinion and a finding without its fix is somebody else's problem.
The deployment role can assume every other role in the account
arn:aws:iam::4471xxxx9002:role/ci-deploy- Evidence
- Its inline policy allows sts:AssumeRole on Resource: "*". From a build container we assumed the database administration role and read a credential out of Secrets Manager. 14:22 UTC, day two.
- Impact
- Anyone who can open a pull request can reach production data. That includes contractors, and it includes anyone who steals a laptop belonging to someone who can.
- Fix
- Scope the trust policy to the four roles the pipeline actually assumes, and add a condition on the repository and branch. The pipeline needs no other change.
- Effort
- Under an hour, plus a pipeline run to confirm
Worked examples, written against invented accounts. Client findings never leave the client.
- A reference stable enough to quote back at us in a year.
- A severity against a scale we publish, so you can argue with it.
- The resource as your own console names it, never paraphrased.
- The request, the response and the timestamp.
- The impact in a sentence your board can read.
- The specific change, with the policy written out.
- Honest engineering hours, including the awkward ones.
A rating you can hold us to
Most reports rate findings against a scale nobody publishes, which makes every rating unarguable and therefore worthless. Here is ours. If you think something is rated wrong, this is the page you get to point at.
Nobody breaks in any more. They sign in and keep going
Almost every cloud incident worth the name is a chain of permissions that somebody granted deliberately, one hop at a time. That chain does not appear in a vulnerability report, a compliance questionnaire or a dashboard — you have to follow it.
Worked examples, written against invented accounts. Client findings never leave the client.
The only number that matters is the second one
An audit produces a score. What the engagement is judged on is where that score is ninety days later, so we publish the curve, including the part where it stops falling.
A typical 90-day window on our own scale, illustrative rather than any one client’s. The flat part is the point: what is left after a month needs a change window, not an afternoon.
Median across the first 90 days
Within 14 days, every engagement so far
We pair on the fourth
We will tell you what a technical audit cannot cover
A framework is mostly policies, people and suppliers. We evidence the estate, and we are specific about the controls that are yours to prove some other way — one square each, so the remainder is countable rather than rounded off.
The international standard for an information security management system. Annex A carries 93 controls; a cloud audit speaks directly to the technological ones.
The report North American customers ask for. Trust Services Criteria, tested over a window rather than on one day.
Required if you touch card data. Prescriptive, technical, and unforgiving about scope — most of the work is proving what is out of it.
Four things we will not do
Every one of these costs us work we could otherwise have taken. That is what makes them worth printing.
From somebody who can actually give it, naming the accounts and the window. If your provider needs notice, we get it. No exceptions, including for the demo.
We take no commission, no referral fee and no partner margin from any vendor. If the honest answer is that you already own something that does the job, that is the answer.
Tooling gives us candidates. If a human here did not reproduce it, it does not go in the report — which is why our finding counts are lower than the tools’ and why they are all real.
A report where nothing is Low is a report nobody finishes, and a practice that cries wolf gets ignored on the day it matters. Our scale is published so you can hold us to it.
Tell us what you are running, and what is worrying you about it.
You will get a straight read on whether an audit is worth doing right now, what it would cover, and what it would cost — before anything is signed and without anybody being sold to.