Over-permissioned IAM roles
Broad grants nobody's revisited since they were first written.
Misconfigured cloud resources
Public buckets, open ports, defaults that shipped straight to production.
Compliance gaps discovered during audits
Found by the auditor, not by you - the most expensive way to find out.
Unmanaged secrets and credentials
Hardcoded keys, no rotation, no vault, no owner.
Findings spread across multiple tools
A dozen dashboards, no single view of what actually matters.
Limited visibility into cloud threats
Activity in progress with nobody watching the account.
Our Security & Compliance Services
Everything a security program needs, actually delivered - end to end by certified cloud security specialists.
DOMAIN 01 · BASELINE
Security baseline
& hardening
- Benchmark against CIS Benchmarks & Cloud Security Best Practices
- Rank findings by real blast radius—not raw severity scores
- Remediate in priority order, internet-facing assets first
- Config conformance packs + Well-Architected review for continuous alignment
DOMAIN 02 · COMPLIANCE
Compliance
automation
- Map SOC 2, HIPAA, PCI-DSS & ISO 27001 controls to automated Config Rules
- Continuously validate compliance with Security Hub standards
- Automatically collect compliance evidence
- Raise tickets instantly when configuration drift is detected
DOMAIN 03 · IDENTITY
IAM cleanup
& zero trust
- Audit every user, role, and access policy
- Remove unused permissions after 90 days
- Rebuild access using the principle of least privilege
- Replace long-lived keys with SSO, MFA, and short-lived credentials
DOMAIN 04 · SECRETS
Secrets
management
- Extract credentials out of code, config files, and CI/CD variables
- Centralize in AWS Secrets Manager with KMS key policies
- Automatic rotation schedules enforced
- Encryption enforced on data at rest and in transit
DOMAIN 05 · DETECTION
GuardDuty
& Security Hub
- Enable threat detection across all accounts and regions
- Aggregate findings into a single Security Hub dashboard
- Reduce alert noise and route actionable alerts to the right teams
- Provide response runbooks for every critical alert type
The same controls, mapped to your framework
Logical access control, change management, continuous monitoring, incident response
PHI encryption, access audit trails, transmission security, workforce access limits
Network segmentation, cardholder data protection, key rotation, logging
Annex A technical controls with documented, repeatable evidence
Security Hub SOC 2 mappings · CloudTrail org trail · IAM Identity Center · GuardDuty
KMS + Config HIPAA pack · S3/EBS/RDS encryption rules · least-privilege roles
Config PCI pack · Secrets Manager rotation · VPC segmentation · WAF
Audit Manager assessments · conformance packs · exportable evidence
The CloudKeeper Advantage
Proven expertise, practical security, and measurable outcomes that keep your cloud secure as you scale.
Engagement Process
How the engagement runs - From read-only access to audit-ready
A typical engagement runs six to ten weeks depending on account sprawl. It starts with a free assessment, and you keep the findings report either way.
Assess
Read-only role, automated scan across every account and region, and a manual review of your identity and network design. You get a ranked findings report with the blast radius of each issue spelled out in plain language.
Prioritise
We agree what gets fixed, what gets accepted as a documented risk, and who owns each item. Anything internet-facing or credential-related goes to the top.
Remediate
Our engineers implement the fixes alongside your team — hardening, IAM rebuild, secrets migration, encryption, detection rollout — in change windows you approve.
Automate
Config Rules, conformance packs and auto-remediation go live so the environment stays compliant after we leave. Drift becomes a ticket, not a finding at next year's audit.
Evidence
Continuous evidence collection, a monthly posture review, and an exportable pack your auditor can work from directly.


Recognized by the Best in the Industry for
End-to-End Cloud Cost Optimization
Major Player in MarketScape’s Worldwide FinOps Cloud Cost Optimization Assessment.
Major Player in FinOps Cost Management Products PEAK Matrix Assessment 2025.
Notable Vendor in Magic Quadrant for Public Cloud IT Transformation Services - Midmarket Global.
Product Challenger in APAC for AWS Ecosystem Partners 2025.
Frequently Asked Questions
- Arrow1.What does a cloud security posture assessment actually involve? Q1. What does a cloud security posture assessment actually involve?
A cloud security posture assessment reviews your cloud environment against a control baseline - usually CIS Benchmarks alongside your provider's own foundational security best practices (AWS FSBP, Azure Security Benchmark, or Google Cloud's security baseline) - and reports where your configuration deviates. CloudKeeper's assessment uses a read-only role, runs automated scans across all accounts, subscriptions or projects and regions, adds a manual review of your identity and network design, and delivers a ranked findings report within five working days. It is free and carries no commitment.
- Arrow2.How long does it take to get SOC 2 or ISO 27001 ready on AWS? Q2. How long does it take to get SOC 2 or ISO 27001 ready on AWS?
For a mid-sized AWS environment, the technical control work typically takes six to ten weeks: one to two weeks to assess and prioritise, four to six weeks to remediate, and two to three weeks to automate continuous evidence collection. Timelines stretch with the number of accounts, the amount of legacy IAM to unwind, and how much of your infrastructure sits outside infrastructure-as-code. Note this covers the technical controls only - policy documentation and the audit itself are handled by your auditor.
- Arrow3.Do you need admin access to our production accounts? Q3. Do you need admin access to our production accounts?
No. The assessment phase runs entirely on a read-only IAM role that you create and can revoke at any time. Write access is only requested for the remediation phase, is scoped to the specific changes agreed in the prioritisation step, and every change goes through a change window you approve. All actions are logged in your own CloudTrail.
- Arrow4.Will cloud hardening our environment increase our cloud bill? Q4. Will cloud hardening our environment increase our cloud bill?
Some controls do add cost - GuardDuty, Config, CloudTrail data events and extended log retention all carry charges. CloudKeeper models that cost before implementation and tunes it: right-sized log retention and lifecycle policies, selective data event logging, and regional scoping. Because we run FinOps engagements for the same customers, the security spend is presented alongside the savings rather than buried in next month's invoice.
- Arrow5.Do you cover multi-cloud? Q5. Do you cover multi-cloud?
Yes - CloudKeeper supports multi-cloud environments across AWS, Azure, and GCP. Our engineering team includes certified cloud security specialists who handle baseline hardening, identity review, and compliance mapping natively on whichever cloud you run. Tell us your mix on the assessment call and we will scope accordingly.
