Skip to content

Who and what can reach your production cloud, and would you notice?

With read-only access to your AWS, Azure or Google Cloud accounts, we work out who and what can reach production.

Free 30-minute call.

A typical SaaS product. The cloud account runs your product and keeps your data and your customers’.

One leaked key that can read your production data

A fictional example of what can go wrong here.

  1. A key leaks

    A developer’s access key ends up in a public repository or on a lost laptop.

  2. It can do too much

    It was made for one quick task, but it can read every storage bucket.

  3. Backups are in reach

    Your database backups sit in storage the key can open.

  4. Nobody notices

    Nothing logs or alerts on access to that storage.

So we ask: Could one leaked key read your data and your customers’, and would you know?

For your engineer

iam/report-uploader-policy.json

{
  "Effect": "Allow",
  "Action": "s3:*",
  "Resource": "*"
}

Read a fictional cloud design example

What we check

The questions we start from. We agree the final list with you on the call.

Best done when your cloud has grown quickly, before a launch, or when nobody’s sure who can reach what.

  • What can each person, role and service actually do?
  • Which storage, databases and services can be reached from the internet?
  • Where do your keys live, who can use them and how often do they change?
  • If something went wrong, would the records you need exist?

What you get, and what it costs

A report with the evidence for each issue, what to fix first, and one round of retesting. See what a report looks like.

Included

  • The assessment of the systems we agree
  • A findings report with the evidence for each issue
  • What to fix first, and how to check each fix
  • A walkthrough call with your engineers
  • One round of retesting after your fixes
  • A list of permissions nobody seems to use, ready to remove

Before you enquire

What people ask us most. Wondering whether a pentest would do? Is a VAPT enough?

What do you need from us?

Read-only access to the accounts or projects in scope, or exported configuration. Infrastructure code helps if you have it.

Where do you stop?

We cover the accounts or projects you name. Pipelines and developer access are a separate assessment.

Is this a penetration test?

No. We read how your accounts are set up, usually with read-only access. If you want us to test hands-on as well, we’ll put that in the scope.

Is retesting included?

Yes, one round. Once your team has made the fixes, we retest them. Each finding also comes with a check your team can run themselves.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Start with the account that holds your data

Which cloud providers do you use, and how many accounts or projects?

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team

Request a free call

Send a short outline of what you want checked and any deadline.

Email Unmesha

Please leave out passwords and customer data. How we handle enquiry information.