Find and fix the security gaps in your AWS account

A fixed-price Cloud Security Baseline Audit for startups. You get a clear, prioritised report in 3 business days, and I can implement the fixes if you want.

Read-only access Signed authorisation first Fixed price, fixed scope
Finding S3-01 Critical

Storage bucket readable by anyone on the internet

Evidence
Bucket customer-uploads allows public read
Impact
Customer files can be downloaded without logging in
Fix
Turn on Block Public Access and remove the public policy statement
Status
Fixed and re-scanned

Excerpt from the sample report

Cloud Security Baseline Audit

The most common ways startups get breached on AWS are misconfigurations, not clever hacks. This audit checks for them and tells you exactly what to change.

IAM

Who can log in, and what they can do

Root account use, MFA, unused access keys, and users or roles with far more permission than they need.

S3

Whether any storage is public

Public buckets, open bucket policies, missing encryption, and missing access logging.

CloudTrail

Whether activity is recorded

If something goes wrong, can you see who did what? Logging coverage, retention, and integrity.

Networking

What's reachable from the internet

Security group rules that expose SSH, remote desktop, or databases to the whole internet.

See exactly what you'll receive

This is a redacted report from an audit of my own test environment. Your report follows the same format.

  • An executive summary written for founders and investors, not only engineers
  • Each finding with its severity, evidence, business impact, and exact fix steps
  • How to confirm each fix worked
  • A quick-win list you can finish in an afternoon
Download the sample report (PDF)

How it works

Three steps, and you always know what happens next.

  1. Scoping call

    A free 30-minute call about your AWS setup and what worries you most. If the audit isn't a good fit, I'll say so.

  2. Audit

    You sign a short authorisation and create a temporary read-only user. I review your account against the CIS benchmark.

  3. Report and fixes

    You get the report within 3 business days. If you want, I fix the Critical and High findings, then re-scan to prove they're resolved.

How I handle your access

Giving someone access to your cloud account is a serious decision. These rules apply to every engagement, with no exceptions.

  • Nothing starts without a signed agreementA written authorisation and scope, signed by you, before any access is used.
  • Read-only access onlyYou create a temporary user with the AWS-managed SecurityAudit policy. It can look, not change.
  • No root credentials, everI never ask for or accept root logins, master keys, or admin passwords.
  • Access removed when we're doneI ask you to delete the audit user at the end, and your findings stay confidential.

About me

I'm Ishtiyak Mahmud, a cloud security consultant working with startups worldwide from Bangladesh. I help small teams find the AWS misconfigurations that lead to breaches, and I fix them instead of only reporting them.

I keep my scope narrow on purpose. I'd rather do one thing very well than promise everything.

  • AWS
  • Prowler
  • CIS AWS Foundations Benchmark
  • Linux
  • Python

Questions

Will you touch our production systems?

No. The audit uses read-only access, so nothing in your account can be changed. If you want me to implement fixes, we agree on each change in writing first.

Which cloud providers do you cover?

This audit is for AWS. If you use another provider, mention it on the scoping call and I'll tell you honestly whether I can help.

What if you don't find anything serious?

That's a good result, and the report documents it. A clean baseline is useful evidence for investors and enterprise customers.

How do I pay?

50% before the audit starts and 50% on delivery. I accept international payments through Payoneer, Wise, and PayPal.

Want to know where your AWS account stands?

Book a free 30-minute scoping call. No obligation, no sales pitch.

Book a free scoping call