Policy Suite
400+ policies, written and version‑controlled.
There is no platform to buy and nothing to migrate onto. The guardrails run inside your own accounts, on your schedule, and you keep them if you stop working with us — they are readable YAML in your repository, not settings inside somebody's product. We build them on Cloud Custodian, the open-source policy engine, so nothing here is a black box you have to take on faith. Ask to see the library on the call.
- Report → notify → enforce, per policy
- Scoped per account and environment
- Deletion always staged with a grace period
- Yours to keep
Ownership & attribution
Every resource gets an owner, an environment and a cost centre at creation — read from the CloudTrail event, not chased in a quarterly cleanup.
- aws-gov-ec2-auto-tag
- aws-gov-rds-auto-tag
- aws-gov-tag-compliance-ec2-mark
- aws-gov-ebs-inherit-instance-tags
- aws-gov-asg-tags-not-propagated
Public exposure
The findings that end up in headlines: data, snapshots and endpoints reachable from the internet without a decision behind them.
- aws-gov-s3-global-grants-remove
- aws-gov-rds-snapshot-public
- aws-gov-ebs-snapshot-public
- aws-gov-eks-public-endpoint
- aws-gov-sg-restrict-admin-ingress
Compliance readiness
The first questions any auditor asks — trail, config history, encryption at rest, key rotation, MFA — answered continuously instead of the week before the audit.
- aws-gov-cis-cloudtrail-secure
- aws-gov-cis-config-enabled
- aws-gov-rds-storage-unencrypted
- aws-gov-cis-kms-key-rotation
- aws-gov-cis-iam-user-needs-mfa
Resilience & continuity
Outage cost, not cloud cost: databases without backups, single-AZ load paths, and backup vaults a compromised key could empty.
- aws-gov-rds-no-backups
- aws-gov-dynamodb-no-pitr
- aws-gov-backup-vault-no-lock
- aws-gov-alb-single-az
- aws-gov-ec2-prod-termination-protection
Runaway & end-of-life
The bill shock and forced-upgrade outages nobody budgets for: spend forecast breaches, unbounded concurrency, log-ingest spikes, versions AWS is about to retire.
- aws-gov-budget-forecast-exceeds-limit
- aws-gov-lambda-no-reserved-concurrency
- aws-gov-log-group-ingestion-spike
- aws-gov-rds-ca-cert-expiring-7d
- aws-gov-eks-eol-version
The five highest-impact policies in each area, drawn from the full library. Scope, thresholds and actions are configured per account — a policy that reports in one environment can enforce in another.
Every policy starts in report mode.
You watch what a policy would have done for as long as you want before it is allowed to act, and you promote it to enforce one policy, one account at a time. The audit shows you which of these would fire on your estate today.