Infrastructure changes every week, and the change that opens something up looks the same as the change that ships a feature. The gap is rarely a decision. It is a default nobody revisited, a key nobody rotated, a log nobody switched on.
Infrastructure changes weekly, and the change that opens something up looks exactly like the change that ships a feature. We find storage buckets and objects readable from the internet, and secrets committed to a repository or sitting in plaintext where the platform offers a real store for them.
Permissions accumulate because removing one is riskier than leaving it. We read IAM roles and policies for grants that reach past the job, wildcard permissions included, and we find access keys that have never been rotated and name the account each one belongs to.
The answer usually arrives too late to matter. We check whether audit logging and trails are switched on at all, and whether the ones that are on actually cover the whole account rather than one region somebody set up first.
Those questions are the shape of it, not the inventory. Underneath them is a larger set of individual settings we read on each platform, and it moves every time a platform ships something new.
Where a CIS safeguard fits the evidence, the finding carries it, so the answer you give an auditor is the answer we already gave you. Where none fits, we leave it unmapped rather than claim a control we cannot stand behind.
A finding names the bucket, the role or the key, not just the class of problem.
Every change is prepared for you, made only once you approve it, logged, and reversible where the platform allows. How that works
Today we read infrastructure from AWS, GitHub, Cloudflare and Vercel. More platforms are in development.