A cloud security scan that ends in a list of fixes, not a 200-page PDF.
We review your AWS, Azure or Google Cloud account with read-only access, find what is exposed or misconfigured, and hand back a short, ranked list of fixes. If you want, we stay on to make the fixes with your team and scan again to prove they held.
Most cloud breaches do not start with a clever exploit. They start with a storage bucket left public, an access key committed to a repository two years ago, an admin account without multi-factor sign-in, or a database port open to the whole internet because someone needed to debug it on a Friday. These are configuration problems, and they build up quietly in every account that more than one person has touched.
A scan finds them. We connect with a read-only role you create and can revoke at any time, run automated checks against the CIS Benchmarks for your provider, and then do the part a tool cannot: read the results against how your business actually uses the account. A tool will flag two hundred items; most teams need to know which ten matter this week. That ranking is what you are paying us for.
A tool will flag two hundred items. Most teams need to know which ten matter this week.
The report is written for the people who will act on it. Each finding says what it is, where it is, why it matters for you specifically, and the exact change that fixes it — the console setting, the policy, or the line of Terraform. Where a finding touches a framework you answer to, we note it: SOC 2 and ISO 27001 for most US and UK buyers, Cyber Essentials in the UK, the Essential Eight in Australia. We map; we do not certify. Certification stays with an accredited auditor.
We run our own products and our clients’ products on AWS, Google Cloud, Azure and DigitalOcean, so the advice comes from accounts we operate day to day, not from a checklist we have only read. Nepal runs at UTC+5:45: a short hop from Dubai, a full morning crossover with London and the end of the Australian day, and a fixed daily window with North America. Most of the work is asynchronous anyway; the scan runs while you sleep.
Scan, fix, or keep watching
- 01
Cloud security scan
A read-only review of one cloud account or project: identity and access, storage exposure, network rules, logging, encryption and secrets. You get a ranked findings report and a walk-through call.
Fixed price · one-off - 02
Scan and fix
The scan, then we make the fixes with your team — policies tightened, keys rotated, logging switched on, infrastructure code updated — and re-scan to confirm each finding is closed.
Fixed scope · remediation - 03
Ongoing review
A scheduled re-scan each month, a short report of what changed, and someone to ask before you open a port or hand out a new role. For teams without a security person on staff.
Monthly · advisory
What every scan covers
- Read-only access through a role you create and can revoke
- AWS, Microsoft Azure and Google Cloud
- Checks against the CIS Benchmarks for your provider
- Identity, storage, network, logging, encryption and secrets
- Findings ranked by real risk to your business
- The exact fix for each finding, console or code
- A written authorisation and scope before anything runs
What teams ask before a scan
- What access do you need to our cloud account?
- A read-only role or service account that you create and control. We give you the exact policy to attach. It cannot change or delete anything, and you can revoke it the moment the review ends. For the fix engagement we work under your change process, through your own accounts and repositories.
- Is this a penetration test?
- No. A scan reviews how your cloud is configured from the inside, with your permission. A penetration test attacks your systems from the outside to see what an intruder could reach. Many teams start with the scan because it finds the most common problems for less money; if you need a penetration test as well, we will tell you and scope it separately in writing.
- Will this get us SOC 2, ISO 27001 or Cyber Essentials?
- It will not certify you — only an accredited auditor or certification body can. What it does is find and fix the cloud configuration gaps those audits look at, and note which control each finding relates to, so you go into the audit with fewer surprises.
- Which countries do you work with?
- We work with businesses in the United States, United Kingdom, Canada, Australia and the United Arab Emirates, and elsewhere on request. Everything is done remotely. We sign your NDA and data-processing terms before we receive any access.
- How long does a scan take, and what does it cost?
- A single account usually takes one to two weeks from access to report, depending on its size. We quote a fixed price after a short scoping conversation about how many accounts, projects and regions you run, and you have that price in writing before we start.
Tell us what you run, and where.
Which cloud, roughly how many accounts or projects, and anything you are already worried about. We reply with a fixed price and the read-only policy to attach.
Lattice Nepal Pvt. Ltd. · Bharatpur · Kathmandu · info@latticenepal.com