What we check
Misconfiguration
Misconfiguration
Insecure service settings across compute, storage, networking, databases, containers, serverless and managed platform services. Defaults that are unsafe in production, deprecated configurations, and settings that silently weaken another control.
Over permissive identity
Over permissive identity
Wildcard and administrative permissions, roles and principals that can escalate privilege, unused and stale credentials, keys that have never been rotated, trust relationships that accept any principal, and privileged accounts without strong authentication.
Public data exposure
Public data exposure
Storage, databases, snapshots, images and endpoints reachable from the internet. Anonymous read or write access, and management interfaces exposed beyond an allowed network.
Encryption gaps
Encryption gaps
Encryption at rest or in transit disabled, platform managed keys where a customer managed key is required, weak transport settings, and key material without rotation.
Logging and audit gaps
Logging and audit gaps
Control plane audit logging disabled or incomplete, log retention below policy, logs stored without protection against tampering, and monitoring or alerting absent on security relevant events.
Identity layer, where granted
Identity layer, where granted
On Azure, with the optional directory tier: privileged role assignments, conditional access coverage, legacy authentication exposure, and multi factor authentication registration.
What we never touch
Access is read only, and it is configuration only.- No create, modify or delete on any resource.
- No access to what is inside a resource. Amnify reads configuration, not content.