Read-only scans

Know what's misconfigured in your AWS account before someone else finds it.

PostureRadar runs read-only checks against your AWS account weekly and emails you the findings. No agents to install, no write access granted, no dashboard you have to remember to check.

scan report — account 837219004821
$ postureradar scan --region us-east-2
CRITICALPublic S3 Bucketsprod-backups-2024 allows public read
CRITICALSecurity Groupssg-08f2a91 opens 22/tcp to 0.0.0.0/0
CRITICALRoot Account Risksroot account has no MFA device
HIGHStale IAM Access Keysci-deploy key is 214 days old
HIGHCloudTrail Loggingno multi-region trail configured
5 findings — 14 checks — all regions
Coverage

What it checks

Public exposure S3 buckets with public ACLs/policies, public EBS/AMI/RDS snapshots, publicly accessible RDS instances
Identity & access Stale IAM access keys, users without MFA, root account risks — plus a note if your account uses IAM Identity Center (SSO), since its own MFA setting isn't something any external scanner can verify via API
Excessive privilege IAM users/roles with AdministratorAccess attached directly or via group membership, or roles any AWS account can assume
Network exposure Security groups open to the internet on sensitive ports — including exposure hidden behind a managed prefix list
Instance hardening EC2 instances still allowing IMDSv1
Encryption Unencrypted EBS volumes, attached or not
Logging Missing or inactive multi-region CloudTrail coverage
Threat detection Active GuardDuty findings at medium severity and above
Setup

How it works

1
Deploy a read-only role

A small CloudFormation template creates one IAM role in your account, scoped to exactly the read-only permissions the checks need — no write or delete access, ever. Read the template yourself before you deploy anything. Delete the stack any time and access is gone.

2
We scan every week

PostureRadar assumes that role and runs 14 checks — public S3 buckets, stale IAM keys, open security groups, missing MFA, and more — across every region, then emails you a findings report with specific fix guidance for most findings: console steps and a CLI command, where useful. No dashboard, no searchable findings archive.

3
You fix what matters

Findings are ranked by severity so you know what to act on first. Cancel anytime.

Pricing

One plan, per AWS account