Private beta

Know what's misconfigured in your AWS account before someone else finds it.

PostureRadar runs read-only checks against your AWS account on a schedule and emails you the findings. No agents to install, no write access granted, no dashboard you have to remember to check.

scan report — account 837219004821
$ posture-radar scan --region us-east-2
CRITICALPublic S3 Bucketsprod-backups-2024 allows public read
HIGHStale IAM Access Keysci-deploy key is 214 days old
HIGHSecurity Groupssg-08f2a91 opens 22/tcp to 0.0.0.0/0
MEDIUMRoot Account Risksroot account has no MFA device
MEDIUMCloudTrail Loggingno multi-region trail configured
5 findings — 41 checks — 12 regions — 2.4s
Coverage

What it checks

Public exposure S3 buckets with public ACLs/policies, publicly accessible RDS instances
Identity & access Stale IAM access keys, users without MFA, root account risks
Network exposure Security groups open to the internet on sensitive ports
Encryption & logging Unencrypted EBS volumes, missing or inactive CloudTrail logging
Threat detection Active GuardDuty findings at medium severity and above
Setup

How it works

1
Deploy a read-only role

A small CloudFormation template creates one IAM role in your account, scoped to exactly the read-only permissions the checks need. No write or delete access, ever.

2
We scan on a schedule

PostureRadar assumes that role, runs the checks across every region, and emails you a findings report — nothing is stored beyond what's needed to generate it.

3
You fix what matters

Findings are ranked by severity so you know what to act on first. Cancel or pause anytime.

Pricing

Two ways to use it

Self-serve

Fully automated

Deploy the role, get a report by email on schedule. No dashboard, no setup call.