FAQ
Frequently asked questions.
The short version of everything below: read-only access, no credentials stored, cancel anytime, and if something goes sideways you can usually fix it yourself.
What does PostureRadar actually do?
It scans your AWS account for common security misconfigurations — public S3 buckets, public EBS/AMI/RDS snapshots, stale IAM access keys, users without MFA, IAM users/roles with AdministratorAccess or overly permissive trust policies, security groups open to the internet, unencrypted EBS volumes, EC2 instances still allowing IMDSv1, GuardDuty findings, publicly accessible RDS instances, missing CloudTrail logging, and root account risks — and emails you a plain-English report with specific fix guidance for most findings. If your account uses IAM Identity Center (AWS SSO), the report also notes that its MFA enforcement isn't something we can verify (see the next question).
Does the MFA check cover IAM Identity Center (SSO) users?
No — the MFA and access-key-age checks only cover traditional IAM users with console passwords. If your account signs in through IAM Identity Center (AWS SSO) instead, those users aren't IAM users and fall outside those two checks. This isn't a choice we made: AWS doesn't expose Identity Center's own MFA enforcement setting through any API, so there's no way for PostureRadar (or any external scanner) to verify it programmatically. If Identity Center is enabled in your account, your report will note that as an informational item — verify its MFA setting directly in the IAM Identity Center console under Settings → Authentication.
What AWS access does it need? Is it safe?
Strictly read-only. The role you deploy grants only
List/Get/Describe-style
permissions — nothing that can create, modify, or delete
anything in your account. You can read the exact permissions
yourself in the
CloudFormation template
before deploying it.
Do you store my AWS credentials?
No. Access works through IAM role assumption
(sts:AssumeRole) with an External ID unique to
you (shared across every AWS account you connect under one
subscription, not a separate one per account) — there are no
access keys or long-lived credentials involved anywhere in
this process, so there's nothing on our side that could leak.
Can PostureRadar cover more than one AWS account?
Yes — one subscription can cover as many AWS accounts as you set at signup, up to 25 (dev, prod, per-team, sandboxes, whatever your setup looks like), billed per account as part of one subscription. Need more than that? Email us — 25 is just an abuse guard on the signup form, not a hard product limit. Deploy the same read-only role and enter that AWS account's 12-digit ID once per account. If you haven't connected all the accounts you signed up for yet, use the add an account page any time — no need to contact support. Need to cover more accounts than your subscription currently includes? Use the subscription management page to increase your quantity yourself, or email us if you'd rather we handle it.
How often do you scan my accounts?
Every week, automatically — no need to schedule anything yourself. Fixed something and don't want to wait? Report emails include a "scan again" link that triggers an immediate on-demand scan of that account instead.
What happens if I lower my account quantity?
We keep scanning your oldest-connected accounts up to your new quantity and stop scanning the rest — we'll email you once, at the point it takes effect, listing exactly which account(s) will no longer be covered. Nothing is deleted or disconnected on our end; if you raise your quantity again later, those accounts pick back up automatically with no need to redeploy or reconnect anything.
Which AWS regions do you scan?
All regions enabled on your account, automatically — you don't need to tell us where your resources live.
Do I need to install any software or agent?
No. Everything runs through the IAM role you deploy via CloudFormation — nothing gets installed inside your AWS account or on any of your infrastructure.
Do you keep a copy of my scan results?
We don't keep a searchable archive or dashboard of past findings — each report is generated fresh and emailed to you, not stored as a queryable record. Operational copies do exist in our email provider's delivery records and technical logs, the same as any email service; see our privacy policy for the full picture. Findings are also sent to Anthropic's API to draft the remediation guidance included in your report.
I accidentally deleted the PostureRadarScanRole stack — what do I do?
Just redeploy it. The role has a fixed name, so recreating the stack with the same External ID restores the exact same access automatically — no new sign-up needed. Use our self-serve recovery page if you've lost the original deploy link.
If I cancel, does that remove PostureRadar's access to my AWS account?
No — cancelling stops your subscription (and future scans) at the end of your current billing period, not the moment you click cancel, so a scan already due before then may still run. Either way, the IAM role stays in your account until you delete the CloudFormation stack yourself. That's entirely in your control, any time.
How do I cancel, update my card, or change how many accounts I'm covering?
Use the self-serve subscription management page — enter the email you signed up with and we'll email you a secure link to Stripe's billing portal, where you can cancel, update your payment method, view past invoices, or change your subscription's account quantity. Cancellation and quantity decreases take effect at the end of your current billing period; adding accounts (a quantity increase) takes effect immediately, billed starting your next cycle with no mid-cycle charge. Email [email protected] if you'd rather we handle it.
My subscription lapsed (or I cancelled) — can I come back?
Yes, and you don't need to contact us — just
sign up again with the same email
address. If you never deleted your PostureRadarScanRole
stack, the role is still there, so you can skip straight to
entering that same 12-digit AWS account ID on the new checkout
page instead of redeploying anything.
Is PostureRadar affiliated with Amazon Web Services?
No. PostureRadar is an independent product that uses the AWS API to scan accounts customers connect to it — it isn't built, operated, or endorsed by Amazon.
Still have a question?
Email [email protected] — a person reads every message.