Cloud-security assurance for AWS

Know your AWS security posture — continuously.

CloudCerta connects to your AWS accounts with a read-only role and continuously assesses your security posture — no credentials stored, no changes made to your infrastructure.

  • Read-only access
  • No credentials stored
  • Set up in minutes
Built for the way security teams work on AWS
Built for SOC 2Read-only IAM roleGDPR readyNo data stored
Platform

Everything you need to stay on top of AWS security

Built tool-neutral from day one — Cloud Posture for AWS today, more tools and clouds to come.

Cloud Posture

Continuous best-practice checks across every connected AWS account, mapped to real-world security controls.

Read-only AWS connector

A cross-account IAM role plus unique External ID — no credentials are ever stored or logged.

Continuous & scheduled scans

Set it once — CloudCerta keeps re-checking on your schedule so posture never drifts silently.

Findings & severity scoring

Every gap is triaged by severity and scored — a passing check is never quietly assumed.

Team roles & multi-tenant

Role-based access and strict tenant isolation, built in from day one for teams of any size.

Reports & notifications

Share posture reports with stakeholders and stay alerted the moment new findings land.

How it works

Read-only access. Zero stored credentials.

CloudCerta gets read-only access and never stores your cloud credentials — three steps from connect to insight.

1

Connect

Grant a read-only role with a unique External ID — sessions are capped at one hour, read-only policy only.

2

Scan

CloudCerta runs continuous posture scans across every connected account, on demand or on a schedule.

3

Act

Review prioritized findings, track your score over time, and share reports with your team.

Coverage & compliance

Your whole AWS footprint — plus SOC 2 & GDPR readiness

Coverage isn't a fixed list. CloudCerta runs continuous best-practice checks across the services your accounts actually use — storage, identity, compute, networking, logging, encryption, and more — with new checks landing all the time.

On top of raw posture, it rolls findings up into framework readiness scores — so you can see where you stand against SOC 2 and GDPR at a glance.

Connect an account
Framework readiness
SOC 287%
Type II control readiness
GDPR92%
Data-protection readiness

Example figures. Readiness is an indicator based on the technical controls CloudCerta can observe — not a compliance assessment or audit.

Example service checks
S3
Amazon S3
Buckets & ACLs
IAM
IAM
Users & policies
EC2
EC2
Security groups
RDS
RDS
Encryption
CT
CloudTrail
Audit logging
KMS
KMS
Key rotation
VPC
VPC
Network access
λ
Lambda
Function config
+ every other service in your account
Pricing

Simple, transparent pricing

Start free on a single account. Scale to scheduled scans, findings scoring, and team roles when you're ready.

Starter

Free

For a single account and on-demand checks.

Get started
  • 1 AWS account
  • Cloud Posture checks
  • On-demand scans
  • 1 user
  • Community support

Team

Most popular
$49/ month

For growing teams that need scheduled coverage.

Start free trial
  • Up to 5 AWS accounts
  • Full Cloud Posture checks
  • Scheduled scans
  • Findings & severity scoring
  • Team roles (up to 10 users)
  • Reports & email support

Enterprise

Custom

For organizations with advanced governance needs.

Contact sales
  • Unlimited accounts
  • SSO / SAML
  • Advanced RBAC & audit logs
  • Priority support + SLA
  • Custom integrations
FAQ

Questions, answered

No. CloudCerta assumes a cross-account read-only IAM role using a unique External ID. Sessions are capped at one hour and nothing — no keys, no secrets — is ever stored on our side.

See your posture score in minutes

Connect a read-only role and get your first continuous assessment today. No credentials stored, ever.