Trusted security · Built from London
Products
Module 05

Cloud Security.

Misconfigurations visible from the internet.

AWS, Azure and GCP exposure discovered from the outside, without API keys, without read-only roles. The same path an attacker would take.

At a glance
Module
05
Cadence
Hourly
Scoring axes
4
Compliance
SOC 2 · ISO · PCI
What we monitor

Inside the module.

Public storage
S3 buckets, Azure blobs, GCS buckets indexed and tested for public read/write.
Open data stores
Internet-facing Elasticsearch, MongoDB, Redis, Postgres without authentication.
Leaked secrets
AWS keys, GCP service-account JSON, Azure SAS tokens in public repos, paste sites, Wayback.
Cloud asset attribution
IPs and hostnames mapped to your AWS / Azure / GCP accounts via cert and DNS analysis.
Hybrid attack paths
Public IaaS instances that bridge to on-prem or partner networks.
Origin server exposure
CDN-bypass risk, origin IPs leaked through certificate transparency.
Scoring

How this module contributes to your rating.

Each factor below is a normalised sub-score (0–100). The module score is the asset-weighted geometric mean, a single missing header on your billing endpoint shouldn’t weigh the same as one on a marketing page.

Public storage exposure
count + sensitivity of public buckets / containers
Open data-store count
unauthenticated databases reachable from the internet
Secret leakage
severity of recently leaked credentials, weighted by recency
Origin-IP leakage
CDN-protected hosts with discoverable origin

See Cloud Security on your domain.

Get your free rating