Cloud & Identity Security Review
One leaked credential should not empty your tenant. We trace the attack paths an intruder would actually take — then help you close them.
What we cover
- AWS, Azure, and GCP IAM: privilege paths and escalation routes
- Federation and SSO configuration — Keycloak, Entra ID, Okta
- Secrets management: sprawl, rotation, CI/CD key exposure
- MFA coverage and phishing-resistant methods
- Token lifetimes, consent grants, and stale credentials
- Network segmentation, storage exposure, and blast radius
- Logging and detection coverage — what would you actually see?
How we test
We start from read-only access: users, roles, policies, grants, and trust relationships across your tenant(s).
From realistic starting points — one leaked key, one phished admin — we trace how far an intruder could actually reach.
Agreed, controlled tests of token handling, consent, and federation edge cases within the rules of engagement.
Findings sorted by real attack path, not checklist severity, with a sequenced remediation plan and a verification pass.
What you get
- Config findings with attack paths, not just checklists
- Identity perimeter scorecard for leadership
- Zero-trust gap analysis with a sequenced rollout plan
- Verification pass after remediation
The engagement at a glance
A short conversation about your environment. You receive a written scope, timeline, and fixed quote — no obligation.
Testing begins only with your written permission and agreed rules of engagement. Always.
A calendar agreed before we start, with an agreed communication plan while testing runs.
A verification pass over everything you fix — included in the price, not an add-on.
See the full engagement process → and how pricing is scoped in our public pricing guide.
Related research from Hmmnm
Common questions
Do you need write access to our cloud?
No. The core review is read-only. Any active testing happens only with explicit written authorization and tightly scoped, time-limited test identities.
We run multiple clouds — can you cover all of them?
Yes. Multi-cloud identity sprawl is exactly where attack paths hide — shared credentials, mirrored misconfigurations, and federation trust between platforms.
Can findings support ISO 27001 or SOC 2 evidence?
The report is structured to slot into audit evidence for access-control and monitoring controls, though we are not the certification body itself.
Want this assessed for your environment?
A short scoping conversation is enough to get a fixed quote. No obligation — a researcher replies.
Start the conversation →