Security Assurance
Security posture where engineering decisions are made — in the cloud account, the cluster, the pipeline and the code.
Runs today, on Google Cloud
Connect a Google Cloud project and this module reads it. Today that means:
- VPC firewall rules open to 0.0.0.0/0
- Primitive roles and public members in the project IAM policy
- Cloud SQL public IP, SSL enforcement and authorised networks
- Long-lived user-managed service account keys
It reads Google Cloud only, not AWS or Azure, and it does not track remediation. Everything further down this page is where the module is going, not what it does now. The wider review is work we do as an engagement — Cloud Security Assessment.
Why this module exists
Security tools report thousands of findings and engineering teams learn to ignore them. The problem is rarely detection — it is that nothing tells you which twelve of those findings matter this week.
What it is being built to surface
Descriptions of intent. No findings exist yet, because nothing is connected yet.
Identity exposure
Over-broad roles, unused credentials, and paths that lead to privilege escalation.
Infrastructure as code
Misconfiguration caught before it is applied rather than after.
Secrets and supply chain
Credentials in the wrong places, and dependency risk that reaches production.
Control mapping
Technical state mapped to the frameworks you are audited against.
What the module covers
- Cloud and identity security posture
- Infrastructure-as-code and pipeline security
- Secrets and software supply chain
- Control mapping for compliance work
Tell us what this would need to catch
We are designing this against real environments. If this is a problem you have, the fastest way to shape it is a conversation with the engineers building it.
Talk to an Engineer