WARQLINE
WQL.PLATFORM.SECURITY.ASSURANCE// ONLINE
/ 01 — SECURITY ASSURANCE

Security Assurance

Security posture where engineering decisions are made — in the cloud account, the cluster, the pipeline and the code.

Runs today, on Google Cloud

Connect a Google Cloud project and this module reads it. Today that means:

  • VPC firewall rules open to 0.0.0.0/0
  • Primitive roles and public members in the project IAM policy
  • Cloud SQL public IP, SSL enforcement and authorised networks
  • Long-lived user-managed service account keys

It reads Google Cloud only, not AWS or Azure, and it does not track remediation. Everything further down this page is where the module is going, not what it does now. The wider review is work we do as an engagement — Cloud Security Assessment.

THE PROBLEM

Why this module exists

Security tools report thousands of findings and engineering teams learn to ignore them. The problem is rarely detection — it is that nothing tells you which twelve of those findings matter this week.

INTENDED SIGNALS

What it is being built to surface

Descriptions of intent. No findings exist yet, because nothing is connected yet.

Identity exposure

Over-broad roles, unused credentials, and paths that lead to privilege escalation.

Infrastructure as code

Misconfiguration caught before it is applied rather than after.

Secrets and supply chain

Credentials in the wrong places, and dependency risk that reaches production.

Control mapping

Technical state mapped to the frameworks you are audited against.

SCOPE

What the module covers

  • Cloud and identity security posture
  • Infrastructure-as-code and pipeline security
  • Secrets and software supply chain
  • Control mapping for compliance work

Tell us what this would need to catch

We are designing this against real environments. If this is a problem you have, the fastest way to shape it is a conversation with the engineers building it.

Talk to an Engineer