Free · 30 minutes with the founder

An honest read of your AWS, in 30 minutes.

A call with the founder, followed by a 1-page PDF report in your inbox within two business days. Eight dimensions — the same ones we lead with on every engagement — scored pass / partial / gap. We'll tell you what to fix yourselves, what we'd take on, and what isn't worth the work.

Free. No follow-up call unless you ask for one.

Request the Scorecard

Honest read — we'll point at DIY, hire, or one of our engagements.

What we look at

We score each dimension as pass / partial / gap, with one sentence of context. The PDF lists the three highest-leverage gaps with the specific control IDs and the IAM or CLI command you can use to confirm the finding yourself.

  1. Account structure

    Organization layout, workload separation, Log Archive isolation, CloudTrail centralized at the org level.

  2. Identity & access

    IAM Identity Center, root-account hygiene, MFA enforcement, permission-set design.

  3. Preventive guardrails

    SCPs, RCPs, AWS Config rules and automatic remediations — the layer that blocks non-compliance before Security Hub sees it.

  4. IaC maturity & drift

    Module-and-live split, default_tags discipline, state-backend hardening, pre-commit chain, and who-can-apply controls.

  5. Network topology

    VPC layout, subnet tiering, public-subnet exposure, NAT and endpoint posture, per-workload security-group isolation.

  6. Public surface

    S3 public-access block, ALB TLS posture, CloudFront origins, public ECR, GitHub OIDC exposure.

  7. Detection & monitoring

    Security Hub, GuardDuty, AWS Config, CIS 4.x metric-filter alarms, and the application-level alarms wired to act on their findings.

  8. CI/CD trust posture

    GitHub OIDC roles, ARN-scoped policies, branch protection, IaC plan-and-apply path.

Benchmark version is pinned in the PDF you receive — we keep the public page version-agnostic so you don't have to wonder if the control IDs in your call match the ones on the website.

Request your Scorecard

Six fields. We'll reply within 4 hours from the founder's inbox with a link to book the 30-minute call.

Engineering team size
What brings you here today?

By submitting, you agree to receive one confirmation email and the 1-page PDF.

What happens after you submit

  1. Within 4 hours

    Confirmation email

    From Nando, with the call link and a 2-sentence agenda based on what you told us above.

  2. The 30-minute call

    Screen-share, or walk it verbally

    We focus on the gaps that move the needle, not the ones that are trivially fixable in a Friday afternoon.

  3. Within 2 business days

    1-page PDF in your inbox

    Eight dimensions scored, the three highest-leverage gaps with control IDs and CLI commands you can run, and an appendix on how NdCoders runs production on this same baseline.

If a gap is small enough that one of your engineers can close it on a Friday afternoon, we will say so on the call. We are not trying to manufacture a sales conversation out of every Scorecard.

What this is not

Not a compliance readiness assessment.
This is not a SOC2, ISO 27001, or HIPAA readiness assessment, and we don't sell the documentation that goes with those audits. If your primary motivation is “we have a questionnaire on the desk and a deadline,” you are better served by Vanta, Drata, or Secureframe paired with a compliance-specialist contractor whose business model is the audit funnel. That is genuinely not us.
Not a managed service.
We don't run your AWS, and we don't sell on-call rotations. We deliver fixed-scope engagements, hand you the IaC, and step out.
Not a sales call dressed up as a free audit.
If we don't think we should be your next engagement, we will say so on the call — and the PDF lands in your inbox either way.
Real founder time.
The 30 minutes is real founder time. The 1-page PDF is real written analysis, not a templated export. The trade-off we're making is throughput: we cap Scorecard calls at a small number per week. If the next slot is two weeks out, that's why.