What we look at
We score each dimension as pass / partial / gap, with one sentence of context. The PDF lists the three highest-leverage gaps with the specific control IDs and the IAM or CLI command you can use to confirm the finding yourself.
-
Account structure
Organization layout, workload separation, Log Archive isolation, CloudTrail centralized at the org level.
-
Identity & access
IAM Identity Center, root-account hygiene, MFA enforcement, permission-set design.
-
Preventive guardrails
SCPs, RCPs, AWS Config rules and automatic remediations — the layer that blocks non-compliance before Security Hub sees it.
-
IaC maturity & drift
Module-and-live split, default_tags discipline, state-backend hardening, pre-commit chain, and who-can-apply controls.
-
Network topology
VPC layout, subnet tiering, public-subnet exposure, NAT and endpoint posture, per-workload security-group isolation.
-
Public surface
S3 public-access block, ALB TLS posture, CloudFront origins, public ECR, GitHub OIDC exposure.
-
Detection & monitoring
Security Hub, GuardDuty, AWS Config, CIS 4.x metric-filter alarms, and the application-level alarms wired to act on their findings.
-
CI/CD trust posture
GitHub OIDC roles, ARN-scoped policies, branch protection, IaC plan-and-apply path.
Benchmark version is pinned in the PDF you receive — we keep the public page version-agnostic so you don't have to wonder if the control IDs in your call match the ones on the website.
Request your Scorecard
Six fields. We'll reply within 4 hours from the founder's inbox with a link to book the 30-minute call.
What happens after you submit
-
Within 4 hours
Confirmation email
From Nando, with the call link and a 2-sentence agenda based on what you told us above.
-
The 30-minute call
Screen-share, or walk it verbally
We focus on the gaps that move the needle, not the ones that are trivially fixable in a Friday afternoon.
-
Within 2 business days
1-page PDF in your inbox
Eight dimensions scored, the three highest-leverage gaps with control IDs and CLI commands you can run, and an appendix on how NdCoders runs production on this same baseline.
If a gap is small enough that one of your engineers can close it on a Friday afternoon, we will say so on the call. We are not trying to manufacture a sales conversation out of every Scorecard.
What this is not
- Not a compliance readiness assessment.
- This is not a SOC2, ISO 27001, or HIPAA readiness assessment, and we don't sell the documentation that goes with those audits. If your primary motivation is “we have a questionnaire on the desk and a deadline,” you are better served by Vanta, Drata, or Secureframe paired with a compliance-specialist contractor whose business model is the audit funnel. That is genuinely not us.
- Not a managed service.
- We don't run your AWS, and we don't sell on-call rotations. We deliver fixed-scope engagements, hand you the IaC, and step out.
- Not a sales call dressed up as a free audit.
- If we don't think we should be your next engagement, we will say so on the call — and the PDF lands in your inbox either way.
- Real founder time.
- The 30 minutes is real founder time. The 1-page PDF is real written analysis, not a templated export. The trade-off we're making is throughput: we cap Scorecard calls at a small number per week. If the next slot is two weeks out, that's why.