GuardKite

A change in your AWS accounts shouldn't go unnoticed for seven months.

GuardKite tracks every security check across every scan, comparing historical data to show you exactly what changed, and when.

The GuardKite dashboard: 426 open findings broken down by severity, a What changed feed listing checks that newly failed or resolved with the day each flipped, five exploitable attack paths, and IAM risk across 21 identities.

What changed, and when

Get immediate answers: Did this check fail today, or has it been failing since January? How many new critical issues popped up this week?

A check flipping state on a date A security group passed the ingress check on every scan from January until the thirtieth of July, when 0.0.0.0/0 was added to port 22. It has failed on every scan since. passed every scan Jan 14 open ever since now Jul 30 0.0.0.0/0 added to port 22 The finding is not new. The change is.

That security group is a routine finding on its own, and it sat open for weeks. What makes it worth opening is what it connects to.

Attack paths

Severity ranks findings against each other. It cannot tell you that these four combine into a route from the internet to a private bucket. Path analysis can.

An example attack path The public internet reaches an EC2 instance through an open security group; that instance assumes a role which can read a private S3 bucket. your account Internet 0.0.0.0/0 Security group port 22 open EC2 instance assumes role S3 bucket private, readable via role Four findings. Individually routine. Together, a route in.

The first link in that chain is a real check: security groups should not allow ingress from 0.0.0.0/0 to port 22.

What a role can actually reach

Reading a policy tells you what it says. GuardKite resolves what it reaches, once inheritance and wildcards are applied: every bucket, key and database the principal can touch.

What one principal can actually reach A single role, through one wildcard policy, reaches three services it was never intended to touch. reachable from that role deploy-role used by CI Action: * Resource: * One wildcard policy. Three services it was never meant to touch. S3: 41 buckets KMS: 12 keys RDS: 6 instances

The policy in that diagram is a real check: IAM policies should not allow full administrative privileges.

Seen enough? The rest of this page is detail. We would rather run it against one of your accounts.

Book a demo

Know what it checks

Every check includes a clear explanation of what it looks for, why it matters, and how to fix it. You can even review our complete library of checks before connecting an account.

The practical questions

Read-only
A cross-account role you create and control. GuardKite never stores credentials.
No agents
Nothing is installed in your environment. Configuration is read through the AWS APIs.
Findings in minutes
Scanning starts when you connect an account. Results populate as they are evaluated.
Every account you run
Connect as many as you have. See them together, or narrow to one while investigating.
Predictable AWS costs
GuardKite reads configuration through the AWS APIs. It does not require AWS Config or Security Hub, so nothing bills against your account as your infrastructure changes.
Access for the team
Give teammates and auditors read-only sight of findings without write access.

What teams say after connecting an account

Adding my AWS account to GuardKite was a no-brainer. The insights were presented intuitively, and I could follow the remediation guides easily.

ZameerFounder, ThinkPost.io

GuardKite helped us quickly improve the security posture of our AWS account. It identified risky configurations and gave us clear, actionable guidance to fix them.

Jude AshanSite Reliability Engineer

Using GuardKite gave us instant visibility into the security risks across our AWS environment. The findings were clear and actionable, which made it easy for our team to prioritize.

ShakeebCo-Founder, RapidLoad AI

See what changed in your own accounts

We connect one of your accounts with a read-only role and walk you through what it finds.