Skip to content

Who and what can reach your production cloud, and would you notice?

With read-only access to your AWS, Azure or Google Cloud accounts, we work out who and what can reach production.

Request a scoping call

Free 30-minute scoping call.

A typical SaaS product. The cloud account runs your product and keeps your data and your customers’.

One leaked key that can read your production data

A fictional example of what can go wrong here.

  1. A key leaks

    A developer’s access key ends up in a public repository or on a lost laptop.

  2. It can do too much

    It was made for one quick task, but it can read every storage bucket.

  3. Backups are in reach

    Your database backups sit in storage the key can open.

  4. Nobody notices

    Nothing logs or alerts on access to that storage.

So we ask: Could one leaked key read your data and your customers’, and would you know?

For your engineer

iam/report-uploader-policy.json

{
  "Effect": "Allow",
  "Action": "s3:*",
  "Resource": "*"
}

Read a fictional cloud design example

What we check

The questions we start from. We agree the final list with you on the scoping call.

  • What can each person, role and service actually do?
  • Which storage, databases and services can be reached from the internet?
  • Where do your keys live, who can use them and how often do they change?
  • If something went wrong, would the records you need exist?

Best done when your cloud has grown quickly, before a launch, or when nobody’s sure who can reach what.

What you get, and what it costs

Fixed fee for the agreed scope, quoted before work starts.

We quote it after the scoping call, once we know what’s in. If the scope grows later, we price the extra before we start it.

Included

  • The assessment of the systems we agree
  • A findings report with the evidence for each issue
  • What to fix first, and how to check each fix
  • A walkthrough call with your engineers
  • One round of retesting after your fixes
  • A list of permissions nobody seems to use, ready to remove

Not included: Making the fixes (your engineers do that), a compliance certificate and anything outside the agreed scope. Quoted separately: Further retests after the first and extra scope added once work has started.

See what a report looks like

Before you enquire

What people ask us most. Wondering whether a pentest would do? Is a VAPT enough?

What do you need from us?

Read-only access to the accounts or projects in scope, or exported configuration. Infrastructure code helps if you have it.

Where do you stop?

We cover the accounts or projects you name. Pipelines and developer access are a separate assessment.

Is this a penetration test?

No. We read how your accounts are set up, usually with read-only access. If you want us to test hands-on as well, we’ll put that in the scope.

Is retesting included?

Yes, one round. Once your team has made the fixes, we retest them. Each finding also comes with a check your team can run themselves.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Start with the account that holds your data

Which cloud providers do you use, and how many accounts or projects?

Request a scoping call

Include your country code. We only use it to follow up on your enquiry.

Please leave out passwords and customer data.

We only use your details to reply to your enquiry. How we handle enquiry information.

Or email contact@unmesha.io directly.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team