What Your Free AWS Scan Actually Shows You
CloudWizard inspects your AWS configuration through a read-only IAM role and surfaces the issues that matter most — ranked by severity, grouped by service, and explained in plain English.
IAM & Access Risk
Who has access to what — and whether those permissions are appropriate.
Over-permissive IAM roles and policies
Unused credentials and access keys
Missing MFA on privileged accounts
Cross-account trust relationships
Root account usage detection
Public Exposure
Resources that are accessible from the internet — intentionally or not.
Publicly accessible S3 buckets
Open security group rules (0.0.0.0/0)
Exposed RDS, EC2, and load balancers
Unintended public snapshots
API Gateway exposure checks
Encryption Gaps
Where your data is stored or transmitted without encryption.
Unencrypted EBS volumes and snapshots
RDS instances without encryption at rest
S3 buckets missing default encryption
Unencrypted SQS queues and SNS topics
CloudTrail logs without encryption
Compliance Posture
How your configuration maps against common security frameworks.
CIS AWS Foundations Benchmark
SOC 2 relevant controls
ISO 27001 alignment
HIPAA relevant checks
Pass/fail summary per framework
Logging & Monitoring
Whether your environment is actually being watched.
CloudTrail enabled and configured
CloudWatch alarms and log groups
GuardDuty and Security Hub status
Config rules enabled
VPC Flow Logs coverage
Configuration Issues
Common misconfigurations that create risk as environments grow.
Default VPC usage in production
Missing resource tagging
EC2 instances with public IPs
Overly permissive bucket policies
Outdated AMIs and patch gaps
Read-Only IAM
We only read config metadata. We cannot modify anything.
No Agents
Nothing deployed into your environment. Ever.
No Payload Data
We never access your app data, DB contents or S3 objects.
Revoke Anytime
Delete the IAM role and access is gone instantly.
No Credit Card
No payment details required. Start scanning immediately.

