A control mapping speaks a different language to a console
"Access is reviewed periodically" is not evidenced by a screenshot; each item on the readiness assessment needed translating into a specific, provable change.
A B2B SaaS company preparing for enterprise customers had a compliance programme underway and an AWS estate that was not going to hold up under it. InfraEdge fixed the engineering. A SOC 2 report is issued by an independent auditor — we are not that auditor and do not claim to make anyone certified.
← Some of our past work · anonymised prior delivery, no client named
Stack
Rough timeline
| Phase | Typical duration |
|---|---|
| Control gap review against the estate | 1 week |
| Remediation | 3–5 weeks |
| Evidence pack assembled for the auditor | 1 week |
Encryption, backups and access reviews existed in some places and not others — which is worse than not existing anywhere, because it makes every claim conditional on which resource someone happens to check.
"Access is reviewed periodically" is not evidenced by a screenshot; each item on the readiness assessment needed translating into a specific, provable change.
The engineers understood their systems well. What was missing was the time to turn IAM and logging into something an auditor’s control mapping recognises.
An optimistic answer that failed later would have cost more than an honest "not yet, and here is the date it will be fixed by."
None of this was one big mistake. It was a set of ordinary decisions made early, at speed, that had never been revisited.
Broad trust and permission policies granted for convenience early on, never narrowed as the team and the estate grew.
Enough for day-to-day debugging. Not enough to answer "show us account activity for the last twelve months."
Some S3 buckets and RDS instances used KMS by default; others predated the account’s default encryption settings and had never been rotated onto it.
S3 Block Public Access was not enabled account-wide, and a handful of security group rules had no author anyone could name.
Each row below closes a specific control gap. None of it makes a compliance claim on its own — it is the evidence behind one.
| Change | What it did |
|---|---|
| IAM hardened | Wildcard actions removed from deploy and application roles, trust policies scoped to the principals that need them, MFA required for human access via IAM Identity Center. |
| Logging improved | An organization CloudTrail trail, multi-region, with a retention period long enough to answer a year-back question. |
| Encryption made consistent | KMS encryption applied across S3 and RDS, including the resources created before the account’s defaults existed. |
| Backup policy implemented | AWS Backup vaults and plans covering every workload the control mapping named, with retention set deliberately rather than left at the service default. |
| Public exposure removed | S3 Block Public Access enabled account-wide, security groups reviewed rule by rule, unexplained rules removed rather than documented and kept. |
| Access reviews and evidence | A recurring access review process, plus the configuration exports, screenshots and policy documents a control mapping actually asks for. |
What the auditor sees now is a set of implemented controls with evidence behind each one, rather than a set of intentions written down after the fact.
InfraEdge closed the engineering gaps a control mapping was going to flag, and produced the technical evidence behind each one. The report and any certification are the auditor’s to issue, not ours to promise. What the team kept is a security posture that survives the next audit cycle without the same scramble, and an evidence chain that shows exactly how each control was verified.
Twenty minutes, no charge. We work out what would actually help — which is sometimes us and sometimes not. Nothing is priced on the call; if there is work worth doing, a written scope and a price reach you within 24 hours.