Assess, fix, keep it that way

EdgeReadyEdgeResolveEdgeAssure

For investors

EdgeSignalAll services
How it works Find your path Case studies Security About What we take on Book a 20-minute triage call
Compliance readiness

The engineering gaps behind a SOC 2 readiness programme, closed.

A B2B SaaS company preparing for enterprise customers had a compliance programme underway and an AWS estate that was not going to hold up under it. InfraEdge fixed the engineering. A SOC 2 report is issued by an independent auditor — we are not that auditor and do not claim to make anyone certified.

← Some of our past work · anonymised prior delivery, no client named

Stack

IAMAWS CloudTrailAWS ConfigAWS KMSAWS BackupAmazon S3IAM Identity Center

Rough timeline

PhaseTypical duration
Control gap review against the estate1 week
Remediation3–5 weeks
Evidence pack assembled for the auditor1 week
The challenge

The audit had a date. The estate did not have a consistent policy.

Encryption, backups and access reviews existed in some places and not others — which is worse than not existing anywhere, because it makes every claim conditional on which resource someone happens to check.

A control mapping speaks a different language to a console

"Access is reviewed periodically" is not evidenced by a screenshot; each item on the readiness assessment needed translating into a specific, provable change.

The team owned the risk, not the vocabulary

The engineers understood their systems well. What was missing was the time to turn IAM and logging into something an auditor’s control mapping recognises.

Guessing was worse than a gap

An optimistic answer that failed later would have cost more than an honest "not yet, and here is the date it will be fixed by."

What we found

Broad IAM, thin logging, and encryption that depended on when a resource was created.

None of this was one big mistake. It was a set of ordinary decisions made early, at speed, that had never been revisited.

Wildcard actions on deploy roles

Broad trust and permission policies granted for convenience early on, never narrowed as the team and the estate grew.

CloudTrail was single-region, short retention

Enough for day-to-day debugging. Not enough to answer "show us account activity for the last twelve months."

Encryption was inconsistent

Some S3 buckets and RDS instances used KMS by default; others predated the account’s default encryption settings and had never been rotated onto it.

Public exposure existed by omission

S3 Block Public Access was not enabled account-wide, and a handful of security group rules had no author anyone could name.

What InfraEdge changed

IAM hardened, logging extended, encryption made consistent, exposure removed.

Each row below closes a specific control gap. None of it makes a compliance claim on its own — it is the evidence behind one.

ChangeWhat it did
IAM hardenedWildcard actions removed from deploy and application roles, trust policies scoped to the principals that need them, MFA required for human access via IAM Identity Center.
Logging improvedAn organization CloudTrail trail, multi-region, with a retention period long enough to answer a year-back question.
Encryption made consistentKMS encryption applied across S3 and RDS, including the resources created before the account’s defaults existed.
Backup policy implementedAWS Backup vaults and plans covering every workload the control mapping named, with retention set deliberately rather than left at the service default.
Public exposure removedS3 Block Public Access enabled account-wide, security groups reviewed rule by rule, unexplained rules removed rather than documented and kept.
Access reviews and evidenceA recurring access review process, plus the configuration exports, screenshots and policy documents a control mapping actually asks for.
Outcome

The engineering gaps behind the findings, resolved — not just documented.

What the auditor sees now is a set of implemented controls with evidence behind each one, rather than a set of intentions written down after the fact.

InfraEdge closed the engineering gaps a control mapping was going to flag, and produced the technical evidence behind each one. The report and any certification are the auditor’s to issue, not ours to promise. What the team kept is a security posture that survives the next audit cycle without the same scramble, and an evidence chain that shows exactly how each control was verified.

Evidence
RDS configuration collected read-onlys3://…/rds_instances.json · sha256 9f2c1a… · 09:14 UTC
Finding
Production database publicly reachable, no tested restoreRDS-007 · High
Remediation
Moved to private subnets, automated backups on, restore drilledPR #142 · 6 files · plan hash b71e04… · restore 41 min
Approval
A named principal approved that exact planapproved 2026-07-12 14:02 · commit 3f9ac21

Book a 20-minute triage call

Twenty minutes, no charge. We work out what would actually help — which is sometimes us and sometimes not. Nothing is priced on the call; if there is work worth doing, a written scope and a price reach you within 24 hours.