Assess, fix, keep it that way

EdgeReadyEdgeResolveEdgeAssure

For investors

EdgeSignalAll services
How it works Find your path Case studies Security About What we take on Book a 20-minute triage call
EdgeAssure · continuous assurance

Keep the estate from quietly going back to how it was.

Every remediation programme has the same ending if nothing follows it. Six months later a security group has been widened for a demo, an engineer has left with the only knowledge of a manual step, and three resources exist that are in no repository. EdgeAssure is scheduled checks against the things that actually degrade, tracked over time, reviewed by an engineer rather than a dashboard that emails you.

Start with visibility and readiness

Continuous improvement and confidence

What changes for you

Drift becomes visible early

The gap between what your Terraform says and what AWS is actually running is measured on a schedule, not discovered during an incident or an audit.

Problems arrive with an owner

A finding with no owner is a finding nobody fixes. Each one lands with a named person and a recommended action, not a severity score and a hope.

A trend, not a snapshot

A one-off audit tells you where you were on a Tuesday. Assurance tells you whether you are getting better or worse — the only version of the question that informs a decision.

Capacity when you need it

A named amount of senior engineering time each month, so small things get fixed as they appear instead of accumulating into the next remediation programme.

What you are left holding

Everything below lands in your repository and your accounts. If you stop working with us, none of it stops working.

  • A regularly updated view of security posture, IaC coverage, drift, backup state, access and cost.
  • The check definitions themselves, in your repository, so you can see exactly what is being asserted and change it.
  • A monthly written review from an engineer — including the months where nothing happened, which is the point.
  • A running record of what changed, what was fixed and what was consciously accepted.

What is included

  • Scheduled checks across security, resilience, IaC coverage, access, backup and cost — the interval is agreed with you and stated in the scope.
  • Drift detection between Terraform state and the live AWS environment.
  • A named amount of senior engineering capacity each month, expressed in days rather than adjectives.
  • A monthly written review, and a call if there is something worth talking about.
  • Response within one business day, UK working hours.
  • Small remediation work absorbed inside the monthly capacity.

What is not

  • On-call, out-of-hours response or production incident cover. We are explicit about this because the alternative is a promise nobody can keep.
  • Unlimited engineering. Capacity is capped and stated, and we tell you when a piece of work exceeds it before starting.
  • A compliance certification, or continuous monitoring sold as one.
  • Silent auto-remediation. Nothing changes your estate without a person approving it, including for us.

The exclusions are the same size as the inclusions on purpose.

What is checked, and how it trends

Specimen — illustrative, not a customer's data

The checks and trends below are illustrative. EdgeAssure evaluates your own estate continuously; this specimen exists to show the shape of the output.

CheckStatusTrend
MFA on root Pass steady
S3 public access High worsening
Security groups Attention steady
Backup completion Pass improving
Logging coverage Pass improving
IAM key rotation Attention worsening

Risk over time

Shaded weeks are illustrative — where an aggregate score like this would cross the threshold that opens a High finding.

Drift is the thing that gets you

Not a dramatic breach. A security group widened for an afternoon and never narrowed, a resource created by hand during an incident, a manual step nobody wrote down. Individually trivial, collectively how a good estate becomes a bad one.

DRIFT DETECTION Terraform state YOUR REPOSITORY, LAST APPLY Live AWS environment WHAT IS ACTUALLY RUNNING Unauthorised change MADE OUTSIDE THE PIPELINE Manual console edit A FAST FIX THAT SKIPPED REVIEW Out-of-band resource CREATED BY ANOTHER TOOL OR TEAM
Drift detected

Caught the next time EdgeAssure checks the estate — not at the next audit, not when a customer asks.

Where this has been done before

All eleven anonymised engagements

Questions this answers

Is this an on-call or incident response service?

No. There is no pager and no out-of-hours cover — buying cover from a firm without a rota is worse than having none. Response is within one business day, UK working hours.

Will anything be changed automatically?

No. There is no silent auto-remediation. Nothing changes your estate without a person approving it, and that includes us.

What do we actually receive each month?

A written review from an engineer rather than a dashboard that emails you — including the months where nothing happened, which is rather the point — plus a named amount of senior engineering capacity, in days.

Where do the checks themselves live?

In your repository. You can read exactly what is being asserted and change it, so assurance is not a black box you rent.

Is the engineering time unlimited?

No. Capacity is capped and stated up front, small work is absorbed inside it, and we tell you when a piece exceeds it before starting.

How long are we tied in?

Three months minimum, then a month’s notice to stop. Long enough for a trend to mean something, short enough that it has to keep earning its place.

Is EdgeAssure the right shape?

Twenty minutes on a call will tell you, and will tell us. If a different product fits better — or what you need is not on this list at all — say so. Nothing is priced on the call; a written scope follows within 24 hours.