Assess, fix, keep it that way

EdgeReadyEdgeResolveEdgeAssure

For investors

EdgeSignalAll services
How it works Find your path Case studies Security About What we take on Book a 20-minute triage call
EdgeReady · readiness assessment

Where your estate actually stands.

Not how it is drawn in the architecture diagram — how it is configured on a Tuesday afternoon. A read-only role, a fixed window, and an assessment scored across security, reliability, operations, cost, performance and governance. You get the material risks in priority order, each one citing evidence you can open yourself, and an explicit list of what we could not check and why.

Start with visibility and readiness

Continuous improvement and confidence

What changes for you

You stop guessing

The difference between "I think our IAM is probably fine" and knowing, with the evidence attached, is the entire product. Most teams are wrong in both directions — relaxed about something that matters, anxious about something that does not.

A prioritised list, not a catalogue

A scanner returns four hundred findings sorted by its own severity rubric. This returns the ones that matter to your business, in the order a senior engineer would actually fix them, with the reasoning written down.

Risk in business language

Every material finding says what it means for you, not just which control it violates. What breaks, who is affected, what it would take to fix, and what happens if you leave it another two quarters.

Something you can forward

The output is written to survive being sent to a board, an insurer or a customer's security team without translation. It is also written so your own engineers can act on it without us.

What you are left holding

Everything below lands in your repository and your accounts. If you stop working with us, none of it stops working.

  • The written assessment, scored per pillar, with every material finding traced to the evidence behind it.
  • The raw evidence set — configuration exports, hashes and timestamps — so any claim can be independently checked.
  • A prioritised remediation backlog, sized by effort and ordered by what actually reduces risk first.
  • An explicit completeness statement: which domains were fully assessed, which were partial, and exactly what a missing permission stopped us seeing.
  • A short architecture map of what is actually running, which for many teams is the first accurate one they have had.

What is included

  • Read-only access, scoped to what you name: an AWS IAM role assumed with temporary credentials, or the equivalent in Azure (a scoped app registration or managed identity over your subscriptions) and GCP (a scoped service account over your projects).
  • Assessment across security, reliability, operations, cost, performance and governance.
  • Identity and access: root usage, IAM Identity Center, long-lived keys, permission boundaries.
  • Resilience: backup configuration, whether a restore has ever been performed, single points of failure.
  • Infrastructure as code coverage, and drift between the code and the live estate.
  • Deployment path: how a change reaches production and who can approve it.
  • Cloud economics: structural inefficiency, not a line-by-line bill review.
  • A findings workshop with your engineers, and a written scope for anything you want fixed.

What is not

  • Penetration testing or application security testing. We assess infrastructure configuration, not your code.
  • Any change to your estate. EdgeReady is read-only from start to finish.
  • A statement that you are compliant with anything, in Compliance mode or otherwise.
  • A scanner report with our logo on it. If a tool found it, we say which tool and we check it before it goes in.

The exclusions are the same size as the inclusions on purpose.

Two modes, one assessment

Same read-only role, same collectors, same evidence set. What changes is the question the findings are ordered against — so running both costs one access grant and one window, not two.

Production

Will it hold under load, and can you get it back?

Load paths and their limits, resilience to a component failing, and recovery: whether a restore has ever actually been performed, how long it took, and what was lost. The mode most teams start in.

Compliance

Which controls does the infrastructure currently fail?

The same estate read against the SOC 2 and ISO 27001 controls that are satisfied by infrastructure — access, logging, retention, encryption, change control — naming the ones it does not currently meet and what closing each would take. A SOC 2 report is issued by an independent auditor, and ISO 27001 certification by an accredited body; this is the engineering work in front of either.

How the assessment is built

Six pillars, assessed against production practice, scored, then ordered by what a senior engineer would fix first rather than by a tool's default severity.

SIX PILLARS · ONE SCORE · RANKED ACTIONS Security IDENTITY NETWORK Reliability BACKUP RESTORE Operations RUNBOOKS ON-CALL £ Cost SPEND VISIBILITY Performance CAPACITY LATENCY Governance OWNERSHIP POLICY Scoring engine WEIGHTED ACROSS ALL SIX PILLARS Prioritised recommendations RANKED BY IMPACT, WITH BUSINESS CONTEXT

What the output looks like

Specimen — illustrative, not a customer's data

The company, the scores and every finding here are invented for illustration. A real EdgeReady assessment scores your own environment, evidence and all.

70out of 100

Pillar

Security 61
Reliability 78
Operations 70
Cost 66
Performance 74
Governance 69

Top risks, by severity

High
4need action before the next customer review
Needs attention
9worth scheduling, not urgent
Clear
19already at production practice
See the deliverable first

Read a real EdgeReady report

The complete deliverable, unabridged: maturity across six pillars, fourteen worked findings with the evidence behind each, a cost baseline and a 30/60/90 plan. The subject company is invented; the structure and the rigour are exactly what you would receive.

Name and work email, then it lands in your inbox. Two fields, and we do not run a nurture sequence off them.

Where this has been done before

All eleven anonymised engagements

Questions this answers

Will you change anything in our estate?

No. EdgeReady is read-only from start to finish. The access you grant reads configuration metadata in the accounts you name; no step in the assessment writes.

Is this only for AWS?

No. AWS is the deepest specialism, which is why the questionnaire on this site is AWS-specific. The assessment is not — the same six pillars are assessed in Azure and GCP.

Does this make us SOC 2 or ISO 27001 compliant?

No. Compliance mode names the controls your infrastructure currently fails and what closing each would take — the engineering work in front of an audit. The SOC 2 report comes from an independent auditor, ISO 27001 certification from an accredited body.

Is it a scanner report with your logo on it?

No. Where a tool found something we name it and check the finding first. The ordering is what a senior engineer would fix first, not a product’s severity rubric.

What happens to the parts you cannot see?

They are written down, in an explicit completeness statement: which domains were fully assessed, which were partial, and what a missing permission stopped us seeing.

Do we pay for the assessment twice if we then hire you?

No. The EdgeReady fee comes off whatever you book with us within 30 days.

Is EdgeReady the right shape?

Twenty minutes on a call will tell you, and will tell us. If a different product fits better — or what you need is not on this list at all — say so. Nothing is priced on the call; a written scope follows within 24 hours.

Where should we send it?

Two fields. We send the document, and that is the end of it unless you write back.