Know what your AWS setup is exposing
We review your AWS account for access, exposure, and configuration gaps, then hand you one ranked list of what to fix first.
Every finding is ranked critical, moderate, or low, in plain language. Flat rate, no retainer.
Why this matters
Most small businesses set up their cloud once, get it working, and never look at it again. Defaults stay permissive, old accounts keep their keys, and the person who configured it has often moved on. Nothing looks wrong from the outside, which is exactly the problem.
You do not need a security team to fix this. You need someone to look once, tell you what is actually exposed, and rank it so you can work through it in an afternoon.
Not on AWS? We still review your site, hosting, forms, and who holds the logins. Tell us what you run and we will tell you whether an audit is worth your money.
What we check
S3
Public access, encryption, versioning.
IAM
Permission scope, stale accounts, MFA.
Databases
Exposure, backups, encryption.
EC2 and security groups
Open ports, permissive rules.
Logging
CloudTrail and monitoring coverage.
Front-end
HTTPS, form handling, exposed keys.
Access
Who holds your AWS, hosting, and domain logins.
Pricing
One flat price, agreed in writing before anything starts. No hourly billing, no retainer, and no invoice that grew after the fact. If what we find once we have access is bigger than what you described, we tell you and agree a new number with you first.
The tier depends on how much there is to look at, not on how many problems we find. Every engagement covers all seven areas above and ends with the same thing: one written report, findings ranked critical, moderate, or low, each with plain-language impact and what to do about it.
$500 · Starter
One site or one cloud account with few services. Roughly a day of review.
$1,200 · Standard
Site, hosting, and the integrations or forms attached to them. Most small businesses land here.
$2,000 · Complex
Multiple services, several accounts, or infrastructure nobody currently owns.
$400 · Re-audit
After you have worked through the report, we check the fixes landed. Existing clients only.
Not sure which fits? Tell us what you run and we will tell you, before you commit to anything.
Questions
About
I am an engineer in Tampa, Florida. I spent two and a half years as a systems architect and I am currently pursuing a master’s in cybersecurity at Georgia Tech.
I started Kestrel Systems because small businesses run real infrastructure without anyone whose job it is to check it. The tooling to find these problems is not exotic. Mostly nobody has been asked to look.
Contact
Tell us what you run and we will scope it.
ryan.cuff@icloud.com