Closed 12 audit findings before pen-test.
Health-tech client needed to ship the audit. We instrumented CloudTrail, tightened S3, and resolved every critical inside two sprints.
What we walked into.
A pre-pen-test review surfaced 12 critical findings: public S3 buckets, missing CloudTrail in two regions, IAM users with console access bypassing SSO, and KMS keys without rotation. Pen-test was four weeks out.
Engineering team of six had no security engineer. They had been quietly punting on these for six months because they did not know where to start.
How we shipped it.
Triage by blast radius
Ranked all 12 findings by what a determined attacker could do, not by report severity. Two findings (S3 misconfig, console-access bypass) jumped to the top. Started there.
S3 hardening as the foundation
Enforced TLS-only bucket policies, enabled S3 Public Access Block at the account level, and turned on default encryption. Caught and remediated two buckets that had been public for over a year.
Region-complete logging
Multi-region CloudTrail with a single S3 destination, log file integrity validation on, and CloudTrail logs sent to a separate logging account isolated from engineering. Same for GuardDuty.
SSO-only access, IAM users gone
Removed every IAM user with console access. Federated all human access through the existing SSO provider. Service accounts now use IAM Roles Anywhere where third parties needed access.
AWS services in this engagement
What shipped.
Pen-test came back clean on all 12 originally-flagged areas. Two new lower-severity findings surfaced, both closed within the same sprint as the report.
The client now has a quarterly check-in playbook from the engagement. They have run it twice on their own since.
A companion that remembers.
Merkx is a live AI companion built so that memory is the product and conversation is only the surface. Claude sits at the memory, response, critique, and personality layers that make it feel like a presence.
AIFrom schema to running backend.
Auxen turns a database schema into deployable, production-shaped code across eleven frameworks. Claude drafts the schema, holds the architecture across dozens of files, and explains every decision it makes.
SecurityHardened 47 IAM roles in 11 days.
Series B fintech needed audit-ready IAM before SOC 2. We refactored every role into least-privilege Terraform modules.
Tell us what you're trying to ship.
A 30-minute scoping call with the engineers who would do the work.