// cloud infrastructure
Every cloud asset, judged against its own configuration
L1 does not ask whether you have a cloud security policy. It counts the assets in your accounts that are currently misconfigured, and hands you the list.
// what it watches
What this layer watches
Cloud Infrastructure reports “Set Up” until the right integration is connected, because until then there is nothing honest to say about it. A platform that showed you green here would be describing an environment it cannot see.
- Identity and access configuration across every connected cloud account, which is also what L4 Access & Identity
- Network exposure: what is reachable, from where, and whether it should be
- Encryption at rest and in transit, including keys and their rotation
- Data-loss prevention controls and where they are absent
- Backup and recovery configuration, tested against your stated objectives
// what turns it red
What turns it red
Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.
| What is measured | What it says | Where clicking it takes you |
|---|---|---|
| Identity and access: over-permissive IAM policies, roles, key age and rotation, root account use | N Assets Need Fixing | The cloud asset inventory, filtered to exactly those non-compliant assets |
| Network exposure: security groups, firewalls, gateways, load balancers and what they leave reachable | N Assets Need Fixing | The same inventory, with the offending resource named |
| Encryption: volumes, buckets, databases, secrets and key management configuration | N Assets Need Fixing | The asset record, showing its encryption state |
| Logging and monitoring: audit trails, log retention, alarms and threat-detection services left off | N Assets Need Fixing | The asset record and the control it fails |
| Backup and recovery configuration, assessed against your stated objectives | N Assets Need Fixing | The asset record and its recovery configuration |
| Whether any cloud account is connected at all | Set Up | The integrations directory, pre-filtered to cloud providers |
This table is not the whole check
Over 90 distinct resource types are classified and assessed across AWS, Azure and GCP — compute, storage, databases, networking, identity, secrets, containers, serverless and the rest. The rows above are the shape of the check, not its inventory.
// getting to green
What it takes to go green
- Connect one or more cloud accounts. Read-only access is enough to begin.
- The scanner enumerates your assets and evaluates each against its expected configuration.
- Each finding becomes a remediation task with an owner and an SLA, not a line on a report.
- The layer turns green when no cloud asset carries an open finding. It turns red again the moment one does.
// the evidence
The evidence this produces
None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.
- Configuration evidence for infrastructure controls across every framework you run — see the framework guides
- A dated record of what was broken, who fixed it, and when
- Asset inventory that auditors accept because it is generated, not typed
// questions this answers
Cloud coverage, answered directly
What does Konfirmity check in AWS, Azure and GCP?
Konfirmity evaluates identity and access configuration, network exposure, encryption at rest and in transit, data-loss prevention, and backup and recovery configuration across every connected cloud account. Each asset is judged against its expected configuration, and any asset that fails becomes a counted finding rather than a line in a report.
Does connecting a cloud account require write access?
No. Read-only access is enough to begin. The scanner enumerates your assets and evaluates their configuration; remediation happens in your own environment, driven by tasks the platform raises.
What does the “Set Up” state on L1 mean?
It means no AWS, Azure or GCP account is connected yet, so the layer has nothing honest to report. Konfirmity shows Set Up rather than green, because a green layer would be describing an environment the platform cannot see.
// keep reading
Where this goes deeper
Want to see this one live?
Book 30 minutes and we will walk through “Every cloud asset, judged against its own configuration” in the actual platform, using your environment as the example.