Konfirmity
Layer 1 of 7 — Cloud Infrastructure

// cloud infrastructure

Every cloud asset, judged against its own configuration

L1 does not ask whether you have a cloud security policy. It counts the assets in your accounts that are currently misconfigured, and hands you the list.

// what it watches

What this layer watches

Cloud Infrastructure reports “Set Up” until the right integration is connected, because until then there is nothing honest to say about it. A platform that showed you green here would be describing an environment it cannot see.

  • Identity and access configuration across every connected cloud account, which is also what L4 Access & Identity
  • Network exposure: what is reachable, from where, and whether it should be
  • Encryption at rest and in transit, including keys and their rotation
  • Data-loss prevention controls and where they are absent
  • Backup and recovery configuration, tested against your stated objectives

// what turns it red

What turns it red

Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.

What is measuredWhat it saysWhere clicking it takes you
Identity and access: over-permissive IAM policies, roles, key age and rotation, root account useN Assets Need FixingThe cloud asset inventory, filtered to exactly those non-compliant assets
Network exposure: security groups, firewalls, gateways, load balancers and what they leave reachableN Assets Need FixingThe same inventory, with the offending resource named
Encryption: volumes, buckets, databases, secrets and key management configurationN Assets Need FixingThe asset record, showing its encryption state
Logging and monitoring: audit trails, log retention, alarms and threat-detection services left offN Assets Need FixingThe asset record and the control it fails
Backup and recovery configuration, assessed against your stated objectivesN Assets Need FixingThe asset record and its recovery configuration
Whether any cloud account is connected at allSet UpThe integrations directory, pre-filtered to cloud providers

This table is not the whole check

Over 90 distinct resource types are classified and assessed across AWS, Azure and GCP — compute, storage, databases, networking, identity, secrets, containers, serverless and the rest. The rows above are the shape of the check, not its inventory.

See how deep we go

// getting to green

What it takes to go green

  1. Connect one or more cloud accounts. Read-only access is enough to begin.
  2. The scanner enumerates your assets and evaluates each against its expected configuration.
  3. Each finding becomes a remediation task with an owner and an SLA, not a line on a report.
  4. The layer turns green when no cloud asset carries an open finding. It turns red again the moment one does.

// the evidence

The evidence this produces

None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.

  • Configuration evidence for infrastructure controls across every framework you run — see the framework guides
  • A dated record of what was broken, who fixed it, and when
  • Asset inventory that auditors accept because it is generated, not typed

// questions this answers

Cloud coverage, answered directly

What does Konfirmity check in AWS, Azure and GCP?

Konfirmity evaluates identity and access configuration, network exposure, encryption at rest and in transit, data-loss prevention, and backup and recovery configuration across every connected cloud account. Each asset is judged against its expected configuration, and any asset that fails becomes a counted finding rather than a line in a report.

Does connecting a cloud account require write access?

No. Read-only access is enough to begin. The scanner enumerates your assets and evaluates their configuration; remediation happens in your own environment, driven by tasks the platform raises.

What does the “Set Up” state on L1 mean?

It means no AWS, Azure or GCP account is connected yet, so the layer has nothing honest to report. Konfirmity shows Set Up rather than green, because a green layer would be describing an environment the platform cannot see.

Want to see this one live?

Book 30 minutes and we will walk through “Every cloud asset, judged against its own configuration” in the actual platform, using your environment as the example.

Book a demo