Skip to content
Vaptiq logo mark — V orientationVAPTIQ
All services

[ Infrastructure ]

Cloud Penetration Testing

AWS, Azure and GCP, IAM paths, workload escape and the blast radius of one key.
Typical duration
5-10 days
Starting price
Scoped
You provide
Read-only audit role, plus a low-privilege identity

[ 01 / The engagement ]

Cloud breaches are identity breaches. The interesting question is not whether a bucket is public, it is what a single leaked access key can reach once it is used, which roles it can assume, which functions it can invoke, and how far that chain runs before something stops it. We test configuration and identity together, because separately neither one tells you the blast radius.

[ 02 / Coverage ]

What we test, in practice.

This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.

Methodology

CIS BenchmarksMITRE ATT&CK CloudCloud provider test policies
  1. 01IAM privilege escalation and role assumption chains
  2. 02Storage, database and snapshot exposure across accounts
  3. 03Serverless function permissions and event-source abuse
  4. 04Container and Kubernetes escape, RBAC and admission control
  5. 05Metadata service access and SSRF-to-credential paths
  6. 06Cross-account trust, organisation and landing-zone boundaries
  7. 07Secrets management, key policy and logging coverage

[ 03 / What you get ]

Four things land at the end of every engagement.

Technical report

Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.

Executive summary

Two pages your board can read. Risk in business terms, with the three things that matter most called out.

Letter of attestation

A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.

Free retest

Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.

[ 04 / Questions ]

Before you commit.

For the vast majority of scopes, no, the major providers permit customer-initiated testing of your own resources. We confirm the current policy in writing during scoping and stay inside it.

No. A posture tool lists misconfigurations. We chain them, so you learn which combination actually reaches your data and which ones are noise.

Scope a cloud penetration testing.

Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.