A teammate “temporarily” opens an S3 bucket during an incident and forgets to revert. Enforcer catches it on the next drift flow, records it as evidence, and proposes the fix — which ships only after you approve it.
Evaluates live AWS state against 92 ISO 27001-mapped policies across 32 resource adapters — IAM, S3, EC2, VPC, RDS, and more.
Every finding carries the exact resource, the violated policy, and the delta — timestamped and reproducible, ready for your auditor.
Enforcer proposes the fix. It runs only once the system is switched into fix mode and a person approves that specific change. The problem, the approval, and the fix are stored together.
Not built yet, honestly. ISO 27001 is the only framework mapped today; SOC 2 is a control mapping on the same engine, and it ships when design partners demand it.
Cluster-wide access rules, network isolation, and resource limits — checked inside your clusters and reported next to your AWS results.