Security by default

Tudovu Security Garrison

Spend less engineering time chasing AWS findings. Build hardened infrastructure or convert what you already run, with remediation proposed in your own repository. Your engineers review and approve what ships.

$500/mo $6,000/year equivalent

We agree on access and scope with you before any scan.

From trigger to approved change

Agents draft. Your team decides.

  1. Trigger

    A new finding, infrastructure drift, or a request from your team starts the work.

  2. Tudovu investigates and drafts a PR

    Agents examine the context and propose a change in your repository. The pull request explains the work for review.

  3. Your team reviews and merges

    Your engineers decide whether to approve, request changes, or decline. A proposed fix does not authorize deployment.

  4. Deploy and prepare the record

    The approved merge proceeds through your deployment workflow and its gates. Evidence is recorded when checks run. Start checks manually in the app; scheduled checks require scheduling to be enabled for your environment. A merge alone does not trigger a re-check. Documentation updates are proposed for your approval; your team approves publication of evidence and documentation.

Your team retains deployment, policy, and publication decisions. Documentation is proposed for approval before it is published.

Build, check, and remediate AWS security findings.

Harden and ship

  • Hardened IaC for new builds and existing infrastructure
  • Reclaimer conversion and migration proposals
  • Security-gated CI/CD with IaC validation
  • Changes reviewed and merged in your own repository

Detect and investigate

  • AWS Security Hub integration and CIS AWS infrastructure benchmark checks
  • Findings from AWS GuardDuty and AWS Trusted Advisor
  • SAST and DAST mapped to OWASP Top 10
  • Dependency CVEs through AWS Inspector
  • Drift detection, remediation PRs, and cost optimization proposals

Keep your team informed

  • Snippy posture briefings in Slack Private preview
  • PRs waiting on your engineers
  • Decisions that need a person
  • Documentation updates proposed for approval

Selectable coverage views map checks to CIS AWS Foundations (40 of the 171 bundled checks), NIST 800-53 rev 5 (68), and ISO 27001:2022 (153). Mappings show technical coverage, not a complete compliance program, consulting engagement, or certification. CIS AWS infrastructure benchmark checks assess AWS configurations. They are distinct from a full CIS framework program. Partner-delivered penetration testing and pen test reports are on the roadmap. Cost savings depend on your environment and are not guaranteed.

Reports and documentation

The record behind your security posture.

Generated from your infrastructure and proposed for review as it changes. Your team approves policy and documentation updates.

For your team

Findings report
Exportable open and closed findings, with severity, age, and owner.
Reclaim Score
The percentage of resources under IaC management, tracked over time.
Remediation log
The merged PR for each fix: what changed, when, and who approved it.

For prospects and customers

Security policies
Access control, encryption, and incident response policies drafted from your environment.
Architecture and data-flow documentation
Documentation of your infrastructure and how data moves through it.
Security posture summary
Findings and remediation posture for customer security reviews, alongside approved documentation in your Living Trust Center.

Pen test reports remain on the roadmap.

Add the SOC 2 audit layer.

Compliance Corps includes all of Garrison plus activated SOC 2 checks, founder-led consulting, the full SOC 2 policy set, and control-mapped evidence for audit preparation.