Tudovu Security Garrison
Spend less engineering time chasing AWS findings. Build hardened infrastructure or convert what you already run, with remediation proposed in your own repository. Your engineers review and approve what ships.
$500/mo $6,000/year equivalent
We agree on access and scope with you before any scan.
Agents draft. Your team decides.
-
Trigger
A new finding, infrastructure drift, or a request from your team starts the work.
-
Tudovu investigates and drafts a PR
Agents examine the context and propose a change in your repository. The pull request explains the work for review.
-
Your team reviews and merges
Your engineers decide whether to approve, request changes, or decline. A proposed fix does not authorize deployment.
-
Deploy and prepare the record
The approved merge proceeds through your deployment workflow and its gates. Evidence is recorded when checks run. Start checks manually in the app; scheduled checks require scheduling to be enabled for your environment. A merge alone does not trigger a re-check. Documentation updates are proposed for your approval; your team approves publication of evidence and documentation.
Your team retains deployment, policy, and publication decisions. Documentation is proposed for approval before it is published.
Build, check, and remediate AWS security findings.
Harden and ship
- Hardened IaC for new builds and existing infrastructure
- Reclaimer conversion and migration proposals
- Security-gated CI/CD with IaC validation
- Changes reviewed and merged in your own repository
Detect and investigate
- AWS Security Hub integration and CIS AWS infrastructure benchmark checks
- Findings from AWS GuardDuty and AWS Trusted Advisor
- SAST and DAST mapped to OWASP Top 10
- Dependency CVEs through AWS Inspector
- Drift detection, remediation PRs, and cost optimization proposals
Keep your team informed
- Snippy posture briefings in Slack Private preview
- PRs waiting on your engineers
- Decisions that need a person
- Documentation updates proposed for approval
Selectable coverage views map checks to CIS AWS Foundations (40 of the 171 bundled checks), NIST 800-53 rev 5 (68), and ISO 27001:2022 (153). Mappings show technical coverage, not a complete compliance program, consulting engagement, or certification. CIS AWS infrastructure benchmark checks assess AWS configurations. They are distinct from a full CIS framework program. Partner-delivered penetration testing and pen test reports are on the roadmap. Cost savings depend on your environment and are not guaranteed.
The record behind your security posture.
Generated from your infrastructure and proposed for review as it changes. Your team approves policy and documentation updates.
For your team
- Findings report
- Exportable open and closed findings, with severity, age, and owner.
- Reclaim Score
- The percentage of resources under IaC management, tracked over time.
- Remediation log
- The merged PR for each fix: what changed, when, and who approved it.
For prospects and customers
- Security policies
- Access control, encryption, and incident response policies drafted from your environment.
- Architecture and data-flow documentation
- Documentation of your infrastructure and how data moves through it.
- Security posture summary
- Findings and remediation posture for customer security reviews, alongside approved documentation in your Living Trust Center.
Pen test reports remain on the roadmap.
Add the SOC 2 audit layer.
Compliance Corps includes all of Garrison plus activated SOC 2 checks, founder-led consulting, the full SOC 2 policy set, and control-mapped evidence for audit preparation.
Explore Compliance Corps