Let's talk about your project
DOKI / Cybersecurity

Cybersecurity · Cloud security

We review the identity, network and storage settings of your cloud accounts with authorised, read-only access. Publicly exposed resources, over-broad permissions and missing logs are reported in order of importance.

  • Identity and access review
  • Network review
  • Configuration review
  • Risk table
01 / What this service includes

We look at the whole account, layer by layer.

01

Identity and permissions

We review users, roles and service accounts against the principle of least privilege. Wildcard permissions, unused keys and accounts without multi-factor authentication are listed.

02

Network and exposure

Internet-facing ports, security groups and subnet separation are examined. A single map shows which resource can be reached from where.

03

Storage and configuration

Public storage buckets, unencrypted disks and disabled logging are identified, and a remediation step is written for each item.

02 / How it works

The cloud layers

The review addresses the four layers of your account separately; findings are grouped and prioritised by layer.

Identity and access
Network and perimeter
Compute and servers
Data and storage
03 / Scope

Let's define the scope together.

We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.

Only explicitly authorized assets and agreed scope are assessed.

Deliverables

  • 01Identity and access review
  • 02Network review
  • 03Configuration review
  • 04Risk table
04 / Process

How we move forward, step by step.

Each step ends with something concrete in your hands; we move on with your approval.

  1. 01

    Scope

    Together we put the goal, the boundaries and the acceptance criteria in writing.

  2. 02

    Assessment

    We assess the current state against agreed criteria and note gaps with evidence.

  3. 03

    Reporting

    We share what was done, the result and the next step in a plain report.

  4. 04

    Retest

    We retest fixed findings and confirm with evidence that they are closed.

05 / Scope

Test categories applied in this service

Which categories are applied is agreed together, based on your target and scope.

Cloud layer

More than 600 cloud configuration checks for AWS, Azure and Google Cloud.
Number of categories: 4
  • Cloud configuration audit

    We audit your AWS, Azure and Google Cloud accounts with more than 600 checks covering permissions, logging, encryption and network settings.

  • Exposed cloud storage detection

    We check whether file storage in the cloud (buckets) has been left open to everyone on the internet by mistake.

  • Kubernetes security

    We review the access, permission and network settings of your container platform against secure configuration guidelines.

  • Container image vulnerability scan

    We scan the container images your applications are packaged in for outdated components with known vulnerabilities.

The figures are the number of checks in our automated security engines. Not every category runs in every test; the ones that fit your target and scope are selected.

Every test runs with your written permission and within the scope we agree together. Tests that could disrupt a service, and social engineering, are planned only with separate written approval. No test proves that a system is completely secure; we report clearly what was and was not found.

06 / Decision details

What to know before you ask for a quote.

What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.

Included

  • A review of identities and permissions, networking and configuration.
  • AWS, Azure and Google Cloud.
  • Evidence, a risk level (critical, high, medium, low) and a fix recommendation for every finding.
  • One retest within 30 days of the report is included in the price.

Not included

  • Fixing the findings (offered separately as Remediation).

What we need from you

  • A signed written authorisation.
  • Read-only audit access (nothing in your account is changed).

Timing and delivery

  • Tests run on weekdays between 09:00 and 18:00 (Türkiye time).

What sets the price

  • Number of cloud accounts (subscriptions) to review.

Payment and aftercare

  • For work agreed in person, the full fee is paid at the start.
  • For remote work, half is paid at the start and half on delivery.
  • We respond to every request within 12 hours.
  • Meetings are held in Turkish; correspondence and deliverables are handled in the language of your choice with translation support.
  • We work in person in Istanbul and remotely across Türkiye and worldwide.
07 / FAQ

The questions on your mind.

Tell us what you need; we will define the scope together.

Tell us about your project
Which cloud environments do you review?

We can work on the common public cloud providers and on virtualisation environments you host yourself. Scope, number of accounts and access method are agreed in the first meeting; the review uses read-only permissions.

Is permission needed before testing?

Yes. Only systems you are authorised for and have approved in writing are assessed.

Will testing affect my live system?

Scope, time window and methods are agreed in advance; risky steps require your separate approval.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.