Track 1
IAM / Access Risk
Review IAM users, roles, policies, high-risk permissions, access concentration, and identity-risk findings that should be visible before security or due-diligence review.
Read-only AWS consulting review
STOIXLAB reviews selected AWS evidence and prepares a practical, human-reviewed report covering identity exposure, CloudTrail/logging readiness, Lambda/serverless runtime safety, and prioritized next-step recommendations.
Engagement boundary
The review can be scoped as one track, two tracks, or a full three-track evidence review. Exact scope depends on AWS environment size, available evidence, and the review goal.
Track 1
Review IAM users, roles, policies, high-risk permissions, access concentration, and identity-risk findings that should be visible before security or due-diligence review.
Track 2
Review CloudTrail/logging readiness, evidence availability, event visibility, and reportable gaps in AWS activity history.
Track 3
Review selected Lambda and serverless runtime evidence, execution boundaries, logging signals, and operational-safety findings.
The STOIXLAB website does not publish exact prices at this stage. Each engagement is scoped after a short review of environment size, selected tracks, and available evidence.
Starter
A focused review of IAM/access risk, logging evidence, or serverless runtime safety.
Standard
A combined review across two AWS evidence areas with one integrated summary.
Full Evidence Review
IAM/access risk, CloudTrail/logging readiness, and Lambda/serverless runtime safety reviewed together for a fuller operating picture.
The AWS Security Evidence Review is delivered as a read-only consulting engagement, supported by STOIXLAB’s internal stoiXDome methodology for AWS-native evidence, workflow safety, and risk-prioritized review.
Clients buy the AWS Security Evidence Review service. stoiXDome is the supporting methodology and technical foundation behind the review approach.
STOIXLAB reviews evidence, prepares findings, and explains practical next steps. The engagement does not make changes to AWS resources and does not replace an internal security owner, legal advisor, or formal compliance decision.
The report is designed for clarity: what was reviewed, what appears risky, what evidence supports the finding, and what should be considered next.
Contact STOIXLAB with the AWS evidence area you want to review first: IAM/access risk, CloudTrail/logging readiness, Lambda/serverless runtime safety, or the full three-track review.
Contact STOIXLAB