Skip to main content

AWS Audit

How the AWS audit works

From subscription to reports, an audit runs in five stages. You stay in control of access from start to finish.

Audit flowYour AWS account authorises a read-only role; Silamir collects the configuration, analyses it with Amazon Bedrock AI in Europe, generates the deliverables and emails them to you.Your AWS accountRead-only roleCollectionAI analysisDeliverablesAudit flowYour AWS account authorises a read-only role; Silamir collects the configuration, analyses it with Amazon Bedrock AI in Europe, generates the deliverables and emails them to you.Your AWS accountRead-only roleCollectionAI analysisDeliverables
  1. 1. Subscribe on AWS Marketplace

    You subscribe to the offer from AWS Marketplace, which then redirects you to this portal. You enter your company and the technical contact's email address, which you confirm with a 6-digit code sent by email. Deliverables will be sent to that address.

  2. 2. Deploy the IAM role

    The portal opens the CloudFormation console of your account with a prefilled template. The stack creates the SilamirAuditReadOnly role, which only the Silamir production account can assume, and only by presenting the unique External ID generated for you. You then paste the role ARN into the portal, which checks access.

    View the CloudFormation template

  3. 3. Choose regions and DAST scan

    You select the regions where your resources live. The DAST scan is optional: baseline mode (passive, up to 20 targets) or full mode (active, with attack payloads, up to 10 targets). Targets are discovered automatically (CloudFront, API Gateway, ALB); an authorisation statement is mandatory.

  4. 4. Collection and analysis

    Ten collectors read your account configuration in parallel. The data is then analysed by Anthropic Claude models invoked through Amazon Bedrock, using European inference profiles. The analysis produces the domain reports, attack scenarios, remediation plan and summary. Automated checks verify that the reports are consistent with the collected data.

  5. 5. Delivery

    You receive an email from audit@aws.silamir.com, usually 30 to 60 minutes after launch. Downloads are protected by a code sent to the verified address; each download link expires after 10 minutes. Artefacts are deleted automatically after 7 days.

After the audit

Delete the SilamirAuditRole CloudFormation stack to revoke access immediately. You can redeploy it for your next audit.

Ready to audit your AWS account?

Subscribe on AWS Marketplace, deploy the read-only role and get your reports within the hour.