AWS Audit
Terms of Use
Last updated: September 27, 2026.
Table of contents
- 1. Purpose and presentation of the Service
- 2. Acceptance of terms
- 3. Subscription and billing
- 4. Customer AWS account and cross-account IAM role
- 5. Audit scope and operations performed
- 6. Use of artificial intelligence
- 7. Processed data, confidentiality and retention
- 8. Personal data protection (GDPR)
- 9. Customer commitments and responsibilities
- 10. Availability and liability
- 11. Intellectual property
- 12. Termination
- 13. Changes to the ToU
- 14. Governing law and competent jurisdiction
- 15. Contact
1. Purpose and presentation of the Service
SAS SILAMIR, trading as Silamir Group ("Silamir"), publishes an online service for the automated audit of Amazon Web Services environments (the "Service"), distributed via AWS Marketplace and accessible from the audit.aws.silamir.com portal.
The Service collects the configuration of the customer's AWS resources in read-only mode, analyses it using artificial intelligence models, then delivers by email a set of reports:
- 10 thematic reports in Word and PDF (inventory, security, FinOps, Well-Architected, resilience, networking, web security, IAM, containers and serverless, secrets and KMS);
- 1 Excel action plan and 1 attack scenarios report (kill-chains);
- 1 narrative executive synthesis (Word and PDF) and 1 19-slide summary deck (HTML and PDF);
- 1 prioritised remediation plan.
These General Terms of Use ("ToU") govern access to and use of the Service. They supplement, without replacing, the subscription contract concluded via AWS Marketplace (AWS Marketplace EULA and conditions of the Silamir Audit AWS listing).
2. Acceptance of terms
Using the Service implies full and unreserved acceptance of these ToU by the customer (legal or natural person acting for professional purposes). The user declares having the necessary powers to bind their organisation and to authorise an audit on the AWS accounts they declare to the Service.
Deploying the CloudFormation stack provided by Silamir and validating the cross-account IAM role constitutes express authorisation to carry out the collection operations described in section 5.
3. Subscription and billing
The Service is exclusively distributed via AWS Marketplace. Subscription, billing and payment are handled by AWS under the terms of the "Silamir Audit AWS" listing (product code 8uxhb9rso66v246fizo5738ff).
- Billing is usage-based: each audit is metered on the
AuditExecutiondimension once the reports have been generated, just before the delivery email is sent. - The current unit price is displayed on the portal before confirming an audit launch, and on the AWS Marketplace product page.
- No direct payment is made to Silamir: all financial flows go through AWS.
- Any billing disputes are first handled by AWS Marketplace; Silamir remains available to facilitate resolution.
4. Customer AWS account and cross-account IAM role
The audit relies on a standard AWS cross-account AssumeRole mechanism. The customer deploys, in their audited account, a dedicated IAM role whose trust policy only allows:
- the Silamir production AWS account
929713278836as principal; - the presentation of a unique External ID generated by the portal, protecting against the confused deputy attack.
Permissions granted to the role are read permissions:
- AWS managed policies
ReadOnlyAccess,BillingandAWSSupportAccess(the latter to read Trusted Advisor checks); - read access to Cost Explorer, Security Hub and Compute Optimizer;
- no permission allows creating, modifying or deleting the customer's resources.
ReadOnlyAccessalso allows reading some data andAWSSupportAccessallows opening support cases: Silamir refrains from both (see section 5).
Maximum session duration of an assumed role is capped at 1 hour. STS temporary credentials are never persisted by Silamir. The customer can, at any time and without notice, delete the CloudFormation stack to immediately revoke access.
5. Audit scope and operations performed
5.1 Configuration collection (always on)
The Service only executes AWS API calls that read configuration and metadata (Describe*, Get*, List*) across ten domains: inventory, security (Security Hub, GuardDuty, Config), FinOps (Cost Explorer, Compute Optimizer), Well-Architected (Trusted Advisor), resilience (backups, replication), networking (VPC, subnets, security groups), web security (CloudFront, API Gateway, ALB, WAF), IAM, containers and serverless, secrets and KMS. It does not read the content of customer data and opens no support case.
5.2 DAST scan (option, opt-in per audit)
The customer may enable a dynamic OWASP ZAP scan on the public endpoints of their account, in one of two modes: baseline (passive requests, at most 20 targets per audit) or full (active scan with attack payloads, at most 10 targets per audit). The scan auto-discovers public URLs by listing CloudFront, API Gateway and ALB in the audited account. Enabling the option, together with the authorisation statement ticked in the portal, constitutes express customer authorisation to perform this scan on the detected endpoints. A scan failure does not interrupt the overall audit.
5.3 Regions covered
20 commercial AWS regions are offered in the portal. Opt-in regions, GovCloud and China are not covered.
5.4 Non-modification commitment
Silamir commits to performing no modification, creation, deletion or write action on the customer's resources, beyond writing audit artefacts to Silamir's own infrastructure.
6. Use of artificial intelligence
Reports are generated using Anthropic Claude Sonnet 4.6 (per-domain analyses) and Claude Opus 4.8 (synthesis, remediation plan), invoked via Amazon Bedrock in the Europe region (inference profiles eu.anthropic.*).
- Data sent to the models is not used to train these models (Amazon Bedrock policy).
- AI-produced analyses are provided for indicative purposes and must be validated by a qualified operator before any action on the customer's infrastructure.
- Silamir implements prompt caching on the Bedrock side to optimise costs; this cache has a 5-minute lifetime and does not affect data confidentiality.
7. Processed data, confidentiality and retention
7.1 Nature of the data
The Service exclusively processes AWS configuration metadata (ARNs, resource identifiers, tags, parameters) and billing data. Collectors read no application data (content of an S3 bucket, database rows, application logs), although the ReadOnlyAccess policy technically allows it.
7.2 Storage and encryption
- Artefacts (collected data and reports) are stored in an S3 bucket encrypted with a dedicated AWS KMS key, isolated in the Silamir Production account (
929713278836), regioneu-west-3(Paris). - The audits and clients DynamoDB tables are encrypted with a dedicated AWS KMS key.
- Fargate containers running the collection operate in a private VPC with VPC endpoints to S3, DynamoDB, STS and Bedrock.
7.3 Retention
- Audit artefacts (raw data, reports) are automatically deleted 7 days after the audit ends (S3 lifecycle).
- Pre-signed download links shared by email are valid for 7 days.
- Audit metadata (identifier, status, timestamps, client) is kept in DynamoDB for billing and support purposes for the duration of the contractual relationship.
7.4 Subprocessors and sharing
No data is shared with any third party outside the technical subprocessors required to deliver the Service:
- Amazon Web Services, Inc. and its affiliates (hosting, compute, storage, AI via Bedrock).
No sale or resale of customer data for commercial or marketing purposes is performed.
7.5 Communication of results
Reports are sent from the address audit@aws.silamir.com. The customer is responsible for receiving and internally distributing the reports; Silamir recommends treating them as confidential.
8. Personal data protection (GDPR)
In the context of Service delivery, Silamir processes personal data as data controller for the following data only: contact name, professional email address, AWS account ID, Marketplace subscription identifier.
- Purposes: contract performance, report communication, support, billing, legal obligations.
- Legal basis: contract performance (Article 6.1.b of the GDPR).
- Retention: duration of the commercial relationship; deletion after termination or on request is performed manually by Silamir within one month.
- Rights: the customer may exercise their rights of access, rectification, erasure, restriction and objection by writing to cloud@silamir.com.
- Complaint: with the French data protection authority (CNIL) at www.cnil.fr.
AWS metadata collected by the Service is, by nature, not personal data. Should the customer choose to tag their AWS resources with personal data (not recommended), they alone bear the responsibility.
9. Customer commitments and responsibilities
The customer commits to:
- only launch audits on AWS accounts they own or for which they have a written authorisation;
- provide accurate information during onboarding (company name, email address, account ID);
- not attempt to bypass the Service's technical controls (External ID, IAM role scope, quotas);
- consider the reports as decision-support material and not as a certification; implementing the recommendations is their sole responsibility;
- promptly inform Silamir in case of any security incident affecting the reports or the temporary credentials used by the Service.
10. Availability and liability
The Service is provided "as is" on a best-effort basis. Silamir does not commit to any formal availability SLA under the AWS Marketplace listing: availability also depends on the availability of the underlying AWS services.
- An audit may fail or be truncated if the IAM role is misconfigured, if AWS quotas are reached, or in case of an AWS service outage; an audit is only billed if its reports have been generated (the step that precedes the delivery email).
- Audit reports are indicative: they do not bind Silamir to regulatory compliance or to the absolute security of the audited environment.
- To the fullest extent permitted by law, Silamir's liability is capped at the total amount invoiced to the customer through AWS Marketplace over the 12 months preceding the triggering event.
- Silamir cannot be held liable for indirect damages (loss of profit, loss of application data, reputational harm), nor for remediation actions decided and implemented by the customer based on the reports.
11. Intellectual property
The tools, scripts, prompts, templates and the Service platform remain the exclusive property of Silamir Group. No licence is granted to the customer beyond a personal and non-transferable right of use, limited to the duration of the subscription.
Data collected from the customer's AWS account and the reports generated therefrom remain the customer's property, who may freely dispose of them.
12. Termination
The customer can terminate their subscription at any time from the AWS Marketplace console (Manage subscriptions → Silamir Audit AWS product). Termination takes effect at the end of the current billing cycle.
Independently of Marketplace termination, the customer can immediately revoke access to the Service by deleting the CloudFormation stack SilamirAuditRole from their AWS account.
Silamir reserves the right to suspend the Service in case of clear abuse (audit launched on a third-party account without authorisation, attempt to bypass technical limits).
13. Changes to the ToU
Silamir reserves the right to modify these ToU at any time. The version in force is the one published on this page. Material changes will be notified by email to active customers at least 30 days before they take effect. Continued use of the Service after that date constitutes acceptance of the new version.
14. Governing law and competent jurisdiction
These ToU are governed by French law. Any dispute relating to their interpretation or performance that has not been resolved amicably shall be submitted to the exclusive jurisdiction of the courts within Paris, notwithstanding plurality of defendants or warranty claims.
15. Contact
For any question relating to these ToU, to the exercise of your rights, or to an incident, contact us at cloud@silamir.com. Publisher: SAS SILAMIR (Silamir Group), 23 rue d'Anjou, 75008 Paris, France - see the legal notice.
These Terms supplement the AWS Marketplace EULA applicable to the Silamir Audit AWS listing. In case of conflict, the AWS Marketplace EULA prevails for commercial clauses (subscription, payment, termination); these Terms prevail for the technical execution of the Service.