← All integrations

Cloud · integration

AWS

IAM, logging, encryption, network exposure, threat detection, backups and India data-residency for an AWS account.

ISO 27001SOC 2PCI DSSCERT-InDPDPARBISEBI CSCRFIRDAI

What ProofLayer proves

Read-only evidence, evaluated against versioned rules.

  • Console users and the root account have MFA; root has no long-lived access keys
  • Access keys are rotated within the allowed age and the password policy meets baseline
  • No public S3, EBS encryption by default, and no security group exposes SSH/RDP to the Internet
  • GuardDuty is on, a multi-region CloudTrail is logging, logs are retained 180+ days and log-file validation is enabled
  • Only Indian regions are enabled (data-residency), and AWS Backup has a plan, a recent successful backup and a tested restore

Configure in ProofLayer

Live in minutes.

  1. Connections → New connection → pick this provider and name the account.
  2. Paste the read-only IAM role ARN ProofLayer should assume (the external ID is generated for you).
  3. Click Test connection — ProofLayer verifies read access from the control plane and reports a clear reason if anything is off.
  4. Set the scan schedule; every run appends to the evidence chain for this account.
  5. Choose the framework mapping(s) and, optionally, a push target (CISO Assistant, a Jira/ServiceNow ticket on failure, or a scheduled auditor pack).

Grant access from your side

Read-only, least-privilege, revocable.

You create the access in your own console and paste a credential ProofLayer stores sealed — it never writes to your systems.

  1. Create a read-only IAM role and attach the AWS-managed SecurityAudit and ViewOnly policies.
  2. Set the trust policy to ProofLayer’s collector principal with the external ID shown on the setup card (a confused-deputy guard).
  3. ProofLayer assumes the role and mints short-lived STS credentials per run — no long-lived keys are ever stored.

In-account agent option. Run the collector on an EC2/EKS instance role with the same read-only policies; ProofLayer holds no credential. The collector posts evidence outbound-only, so ProofLayer holds no credential into your environment.

Start

Connect AWS against your next audit.