Skip to content
kubepath Book a call
Menu

Infrastructure that won't leak or fall over.

We audit and harden the cloud, pipelines and servers under your app, and leave infrastructure your next engineer can understand.

Who it's for

  • Everything deploys straight to production and shipping feels risky
  • Your only senior engineer left and nobody knows how it fits together
  • Bots, brute force or DDoS keep taking the site down
  • A customer asked about IAM, logging, encryption or backups and you had no answer

What's covered

Identity and access

IAM roles, least privilege, MFA everywhere, no shared root keys, clean offboarding.

Secrets

Keys moved into a secrets manager, leaked ones rotated.

Environments

Separate dev, staging and production with safe, repeatable deploys.

CI/CD

Branch protection, required reviews, dependency and secret scanning in the pipeline.

Network and edge

Firewalls, exposed ports, SSH hardening, Cloudflare WAF, rate limiting, hidden origin.

Backups and recovery

Automated backups, tested restores and a written recovery plan.

Logging and monitoring

Audit logs and alerts that matter, plus a SIEM when you need one.

Containers and Kubernetes

Image scanning, RBAC, network policies, CIS baselines.

What you get

TimelineAudit in 3 to 5 days. Fix sprint of 1 to 3 weeks.
PriceAudit from USD 2,000. Fix sprint from USD 4,000.
  • Prioritised findings, critical first, with why each one matters
  • Fixes delivered as infrastructure as code and pull requests
  • Architecture diagram and runbooks for deploy, restore and key rotation
  • Handover call so your team owns it

Not included

  • Application code review (see App Security Review + Fix)
  • 24/7 operations (available on retainer)