Evidence-based, controlled, and transparent.
We believe cloud consulting should be predictable. We define the boundary before touching anything, evaluate using actual configuration evidence, explain findings in plain English, and separate review from implementation.
How Kervora Cloud Works
A disciplined four-stage process that prioritises clarity, evidence, and controlled execution at every step.
Scope
Understand the environment, objectives and agreed boundaries before access or technical work begins.
Assess
Review the agreed AWS areas using evidence rather than assumptions.
Explain
Turn technical findings into prioritised, plain-English recommendations.
Improve
Where requested, implement approved changes with controlled delivery, validation and evidence.
Your AWS environment stays under your control.
Granting third-party access to cloud infrastructure requires absolute confidence in handling, intent, and boundaries. Kervora adheres to strict, transparent operational rules designed to safeguard your environment at all times.
Scope Agreed in Advance
We never perform scans or touch infrastructure outside agreed target accounts and pre-defined architectural boundaries.
Least-Privilege Role Access
Assessments use read-only AWS managed policies (such as SecurityAudit or ViewOnlyAccess) tailored strictly to what is needed.
Temporary, Controlled Access
We recommend cross-account IAM role assumption with external IDs or AWS IAM Identity Center sessions rather than static user accounts.
Zero Root Credential Handling
We will never ask for, accept, or handle root account credentials. Root access is never required for consulting reviews.
No Credential Transmission via Email
We explicitly instruct clients never to send AWS passwords, IAM secret keys, or private SSH keys via email or web forms.
Independent Assessment & Approval
Assessment is strictly separate from implementation. No changes are ever applied to your environment without prior written sign-off.
Validation & Change Evidence
Any approved implementation is validated against recorded test steps and configuration evidence before handover.
Immediate Access Revocation
Once work is delivered, client teams simply revoke or delete the assumed IAM role, leaving zero lingering access.
What you receive from an engagement
Depending on the engagement, Kervora provides concise, actionable documentation structured for both engineering teams and business leadership.
Clear Findings
Understand what was identified without having to interpret raw AWS JSON output or cryptic console logs.
Prioritised Actions
Separate urgent risks from useful operational improvements and longer-term architectural considerations.
Supporting Evidence
Where appropriate, findings reference the specific AWS resource IDs, configuration lines, and metrics observed.
Practical Recommendations
Recommendations clearly explain what could be changed, why it matters, and the operational trade-offs involved.
Defined Next Steps
Use the review as a clear foundation for internal engineering, Kervora implementation, or specialist partner delivery.
Have questions about our process?
Speak directly with Shaun to discuss how an assessment or remediation engagement would work for your specific AWS setup.