How Securitain works
Securitain converts read-oriented AWS security information into connected identity and cloud-risk context.
At a high level, the process consists of four stages:
CONNECT Customer-controlled AWS role │ ▼ INVENTORY Identity, policy, trust and security context │ ▼ ANALYZE Access, exposure, relationships and risk │ ▼ DELIVER Findings, graphs, governance and reports
1. Connect
An AWS account is connected using a cross-account IAM role created in the customer's AWS environment. Securitain assumes that role using AWS Security Token Service, or STS. An External ID is included in the trust relationship to provide additional protection when establishing cross-account access.
The customer remains in control of the AWS role and the access it allows.
Securitain does not require:
- customer IAM user access keys
- long-lived AWS credentials
- an agent installed on workloads
- standing administrative permission to customer resources
2. Inventory
Once the connection is established, Securitain collects the security metadata required for the capabilities available to that account. Depending on available permissions and enabled assessment capabilities, this can include context related to:
- Identity — IAM users, groups, roles, policies, access keys, root-account security signals.
- Authorization — attached and inline policies, permission boundaries, trust relationships, effective-permission context, sensitive permissions.
- Enterprise identity — supported IAM Identity Center information, permission sets, AWS Organizations and SCP context.
- Exposure — external principals, cross-account trust, supported resource policies, federation relationships.
- Security and usage evidence — where enabled, additional AWS security and activity signals used for least-privilege and exposure analysis.
The available scope can differ between AWS accounts. Securitain therefore validates what it can assess rather than assuming every connected account has identical capabilities.
3. Analyze
Collected information is evaluated from several perspectives.
- Identity risk — what identities exist and which show security-relevant conditions?
- Permission risk — what capabilities are granted, and how do different authorization controls affect them?
- Exposure — what trust relationships allow access from another account, identity provider or external principal?
- Escalation — can one set of permissions lead to a more privileged capability?
- Reachability — what roles, resources or security-sensitive capabilities could an identity ultimately reach?
- Governance — what findings remain open, have been remediated, or are governed through an approved exception?
Relationships create context
Many AWS security conditions become meaningful only when several pieces of information are correlated. Consider:
IAM User ↓ Group ↓ Policy ↓ AssumeRole permission ↓ Privileged Role ↓ Production
No single object represents the entire risk. Securitain correlates these relationships so teams can investigate the complete access context. This relationship model supports capabilities such as the IAM Relationship Graph, privilege-escalation analysis, blast-radius analysis, cross-account analysis and identity-to-data analysis.
The underlying detection and correlation implementation is managed by Securitain and is not required for customers to operate the platform.
4. Deliver
Analysis is presented through several different views depending on the security question being investigated:
- Findings — actionable security conditions with evidence and remediation context.
- IAM inventory — searchable identities, roles, policies, groups and credentials.
- Relationship Graph — a visual representation of selected identity, policy and trust relationships.
- Escalation analysis — potential routes through which permissions may lead to more privileged capabilities.
- Exposure — cross-account, trust-policy, resource-policy and federation context.
- Governance — remediation and exception workflows that keep risk decisions traceable.
- Compliance — mappings between supported technical findings and relevant control frameworks.
- Reports — views designed for technical teams, security leadership and compliance stakeholders.
Assessments represent a point in time
AWS environments change continuously. A Securitain assessment represents the security information observed for an AWS account during a particular scan. For that reason, the platform preserves scan context and freshness information. A newer IAM change may not be represented by an older assessment.
When investigating a result, consider:
- AWS account
- scan time
- successful assessment capabilities
- unavailable capabilities
- assessment errors
- evidence freshness
Partial assessment does not mean pass
AWS permissions, service availability or configuration can prevent some information from being assessed. Securitain distinguishes between:
- Passed — the relevant security condition was assessed and the control criteria were satisfied.
- Finding — evidence indicates a security-relevant condition.
- Not assessed / unavailable — Securitain does not have sufficient information to make the determination.
Limitation
Customer-controlled access
The AWS connection remains under the customer's control. Customers can change or revoke the Securitain IAM role from their own AWS environment. Because Securitain's AWS integration is read-oriented, the platform can investigate security posture without requiring permission to make infrastructure changes.