Help Center

Find answers. Get set up. Stay secure.

Everything you need to connect AWS, understand identity security findings, map compliance controls, and make the most of Securitain.

Browse help topics

Organized by what you need to do

Getting Started

Connect your AWS account and run your first scan in minutes.

  • Connect AWS via the read-only CloudFormation role
  • Understand the read-only IAM role and what it can access
  • Run your first security scan and review results
  • Understand findings — severity, evidence, and remediation guidance

Identity Security

Understand IAM identities, trust relationships, and privilege escalation.

  • IAM users, roles, groups, and policy analysis
  • Trust relationships and cross-account access
  • Privilege escalation — how iam:PassRole and role chaining create risk
  • IAM Identity Center and AWS Organizations / SCP analysis

Compliance

Map findings to control frameworks and generate audit-ready evidence.

  • How Securitain maps findings to compliance control areas
  • Reviewing compliance evidence per scan
  • Generating and exporting compliance reports (PDF, CSV)
  • Supported frameworks: CIS, SOC 2, HIPAA, NIST 800-53, PCI DSS, ISO 27001

Security & Privacy

Understand exactly what Securitain accesses — and what it does not.

  • How Securitain connects to your AWS account (read-only role, STS, ExternalId)
  • What Securitain reads vs. what it never accesses
  • How to revoke access and disconnect an account
  • Data retention, encryption, and deletion workflows
Frequently asked questions

Common questions about Securitain

How does Securitain connect to my AWS account?

Securitain is agentless. You deploy a read-only cross-account IAM role via CloudFormation. The role is protected with a unique ExternalId to prevent confused-deputy attacks. Securitain assumes that role using temporary AWS STS credentials — no long-lived keys, no agents, nothing installed in your environment.

What does a scan actually read?

Securitain reads IAM users, groups, roles, policies, access-key metadata, MFA status, credential report data, IAM role trust policies, and supported resource policies (S3, KMS, SQS, SNS, Secrets Manager). Where the role has permission, it also reads IAM Identity Center permission sets and AWS Organizations SCP configuration.

What does Securitain never access?

Securitain does not read S3 object contents, database records, secrets values, application data, or any runtime logs. It does not make changes to your infrastructure, rotate credentials, or deploy policies. It cannot access AWS accounts you have not explicitly connected.

How are findings explained?

Every finding shows the evidence behind it — the specific identity, policy, permission, trust relationship, or credential configuration that triggered it. Findings include severity context, remediation guidance with AWS CLI examples, and compliance control mappings where applicable.

Does Securitain certify me as compliant with HIPAA, SOC 2, or PCI DSS?

No. Securitain maps technical security findings to relevant control areas across frameworks such as CIS AWS Foundations, SOC 2, HIPAA, NIST 800-53, PCI DSS, and ISO 27001. This is finding-to-control mapping with supporting evidence — not formal attestation. Certification is performed by independent auditors.

How do I disconnect an AWS account?

You can remove a connected account from your Securitain settings at any time. After disconnecting, you should also delete the cross-account IAM role from your AWS account to fully revoke access. Securitain retains your scan history for the retention period set in your plan, after which it is deleted.

Get in touch

Support options

Can't find what you need in the docs? We're here.

Email Support

Send a question or report an issue — our team responds with detailed, technical guidance.

Response within one business day

support@securitain.com

Book a Technical Session

Schedule time with the team to walk through your AWS environment, findings, or compliance questions.

Available for all plans

Chat with Securitain