CI/CD OIDC → AWS data
4M records reachable from a CI run
AWS, Azure, GCP and the federated identity glue between them — IAM trust paths, control-plane misconfigurations and cross-cloud privilege escalation, validated continuously.
Modern enterprises run AWS, Azure and GCP, federated through Microsoft Entra, Okta or Google Workspace, with workload identities crossing boundaries. Every misconfigured trust is a potential attack path.
Cloud security tooling enumerates misconfigurations. None of it tells you which combination chains into actual control-plane compromise.
KeenSafe maps roles, service principals, federated identities and SCP/Conditional-Access boundaries across accounts, subscriptions and projects — then walks the privilege paths.
Read-only connectors mean we never modify your cloud. Exploitation is scope-bounded and reversible.
Roles, service principals, workload identity federation and OIDC trust graphed across clouds.
Org-, account- and resource-level API misconfigurations exploited safely.
S3 / Blob / GCS, RDS / Cosmos / BigQuery, KMS / KeyVault — exploitable read/write paths.
Workload-identity federation, OIDC trust, SaaS-to-cloud roles validated end-to-end.
EKS / AKS / GKE, Lambda / Functions / Cloud Run — RBAC, runtime escapes, metadata-service abuse.
CIS Benchmarks, NIST 800-53, ISO 27017, PCI DSS cloud, AWS / Azure / GCP Well-Architected security.
Cloud attack paths typically chain through identity. The interesting work is finding the privilege graph that traverses from a low-privilege federated identity into a crown-jewel data store.
4M records reachable from a CI run
Cross-cloud admin reach proven
KeenSafe never modifies cloud configuration.
First-class connectors. Oracle / IBM via webhooks.
Most environments find at least one cross-cloud admin reach.
Cloud config drift surfaces as risk in minutes.
"Can a federated identity reach customer data through our cloud, today?" KeenSafe answers it across AWS, Azure and GCP — quarter over quarter.
For regulators and insurers asking the same question, evidence is portable.
Per-cloud connectors enumerate the privilege graph; the orchestrator runs reachability analysis from declared crown jewels backwards to entry points; chains are validated by safe assume-role / token-issuance simulation.
A guided session walks the validated chain from a federated identity to a crown-jewel data store.