Skip to content
CloudSecOps

How an engagement actually runs.

Every consultancy now claims AI acceleration. Almost none will tell you what the AI does, what it doesn't, or where your money goes. Here is our pipeline, stage by stage — published so you can judge the engineering before you buy it.

The CloudSecOps engagement pipeline: scope, then automated inventory and reconnaissance, AI-assisted analysis, human validation by senior engineers, findings and remediation written by the engineer who found them, and automated verification retesting. Automation handles enumeration and correlation; engineers own exploitation, architecture, and judgment.
  1. 01

    Scope

    Fixed scope, fixed price — agreed in days

    AI + engineers
  2. 02

    Inventory & Recon

    Asset, identity and data-path enumeration

    automated
  3. 03

    AI-Assisted Analysis

    Correlation and first-pass triage at machine speed

    AI + engineers
  4. 04

    Human Validation

    Exploit chains, architecture, judgment

    engineers
  5. 05

    Findings & Fixes

    Written by the engineer who found them

    engineers
  6. 06verified

    Verify

    Retest until confirmed fixed

    automated

Four layers, one request.

  1. 01 — The stack

    Four layers, one request.

    Identity, workload, model, data. Every request your business runs crosses all four, and a weakness in any one of them is a path through the rest.

  2. 02 — The happy path

    This is what should happen.

    An authenticated identity reaches a workload, which calls a model, which touches only the data it was scoped to. Legible, bounded, auditable.

  3. 03 — The real path

    This is what we find.

    A probe enters at the workload layer — an over-permissioned role, a poisoned tool response, a forgotten endpoint — and reaches straight for the data, skipping every boundary that was supposed to matter.

  4. 04 — The control

    Then we close it, and prove it.

    Gateway policy, scoped identity per tool, human approval on the actions that deserve it. We retest until the original path is dead — the engagement ends at verified, not at PDF.

Stage by stage

01

Scope

AI + engineers
Inputs
Architecture walkthrough, account inventory, your top three worries
What automation does
Public-surface reconnaissance and rough asset counts before the call, so we arrive informed rather than asking you to describe your own estate.
What engineers do
The engineer who will do the work runs the call, argues with your assumptions, and writes the scope. Fixed scope, fixed price — or an honest 'you don't need this yet'.
What you get
A written scope with explicit in/out boundaries, destructive-action rules, and a price that doesn't move.
02

Inventory & Reconnaissance

automated
Inputs
Scoped read access, issued by you and revocable
What automation does
Identity, resource, network-reachability and data-path enumeration across accounts and projects. Configuration state, policy documents, logging coverage, and exposure mapping collected into one graph.
What engineers do
Nothing yet — this is the work that used to consume the first week of a traditional engagement.
What you get
A complete environment graph. You get it whether or not we find anything interesting.
03

AI-Assisted Analysis

AI + engineers
Inputs
The environment graph, plus current threat intelligence
What automation does
Correlation across signals that humans read serially: which permissive role is reachable from which exposed service, which finding matters because of what sits behind it. First-pass triage ranks candidates by exploitability, not scanner severity.
What engineers do
Every candidate is reviewed. Machine output is never forwarded to you — it is the starting point for the next stage, not a deliverable.
What you get
A ranked candidate list. Internal artifact; it exists to direct human attention.
04

Human Validation

engineers
Inputs
The ranked candidates, and the parts of your architecture that worry us
What automation does
Nothing. This stage is where the fee goes.
What engineers do
Exploit chains built and proven end to end. Threat models drawn against how your system actually behaves. Business-logic and multi-step attacks that no scanner enumerates. Findings that don't survive scrutiny are dropped, not padded into the report.
What you get
Confirmed findings with reproducible steps — reported as they're confirmed, not saved for a delivery date.
05

Findings & Remediation Engineering

engineers
Inputs
Confirmed findings, your stack, your constraints
What automation does
Report assembly, evidence collection, and cross-referencing.
What engineers do
Each finding is written by the engineer who found it — impact, path, and a fix designed for your environment. Where the fix is code or policy, we write the code or policy. Where it's an architectural change, we draw it.
What you get
The report, remediation artifacts, and an executive summary that states impact without inflating it.
06

Verify

automated
Inputs
Your deployed fixes
What automation does
Re-execution of the original proof for each finding, plus regression checks on the surrounding surface.
What engineers do
Judgment on partial fixes: we say so plainly when a mitigation reduces risk without removing it.
What you get
Each finding marked fixed, partially fixed, or accepted — with evidence. The engagement ends here, not at PDF delivery.

The pipeline, written out

The same six stages as above, in plain prose — for readers, and for anything that reads on their behalf.

01Scope

An engagement starts with an architecture walkthrough, an account inventory, and your top three worries. Before the scoping call happens, automation has already run public-surface reconnaissance and rough asset counts, so we arrive informed rather than asking you to describe your own estate. The call itself is run by the engineer who will do the work, and that engineer argues with your assumptions and then writes the scope personally. The result is a written scope with explicit in-and-out boundaries, agreed rules for destructive actions, and a fixed price that does not move after signature. When the honest answer is that you don't need the engagement yet, we say that instead, and the process ends there.

02Inventory & Reconnaissance

With scoped, revocable read access that you issue, automation enumerates identities, resources, network reachability, and data paths across every account and project in scope. Configuration state, policy documents, logging coverage, and exposure mapping are collected into a single environment graph. No engineer touches this stage — it is exactly the work that used to consume the first week of a traditional engagement, and it is the reason ours doesn't. The output is a complete graph of what you actually run, and you receive it whether or not the engagement goes on to find anything interesting: an accurate inventory has standalone value even when the news is good.

03AI-Assisted Analysis

The environment graph is combined with current threat intelligence, and machine analysis correlates signals a human would otherwise read serially: which permissive role is reachable from which exposed service, and which finding matters because of what sits behind it. A first-pass triage ranks candidates by real exploitability rather than by scanner severity labels. Every candidate on that list is then reviewed by an engineer. Machine output is never forwarded to you as a finding — it is the starting point for human validation, not a deliverable. The stage produces a ranked candidate list that stays internal; its only job is to direct expensive human attention at the places most likely to matter.

04Human Validation

This stage is where the fee goes, and nothing in it is automated. Working from the ranked candidates — and from the parts of your architecture that worry us independently of any tool — engineers build and prove exploit chains end to end, draw threat models against how your system actually behaves, and pursue the business-logic and multi-step attacks that no scanner enumerates. Candidates that don't survive scrutiny are dropped rather than padded into the report. What leaves the stage is a set of confirmed findings with reproducible steps, reported as they are confirmed — a critical finding on day two reaches you on day two, not on the delivery date.

05Findings & Remediation Engineering

Each confirmed finding is written up by the engineer who found it: the impact, the attack path, and a fix designed for your environment and constraints rather than a generic recommendation. Where the fix is code or policy, we write the code or the policy; where it is an architectural change, we draw it. Automation handles the mechanical parts — report assembly, evidence collection, and cross-referencing. You receive the full report, the remediation artifacts themselves, and an executive summary that states impact plainly without inflating it, written for the people who have to decide what to fund.

06Verify

After you deploy fixes, automation re-executes the original proof for every finding and runs regression checks on the surrounding surface, so "fixed" is demonstrated rather than asserted. Engineers apply judgment where the result is not binary: when a mitigation reduces risk without removing it, we say so plainly instead of marking it green. Every finding ends the engagement marked fixed, partially fixed, or accepted, each with evidence attached. The engagement ends here, at verified remediation, not at PDF delivery.

The rules we work by

Automation earns its place or it goes

We automate work that is repetitive and verifiable: enumeration, correlation, evidence collection, regression retesting. We do not automate judgment, and we don't ship you machine output with our name on it.

Findings arrive when they're confirmed

Nothing is held back for a delivery date. If something is critical on day two, you hear about it on day two — usually with a suggested mitigation before the report exists.

The engineer on the call is the engineer on the engagement

There is no bench, no handoff to a junior team, and no account manager between you and the work. That constrains how much we take on, which is the trade we've chosen.

We say when you don't need us

Some enquiries end with a recommendation to fix three things yourself and call back in six months. That costs us a project and earns a client.

Now you know how we work.

The scoping call is 30 minutes with the engineer who'd run the engagement.