Enforcer Brand Icon
Enforcer-CCA
Access ControlsAWSKubernetesSOC 2 (Roadmap)
ProofFeaturesSecurityPricingAbout
Talk to the founder
Enforcer Brand Icon
Enforcer-CCA

Enforcer checks how your cloud is really configured against ISO 27001 every day, and keeps a dated record. It runs alongside the compliance tool you already have.

Platform

  • Features
  • Proof
  • Security & data handling
  • Support Portal

Solutions

  • AWS
  • Kubernetes
  • SOC 2 (Roadmap)

Company

  • About Us
  • Roadmap
  • Pricing
  • Why live-state evidence

Connect

  • Talk to the founder

Ask AI about Enforcer

Start a custom consultation with your favorite AI strategist. Click any LLM platform below to automatically open a session pre-loaded with our detailed, fact-checked product brief.

Prompt Overview

“You are a GRC and compliance strategist advising a cloud-native company that sells to banks or other regulated enterprises. Analyze the business value of Enforcer CCA, a tool that turns the live state of cloud infrastructure into dated comp...”

© 2026 Enforcer-CCA · Runs in your own infrastructure
Terms and ConditionsPrivacy Policy
Private beta — ISO 27001 across AWS & Kubernetes

The gap between “we passed” and “we’re safe” isa year wide.

Last audit
we passed
◄►365 days of unwatched change
Next audit
we hope

Enforcer checks how your cloud is really configured against ISO 27001 every day — read-only — and keeps a dated, hash-verified record of every result. When a bank asks how you control access, you export the answer instead of assembling it. It runs alongside the compliance tool you already have.

Talk to the founder — 20 minutesDownload a sample evidence pack
  • 133 automated ISO 27001 checks
  • Read-only. 45 resource types.
  • SHA-256 on every record
  • No AI in the evidence path
What Enforcer inspects
AWS
Kubernetes
IAM & Access
S3
EC2
VPC & Networking
RDS
CloudTrail
K8s RBAC
ResourceQuota
AWS
Kubernetes
IAM & Access
S3
EC2
VPC & Networking
RDS
CloudTrail
K8s RBAC
ResourceQuota
AWS
Kubernetes
IAM & Access
S3
EC2
VPC & Networking
RDS
CloudTrail
K8s RBAC
ResourceQuota
01Why this exists

I spent years working inside banking environments. Access was shared like candy: credentials passed around, permissions granted “temporarily” and never revoked, one person able to approve their own work.

Every one of those environments had a compliance tool. Every one of them passed.

The tools were not lying. They were reading policy documents and HR records, and the policy documents were fine. Nobody was looking at what the infrastructure was actually doing.

I built Enforcer to look.

OSOmmar Shaikh — founder
02The artifact

This is what “a dated record” actually means

Every check produces one row. Every export bundles those rows with a manifest that hashes every file in the pack. Most compliance tools describe their evidence. Here is ours — read it, download it, and recompute the hashes yourself.

evidence-pack — read-only

A SHA-256 for every file in the pack, plus the database-side hash of each evidence record.

{
  "counts": {
    "control_evaluations": 8,
    "evidence_records": 5,
    "report_artifacts": 1
  },
  "evidence_integrity": [
    {
      "hash_sha256": "d0efcbaa5bdb168a6ee4cdae34bdf1f1b775d5964ff1cf72a15eb8e8ea343476",
      "id": "ev_5a0d6e92_bpa"
    },
    {
      "hash_sha256": "332acd2c1fbfd747fd3a718754180430b92c2e0965eb29999250d7e34d9e4d6e",
      "id": "ev_7f21a4c0_admin"
    },
    {
      "hash_sha256": "f6b76384ccb0f35d38c5438dea64b20061f492f5edf55b5fba5349da0c72e312",
      "id": "ev_c93f10ab_key"
    },
    {
      "hash_sha256": "357e43765be1d86d32238a2815c2e245635a7e1ba9028ab7a71f637ffb96da69",
      "id": "ev_1b8e33d5_crb"
    },
    {
      "hash_sha256": "400ccd472686c77f69555c40cae9a12ea87c72b1e048f4d3d614e0991750ce07",
      "id": "ev_9e6c07f4_enc"
    }
  ],
  "files": [
    {
      "bytes": 1475,
      "path": "controls/control_matrix.csv",
      "sha256": "32f6f1e44d10858578fade69a6efff3b51a68f690665d0d14906f50fafe211e4"
    },
    {
      "bytes": 5299,
      "path": "controls/control_matrix.json",
      "sha256": "8f58845222c5267d2ac34e46a6a05af6e13e0ca6f82f6c351fa1f0e95027470a"
    },
    {
      "bytes": 588,
      "path": "evidence/ev_1b8e33d5_crb.json",
      "sha256": "223d355bdc09b219966e68bad4f8779ee8c0731fb13f177fa22a486960a384f5"
    },
    {
      "bytes": 629,
      "path": "evidence/ev_5a0d6e92_bpa.json",
      "sha256": "5beba4f9151ebfb4ec1bcab34e1b21a84c2980f7abbfa366864c705494c190a7"
    },
    {
      "bytes": 545,
      "path": "evidence/ev_7f21a4c0_admin.json",
      "sha256": "0a91cfbbc5e46df0b8c9f30265621444de5cf706601f0d5a169c9c8fee0ad80e"
    },
    {
      "bytes": 612,
      "path": "evidence/ev_9e6c07f4_enc.json",
      "sha256": "66d5adace8076bd95fe8b0d9cd43accffe894d028bc1481a7416c53a0862b362"
    },
    {
      "bytes": 465,
      "path": "evidence/ev_c93f10ab_key.json",
      "sha256": "8ceaedcd16c60df56297259968fb7489eb2692db43c21472c5d39625b2f3b375"
    },
    {
      "bytes": 492,
      "path": "report/sample-report.html",
      "sha256": "ae16de72efa0dd53d08e5fa63487fdbb8c87cb19466636c8c6138339d277d459"
    }
  ],
  "generated_at": "2026-07-10T12:52:15.030863+00:00",
  "pack_format_version": "1.0",
  "report": {
    "created_at": "2026-07-09T02:15:00+00:00",
    "environment_name": "acme-payments-prod",
    "id": "rpt_sample_0001",
    "standard_id": "std_iso27001_2022",
    "standard_name": "ISO/IEC 27001 2022",
    "status": "COMPLETED"
  },
  "score_summary": {
    "compliance_score": 50.0,
    "controls_assessed": 8,
    "error_controls": 0,
    "failing_controls": 4,
    "passing_controls": 4,
    "unevaluated_controls": 85
  }
}

Verify it yourself

Nothing here needs our word. Download the pack, hash any file in it, and compare againstmanifest.json.

$ unzip enforcer-sample-evidence-pack.zip
$ shasum -a 256 evidence/ev_5a0d6e92_bpa.json
5beba4f9151ebfb4ec1bcab34e1b21a84c2980f7abbfa366864c705494c190a7

The pack itself hashes to ce40e958d50efa7b01dead2006d07f77d848438e24bac668e4537ae39a597fbe.

What this sample is, exactly

A real pack, built by the same function that builds a customer's, from a synthetic environment. The account, buckets and people are invented. The format and every hash are real.

Download (5.6 KB)How to read it

Private beta. The founder answers every message himself.

Talk to the founder
03In plain terms

What Enforcer actually is

If you sell to banks, you have to prove your systems are set up safely — and keep proving it. Enforcer connects to your cloud with read-only access, checks how it is really configured every day, and keeps a dated record of what it found. When something changes for the worse — a database opened to the internet, a contractor holding more access than they should — it notices that day and writes it down.

Today
  • Once a year, someone collects screenshots.
  • A bank asks how you control access. Two engineers spend a week answering.
  • Between audits, nobody can say what actually changed.
With Enforcer
  • Every day, your cloud is checked against the ISO 27001 standard.
  • The answer is already written down, dated, and ready to hand over.
  • If something changes for the worse, you hear about it that day.
04Measured, not marketed

What it checks

Not goals or projections. These are the checks Enforcer runs against your systems today, every day. Every number below links to what it counts.

92Security checks Enforcer runs on your AWS setup32Kinds of AWS resource it inspects — servers, storage, accounts, networks41Security checks it runs inside your Kubernetes clusters13Kinds of Kubernetes resource it inspects25ISO 27001 requirements those checks answer, of 93 in the standard71Read-only AWS permissions Enforcer asks for. None of them can read your data
05What we cover — and what we don't

One standard, covered properly

Other tools list twenty standards and check each one shallowly. We would rather cover ISO 27001 all the way down to the individual server — and add standards when customers ask for them, not to fill a sales slide.

ISO 27001

Available now

133 checks run every day across 32 kinds of AWS resource and 13 kinds of Kubernetes resource, answering 25 of the standard's requirements. Who has access, what is exposed to the internet, what is encrypted, what is logged — answered for each individual server and account, not on a form.

Checked every day

SOC 2

Roadmap

Not built yet, and we will not pretend otherwise. ISO 27001 is the only standard Enforcer checks against today. The underlying engine does not care which standard it is given, so adding SOC 2 means writing the mapping, not rebuilding the product. We build it when the companies we work with tell us it is what is blocking them.

Not available today

Bank vendor reviews & DORA

Same record

When a bank reviews you as a supplier, it asks who can touch what, and how you know. Those are the same questions ISO 27001 asks — so the record Enforcer already keeps answers the review. No separate project.

Answered by the ISO 27001 record
06Before anything changes

Two gates, not one

Enforcer ships with every check in monitor-only mode. Out of the box it cannot change anything in your account. Two independent things must happen first, and neither one is a default.

  1. 01

    Finding

    A check fails. Enforcer records the resource, the rule, and the time.

  2. 02

    Gate 1 — the setting

    The check must be switched out of monitor-only mode. All 133 ship in monitor-only.

  3. 03

    Gate 2 — the person

    A named human approves this specific fix. There is no default-approve.

  4. 04

    Fix

    Only now does anything change. Finding, approval and fix are stored as one record.

24 of the 133 checks have a fix Enforcer knows how to apply. The rest it reports and leaves alone. Nothing here runs on its own, and nothing about it is a guess.

07The infrastructure half of compliance

What your compliance tool cannot see

Your auditor asks about separation of duties once a year. Your infrastructure answers the question every day. Enforcer writes the answer down.

See who can do what

Shared logins, accounts with far more power than the job needs, one person able to approve their own work. Found the day it happens, not at next year’s audit.

Proof from the systems themselves

Each record names the exact server or account, what was checked, what it read, and when — and carries a SHA-256 you can recompute. Not a photograph taken whenever your old tool last checked in.

Runs alongside what you already have

Keep Vanta or Drata for policy documents, training, and HR records. Enforcer covers what they cannot see, inside your cloud. Nothing to migrate, nothing to rip out.

Kubernetes covered, not skimmed

Most compliance tools treat Kubernetes as one box to tick. Enforcer checks access rules, network isolation, and resource limits inside your clusters, and rolls them up next to your AWS results under the same control.

08Objections

The questions we would ask us

Including the ones with answers we would rather not have to give.

01What does Enforcer actually do?
It connects to your cloud with read-only access and checks, every day, how your systems are really set up: who has access to what, what is exposed to the internet, what is encrypted, what is being logged. It compares all of that to the ISO 27001 security standard and writes down what it found, with the date. If something changes for the worse, you know that day instead of at your next audit.
02Do I have to replace the compliance tool I already have?
No. Tools like Vanta and Drata handle policy documents, staff training, and HR records, and they do that well. What they cannot do is look inside your cloud and tell you how it is configured right now — they check in occasionally and record a tick. Enforcer covers that missing half. You install nothing new in your cloud, and nothing about your existing tool changes.
03What access do you need to my AWS account?
A read-only IAM role. It grants 71 permissions across 24 services, and we publish the exact policy document so you can read it before you grant anything. Every permission is a List, Get or Describe on configuration. None of them can read your data: there is no s3:GetObject, no secretsmanager:GetSecretValue, no ssm:GetParameter, no dynamodb:Scan. Enforcer can see that a bucket exists and how it is configured. It cannot see what is inside it.
04Can Enforcer change my systems on its own?
No, and it is built so that it cannot. Every check ships in monitor-only mode, so out of the box Enforcer changes nothing at all. Two separate things must then happen: the check has to be switched out of monitor-only, and a person has to approve that specific fix. Neither is a default. The problem, the approval, and the fix are stored together, so you can always show who decided what. There is no AI making decisions and no AI in the record.
05I already have AWS Config, Security Hub, or Prowler. Why would I add this?
Those tools find misconfigurations, and they are good at it. Some of them are free. Enforcer is not trying to beat them at that job — it does a different one. It takes the state of your infrastructure, maps it to the specific ISO 27001 requirement it evidences, and produces a dated record with a hash on it. Finding a public bucket is a security task. Proving that control A.8.2 held for every one of your resources on the 14th of March, to someone who does not trust you, is a compliance task. If your tooling already does the second thing, you do not need us.
06What does it cover?
AWS — 32 kinds of resource and 92 checks — and Kubernetes, with 13 kinds of resource and 41 checks. Together they answer 25 of the requirements in ISO 27001. That is the only standard Enforcer checks against today. SOC 2 is not built yet, and Azure and Google Cloud come later. We would rather cover one standard properly than twenty shallowly.
07Where does my data go?
Nowhere. Enforcer runs as an appliance inside your own infrastructure — your cloud account, your hardware, your network. There is no Enforcer SaaS backend for it to phone home to, and the licence is verified offline. The findings, the evidence records, and the database all stay on the machine you installed it on. We cannot see your findings, because they never leave your building.
08Is it highly available?
No, and we would rather say so now than during your procurement review. Enforcer today is a single-node appliance. If the node dies you restore it from backup; there is no database replica and no automatic failover. This is a deliberate trade-off for a product at this stage, and it is the first thing we would change for a customer who needs it. If you are running compliance checks that cannot tolerate a restore window, tell us and we will tell you honestly whether we are ready for you.
09What happens to my evidence if your company goes away?
It stays where it already is: on your machine, in your database. An evidence pack is a plain ZIP containing JSON and CSV files and a manifest of SHA-256 hashes — no proprietary format, nothing that needs our software to read. You can open one today, without an account, from the sample on our proof page. We are a solo, bootstrapped company; you should ask this question of us, and you should not have to take our word for the answer.
10Can I buy it today, and what does it cost?
Not yet. Enforcer is in private beta and we are recruiting a small design-partner cohort — companies that get reviewed by banks, or that go through ISO 27001 audits, and are tired of assembling screenshots. Partners get a discounted first year, direct access to the founder, and real influence over what we build. We publish the price we think this is worth, and the reasoning behind it, on the pricing page. We have never sold this, so treat that number as a starting point for a conversation rather than a quote.
11Will my auditor accept this?
Honest answer: we do not know yet, and we are not going to claim otherwise. No auditor has reviewed our evidence format. What we can say is exactly what the record contains — the resource, the check, the result, the timestamp, and a hash you can recompute — and you can download one and judge it yourself. Sitting down with ISO 27001 lead auditors and having them tell us what they will and will not accept is our first priority. Until they do, we will not say they have.
12I am an ISO 27001 auditor or assessor. Should we talk?
Yes, and we would rather talk to you than to a prospect. We want to know what you accept today as evidence that an infrastructure control was operating, what makes you distrust automated collection, and what your clients struggle most to produce. We will show you the evidence format, take the criticism, and publish what you tell us — including if you reject it. Say so on the contact form and it goes straight to the founder.
Now in private beta

Be a design partner.

We are recruiting a small cohort — compliance leads and security engineers at companies that answer to banks and their auditors. You get a discounted first year and a direct line to the founder. In exchange, you tell us what your assessor actually asks you for, and we shape the evidence pack around it before the format is frozen.

Talk to the founderSee the evidence format

No card. No SaaS backend. The founder answers every message himself.