Security
Encryption, public access controls, MFA, TLS, identity least privilege
Lensix reviews your AWS, Azure, and GCP environments the way a senior cloud engineer would: security posture, architecture, spend, performance, reliability, and operational gaps. Every finding ranked by severity, with the reasoning behind it, in a dashboard your whole team can read.
Read-only, enforced by the cloud itself. Revoke it instantly, any time. Or grant no access at all and run the collector yourself.
Resource metadata, not your data. Bucket contents, database records, and secrets never leave your cloud.
Every check Lensix runs works through all three paths. Pick whichever one your security team is comfortable with. Plenty of teams use two at once: live accounts for some environments, self-hosted for the ones they keep fully closed off.
Deploy a read-only role in your own account using our template. AWS gets the AWS-managed ReadOnlyAccess policy, Azure gets Reader, GCP gets Viewer. Lensix can only describe and list. Delete the role and access is gone instantly, no ticket required.
See how it is enforcedA Docker container on your own infrastructure, on your own schedule, using your own credentials. It reads your account, writes one results file, and sends us only that. No IAM role, no service principal, no service account, nothing live for Lensix to hold.
See how self-hosting worksGenerate a point-in-time inventory with a tool you run locally, then upload the file. Zero credentials shared with Lensix on this path. You get findings across all six areas, from a snapshot instead of a live connection.
See what the file containsWhat a Lensix review covers
Security
Encryption, public access controls, MFA, TLS, identity least privilege
Architecture
Single points of failure, network topology, coupling, drift from reference patterns
Cost
Unused resources, oversized instances, idle services
Performance
Right-sizing, Performance Insights, caching, throughput
Reliability
High availability, deletion protection, backup retention, redundancy
Operations
Audit logging, config rules, access logging, lifecycle policies
All six areas, across AWS, Azure, and GCP, in a single review. This is the same ground a cloud specialist covers in a paid architecture assessment, run continuously instead of once a year.
Free
No credit card required
3
Cloud providers
6
Review areas
3
Ways to connect
Security & trust
We take that seriously. Here is exactly what access Lensix gets, what it keeps, and how you revoke it whenever you want. Read our full security practices →
Lensix reads facts about how resources are configured, such as “this S3 bucket has public access enabled” or “this RDS instance has no deletion protection.” It does not read, transfer, or store the contents of your S3 buckets, database records, Secrets Manager values, or any business data.
What we store, in full: resource identifiers, names, types, regions, configuration settings, and check results. That is what powers the inventory and tracks findings over time. Your business data never leaves your cloud.
For AWS, Lensix uses the AWS-managed ReadOnlyAccess policy, written and maintained by AWS. It permits only describe and list API calls. There is literally no API call Lensix can make that creates, modifies, or deletes anything in your account.
Azure uses the Reader role. GCP uses the Viewer role. These are the lowest-privilege read-access roles each cloud offers.
For AWS, you deploy the IAM role in your own account using our CloudFormation template or manual step-by-step instructions. The role and its permissions live entirely in your AWS account. Lensix never holds your AWS credentials.
Want to cut access? Delete the IAM role and Lensix is locked out immediately, with no ticket or cancellation required. Same for Azure and GCP: remove the role assignment or delete the service account and access is gone instantly.
Lensix is built by Absolute Ops, which has spent years doing hands-on cloud security reviews, architecture assessments, and compliance audits for organizations across healthcare, finance, and technology.
Lensix exists because those reviews kept surfacing the same findings by hand. What you get in the dashboard is that review process, encoded. We know what we are asking you to grant, and we designed the access model to minimize it.
Connect your cloud accounts however you prefer. Nothing in your environment is ever modified.
Register your organization in seconds. Invite your team with admin or member roles.
Read-only role, self-hosted collector, or inventory file upload. All three produce the same review, and nothing in your environment is ever modified.
Open your dashboard and get a prioritized list of real issues: open security holes, fragile architecture, wasted spend, overdue backups, ranked by severity so you start with what matters. Plus a full resource inventory showing everything in your cloud.
Whether you are a solo engineer or a platform team, Lensix gives you a continuous read on what is broken, what is expensive, and what is at risk, with agents and rule-writing left out of it.
Most tools check settings against a rule list and stop there. Lensix looks at how the pieces fit together: single points of failure, network topology that will not survive an AZ outage, resources coupled in ways that make change risky.
Security, architecture, cost, performance, reliability, and operations, all in the same pass. Wasted spend, under-provisioned databases, missing backups, and broken audit trails surface together, because that is how they actually show up in a real environment.
An open S3 bucket is not the same priority as a missing lifecycle policy. Every finding is ranked critical, high, medium, low, or info, with the reasoning attached, so you spend time on what actually matters.
Managing three AWS accounts across two environments? Lensix consolidates every account into a single view, scoped to your organization. Add accounts in minutes, filter by provider, account, or severity.
Fix the issue, run the next review, and it is gone. Lensix clears resolved findings automatically, so your dashboard is a live picture of the environment rather than a stale report.
Every review builds a live inventory of your cloud resources across all providers. Browse by resource type, region, or provider, and see exactly what you have and where your findings are concentrated.
Turn an EC2 instance into an interactive diagram of its VPC, subnet, route table, security groups, and attached volumes, or pick a VPC and see every peering connection it has. The topology an architecture review depends on, without cross-referencing IDs by hand.
Lensix reads resource metadata: identifiers, names, types, regions, configuration settings, and results. It does not read the contents of your buckets, database records, or secrets. That data never leaves your environment.
Disable checks that do not apply, adjust severity for your risk tolerance, and suppress known exceptions with expiry dates, all without touching a config file.
Set a recurring interval and Lensix keeps reviewing on schedule. No cron job to babysit, and nobody has to remember to run it before the next audit.
Email digests plus Slack and Teams notifications when new findings appear, so issues surface where your team is already paying attention rather than in a dashboard nobody opens.
From compute and storage to messaging and identity, Lensix reviews the services your workloads depend on.
Free to start. Connect your AWS, Azure, or GCP account however you prefer, and you will have a prioritized review before your next standup.
Create an account