AWS · Azure · GCP

A cloud analyst on your team

Reviewing and hardening cloud environments since 2021

Lensix reviews your AWS, Azure, and GCP environments the way a senior cloud engineer would: security posture, architecture, spend, performance, reliability, and operational gaps. Every finding ranked by severity, with the reasoning behind it, in a dashboard your whole team can read.

Read-only, enforced by the cloud itself. Revoke it instantly, any time. Or grant no access at all and run the collector yourself.

Resource metadata, not your data. Bucket contents, database records, and secrets never leave your cloud.

AWS, Azure & GCPSix review areasSeverity-ranked findingsFree to start
Your choice, not ours

Three ways to connect. Same review either way.

Every check Lensix runs works through all three paths. Pick whichever one your security team is comfortable with. Plenty of teams use two at once: live accounts for some environments, self-hosted for the ones they keep fully closed off.

Free and paid

Give us read-only access

Deploy a read-only role in your own account using our template. AWS gets the AWS-managed ReadOnlyAccess policy, Azure gets Reader, GCP gets Viewer. Lensix can only describe and list. Delete the role and access is gone instantly, no ticket required.

See how it is enforced
Paid plans

Run the collector yourself

A Docker container on your own infrastructure, on your own schedule, using your own credentials. It reads your account, writes one results file, and sends us only that. No IAM role, no service principal, no service account, nothing live for Lensix to hold.

See how self-hosting works
Free and paid

Upload an inventory file

Generate a point-in-time inventory with a tool you run locally, then upload the file. Zero credentials shared with Lensix on this path. You get findings across all six areas, from a snapshot instead of a live connection.

See what the file contains

What a Lensix review covers

Security

Encryption, public access controls, MFA, TLS, identity least privilege

Architecture

Single points of failure, network topology, coupling, drift from reference patterns

Cost

Unused resources, oversized instances, idle services

Performance

Right-sizing, Performance Insights, caching, throughput

Reliability

High availability, deletion protection, backup retention, redundancy

Operations

Audit logging, config rules, access logging, lifecycle policies

All six areas, across AWS, Azure, and GCP, in a single review. This is the same ground a cloud specialist covers in a paid architecture assessment, run continuously instead of once a year.

Free

No credit card required

3

Cloud providers

6

Review areas

3

Ways to connect

Security & trust

Letting a tool into your cloud is a real decision

We take that seriously. Here is exactly what access Lensix gets, what it keeps, and how you revoke it whenever you want. Read our full security practices →

Resource metadata, not your data

Lensix reads facts about how resources are configured, such as “this S3 bucket has public access enabled” or “this RDS instance has no deletion protection.” It does not read, transfer, or store the contents of your S3 buckets, database records, Secrets Manager values, or any business data.

What we store, in full: resource identifiers, names, types, regions, configuration settings, and check results. That is what powers the inventory and tracks findings over time. Your business data never leaves your cloud.

Read-only, technically enforced

For AWS, Lensix uses the AWS-managed ReadOnlyAccess policy, written and maintained by AWS. It permits only describe and list API calls. There is literally no API call Lensix can make that creates, modifies, or deletes anything in your account.

Azure uses the Reader role. GCP uses the Viewer role. These are the lowest-privilege read-access roles each cloud offers.

You create it, you control it, revoke anytime

For AWS, you deploy the IAM role in your own account using our CloudFormation template or manual step-by-step instructions. The role and its permissions live entirely in your AWS account. Lensix never holds your AWS credentials.

Want to cut access? Delete the IAM role and Lensix is locked out immediately, with no ticket or cancellation required. Same for Azure and GCP: remove the role assignment or delete the service account and access is gone instantly.

The analyst behind the product

Lensix is built by Absolute Ops, which has spent years doing hands-on cloud security reviews, architecture assessments, and compliance audits for organizations across healthcare, finance, and technology.

Lensix exists because those reviews kept surfacing the same findings by hand. What you get in the dashboard is that review process, encoded. We know what we are asking you to grant, and we designed the access model to minimize it.

Your first review in minutes

Connect your cloud accounts however you prefer. Nothing in your environment is ever modified.

  1. 1

    Create your account

    Register your organization in seconds. Invite your team with admin or member roles.

  2. 2

    Choose how you connect

    Read-only role, self-hosted collector, or inventory file upload. All three produce the same review, and nothing in your environment is ever modified.

  3. 3

    See what actually needs fixing

    Open your dashboard and get a prioritized list of real issues: open security holes, fragile architecture, wasted spend, overdue backups, ranked by severity so you start with what matters. Plus a full resource inventory showing everything in your cloud.

Built for teams who own the infrastructure

Whether you are a solo engineer or a platform team, Lensix gives you a continuous read on what is broken, what is expensive, and what is at risk, with agents and rule-writing left out of it.

  • Reviews architecture, not just config

    Most tools check settings against a rule list and stop there. Lensix looks at how the pieces fit together: single points of failure, network topology that will not survive an AZ outage, resources coupled in ways that make change risky.

  • Six areas, one review

    Security, architecture, cost, performance, reliability, and operations, all in the same pass. Wasted spend, under-provisioned databases, missing backups, and broken audit trails surface together, because that is how they actually show up in a real environment.

  • Know what to fix first

    An open S3 bucket is not the same priority as a missing lifecycle policy. Every finding is ranked critical, high, medium, low, or info, with the reasoning attached, so you spend time on what actually matters.

  • One dashboard, many accounts

    Managing three AWS accounts across two environments? Lensix consolidates every account into a single view, scoped to your organization. Add accounts in minutes, filter by provider, account, or severity.

  • Fixes update themselves

    Fix the issue, run the next review, and it is gone. Lensix clears resolved findings automatically, so your dashboard is a live picture of the environment rather than a stale report.

  • Full resource inventory included

    Every review builds a live inventory of your cloud resources across all providers. Browse by resource type, region, or provider, and see exactly what you have and where your findings are concentrated.

  • See how your resources connect

    Turn an EC2 instance into an interactive diagram of its VPC, subnet, route table, security groups, and attached volumes, or pick a VPC and see every peering connection it has. The topology an architecture review depends on, without cross-referencing IDs by hand.

  • Your data stays in your cloud

    Lensix reads resource metadata: identifiers, names, types, regions, configuration settings, and results. It does not read the contents of your buckets, database records, or secrets. That data never leaves your environment.

  • Tune it to your environment

    Disable checks that do not apply, adjust severity for your risk tolerance, and suppress known exceptions with expiry dates, all without touching a config file.

  • Reviews on a schedule

    Set a recurring interval and Lensix keeps reviewing on schedule. No cron job to babysit, and nobody has to remember to run it before the next audit.

  • Alerts where your team already is

    Email digests plus Slack and Teams notifications when new findings appear, so issues surface where your team is already paying attention rather than in a dashboard nobody opens.

Comprehensive coverage across your cloud stack

From compute and storage to messaging and identity, Lensix reviews the services your workloads depend on.

Compute & Containers

  • EC2
  • Lambda
  • ECS
  • EKS
  • ECR

Storage

  • S3
  • EBS
  • EFS

Databases

  • RDS
  • DynamoDB / DAX
  • ElastiCache
  • Redshift
  • OpenSearch
  • DocumentDB
  • Neptune

Networking

  • VPC
  • Security Groups
  • Load Balancers
  • API Gateway
  • CloudFront

Identity & Account

  • IAM Users
  • Account Controls
  • CIS CloudWatch Alarms
  • Secrets Manager

Messaging & Streaming

  • SNS
  • SQS
  • Kinesis
  • MSK
  • MQ

Analytics & Data

  • Athena
  • EMR

DevOps & Cost

  • CodeBuild
  • Cost & Budgets
  • WorkSpaces

Azure Coverage

Virtual Machines

  • VMs
  • Scale Sets
  • Managed Disks
  • Snapshots

Containers & Apps

  • AKS
  • Container Registry
  • Container Apps
  • App Service
  • Functions

Networking

  • NSGs
  • Load Balancers
  • App Gateway
  • Front Door
  • CDN
  • Bastion

Storage & Data

  • Storage Accounts
  • Blob Storage
  • Data Lake
  • Synapse

Databases

  • SQL Server
  • PostgreSQL
  • MySQL
  • Cosmos DB
  • Redis Cache

Identity & Security

  • Key Vault
  • Security Center
  • Defender for Cloud
  • Authorization

Messaging

  • Event Hub
  • Service Bus
  • Event Grid

Monitoring & Logging

  • Azure Monitor
  • Activity Logs
  • Diagnostic Settings

GCP Coverage

Compute

  • Compute Engine
  • Cloud Functions
  • Instance Groups

Kubernetes

  • GKE
  • Node Pools
  • Workload Identity

Networking

  • VPC
  • Firewall Rules
  • Subnets
  • DNS
  • Load Balancers

Storage

  • Cloud Storage
  • BigQuery
  • Disk Snapshots

Databases

  • Cloud SQL (MySQL, PostgreSQL, SQL Server)
  • Pub/Sub

Identity & IAM

  • IAM
  • Service Accounts
  • Workload Identity Federation

Encryption & Keys

  • Cloud KMS
  • Customer-Managed Keys

Monitoring & Logging

  • Cloud Logging
  • Audit Logs
  • Log Sinks

Common questions

What is Lensix?
Lensix is a cloud analyst for your team. It reviews your AWS, Azure, and GCP accounts across six areas the way a senior cloud engineer would: security, architecture, cost, performance, reliability, and operations. Findings are ranked by severity so your team always knows what to fix first.
How is Lensix different from a cloud security scanner?
A scanner tells you which rules failed. Lensix reviews the environment. Alongside security misconfigurations it flags fragile architecture, single points of failure, spend you are not using, and the operational gaps that only surface during an audit. Every finding carries the reasoning behind it and a severity that reflects real risk rather than rule count.
Is Lensix free?
Yes. Create an account, connect your cloud accounts, and get your first review. No credit card required.
Which cloud providers does Lensix support?
AWS, Azure, and GCP are all fully supported. Connect any combination and see findings from all accounts in a single dashboard.
What does Lensix review?
Six areas: Security (unencrypted resources, public access, missing MFA, weak TLS), Architecture (single points of failure, network topology, resource coupling, drift from reference patterns), Cost (idle instances, unused storage, oversized databases), Performance (underutilized resources, missing caching), Reliability (no backups, deletion protection disabled, redundancy gaps), and Operations (CloudTrail gaps, missing access logging, expired certificates).
How does Lensix connect to my cloud accounts?
Three ways, and you pick. A read-only role you deploy yourself: cross-account IAM role in AWS, service principal in Azure, service account in GCP. A self-hosted collector on paid plans: a Docker container you run with your own credentials, which sends us only the results file. Or an inventory file you generate locally and upload, with zero credentials shared. All three produce the same findings.
What data does Lensix store?
Resource metadata only: identifiers, names, types, regions, configuration settings, and check results. Enough to power the resource inventory and track findings over time. Lensix does not read, transfer, or store the contents of your S3 buckets, database records, Secrets Manager values, or any business data.
Can I review multiple accounts?
Yes. Add as many AWS, Azure, or GCP accounts as you need. All findings appear in one dashboard, filterable by provider and account.
Does Lensix make changes to my environment?
Never. Lensix is entirely read-only across every provider it supports. It calls only read-only APIs.

Put a cloud analyst on your team today

Free to start. Connect your AWS, Azure, or GCP account however you prefer, and you will have a prioritized review before your next standup.

Create an account