Cloud Security, Built and Run by Engineers
We review your Google Cloud and Workspace environments, deploy the tooling that watches them, and fix what it finds.
Almost every organisation we meet has had a security assessment. Some have had three. The findings sit in a spreadsheet, the highest-severity items are still open a year later, and the next assessment finds them again.
The gap isn’t knowing. It’s capacity. Nobody on the platform team has a spare week to rewrite IAM bindings or unpick a service account that eleven workloads depend on.
We do both halves. We find the problem and we fix it, in your Terraform, with your team watching.
What we do
Cloud Security Reviews (GCP)
A two-week review of your Google Cloud organisation: IAM, org policy, network exposure, encryption, logging and how your projects are laid out. You get findings ranked by what an attacker would actually use, and a fix list we can deliver for you.
Workspace Reviews
Your Workspace tenant is where the data lives. We review admin settings, third-party OAuth grants, Drive sharing, admin account hygiene and Gmail authentication, then hand back settings changes with the exact admin console path for each one.
Wiz
Wiz shows you everything. That’s the problem and the point. We connect it to your organisation, tune it so the noise drops, and then work the queue with you until the toxic combinations are gone.
Managed Agentic SOC
New from Aviato. We run detection and response for you on Google SecOps, with Claude-based agents doing triage and enrichment and our engineers making the calls. We’re taking on a small number of first customers.
Google SecOps
Getting logs into Google SecOps is easy. Getting them parsed, normalised and actually detecting something is the work. We build ingestion, write the detections in YARA-L, and hand over a platform your team can run.
Not sure which one you need?
- If you’ve never had your Google Cloud environment reviewed, start with a Cloud Security Review. It tells you where you stand in two weeks and costs less than the tooling.
- If you already know roughly where you stand and want it watched continuously, start with Wiz.
- If your problem is alerts rather than misconfiguration, and nobody is reading them, that’s Google SecOps or the Managed Agentic SOC, depending on whether you want to run it or want us to.
- If you’re a Workspace-heavy business with light GCP usage, do the Workspace Review first. That’s where your exposure is.
- Not obvious from the outside? Ask us. A 30 minute call is usually enough to tell.
Why us?
Focused Tech Stack
We only do Google Cloud, Google Workspace and Wiz. No AWS, no Azure, no long tail of tools we’ve read the datasheet for.
Our team
Our team is led by ex-Googlers who have worked inside the products they now secure.
No Lock-in
We don’t build lock-in. Everything we deliver is documented and handed over, and we’ll tell you when the answer is a setting change rather than a project.
Ready to Transform Your Cloud Infrastructure?
Join thousands of businesses already benefiting from our Cloud
Foundations.
Subscribe Now
Join our newsletter to stay up to date on features and releases
Let's build something transformative together on Google Cloud.
Schedule a complimentary architectural review session with our certified Google Cloud and AI engineering specialists.