The shared engine

One engine behind everything HardenAxis does.

Security Snapshot and Hardening Advisor aren't separate scanners bolted together — they're two views into the same pipeline. This page shows what each stage does and, just as importantly, what stage it's actually at.

Built on the signals you already have

HardenAxis doesn't ask you to rip out your existing tooling. It normalizes findings from the sources most AWS-native teams already run, and adds the layer those sources don't provide: deciding what to do next, doing it safely, and proving it worked.

  • AWS Security Hub
  • AWS Config
  • Prowler OSS
  • IAM Access Analyzer
01

Assess

Available

Prowler OSS and IAM Access Analyzer scan a read-only cross-account role and produce a normalized, prioritized snapshot. This is Security Snapshot, and it works today.

02

Prioritize

Beta

Correlating findings with the context that determines actual risk, not severity alone. Part of Hardening Advisor's beta; still being built out.

03

Harden

Beta

Generating an IaC-aware change — a Terraform PR or CloudFormation change set — with blast radius and rollback defined before anything is applied. The direction Hardening Advisor is being built toward; not every finding has this path yet.

04

Verify

Beta

Re-checking a fix directly against AWS and recording the finding → ticket → PR → deploy → recheck chain as evidence. In active development alongside Hardening Advisor — we won't call this 'verified' until the provenance chain is real, not just a rescan.

05

Monitor

Research

Watching verified controls for drift and telling a reverted fix apart from a new problem. A research-stage product (Drift Monitoring) with no committed timeline.

We'd rather a stage read beta or research honestly than oversell it — see /contact if something here ever looks inconsistent with what you experience.

Why we're not calling Verification a finished feature

AWS Security Hub already re-checks controls automatically and flips their status from FAILED to PASSED. A simple rescan is not a differentiator — AWS already gives you that for free. What Verify is meant to add is the provenance chain around that rescan: which PR, whose approval, which deploy. Until that chain is real end-to-end, we label it beta, not available.

Start with what's real today

Security Snapshot runs on the Assess stage of this engine and is available now.

Start a security assessment