Security and compliance
CloudFix Compliance and Security Assurance
CloudFix is SOC 2 Type 2 audited. This page explains the access model a security reviewer will ask about: what CloudFix can read, what it can change, who approves each change, and where the record of it lives.
Source of record
trust.cloudfix.com
CloudFix’s security and compliance documents, including the SOC 2 Type 2 audit report, policies and security questionnaire answers, are published in the Trust Center. This page is a summary; the Trust Center is authoritative.
Visit the Trust CenterAudited, certified and listed
The access model
Four steps, and one of them is yours.
01Connect
A CloudFormation stack in your account
It creates the IAM roles CloudFix uses, scoped to least privilege. No long-term credentials, passwords or access keys to hand over.
02Read
Finders are read-only
They read your Cost and Usage Report, resource configurations and CloudWatch metrics. They never read customer data in any data store, and they change nothing.
03Approve
You approve every change
You choose who can approve, and whether a fix runs now, runs on a schedule, or never runs.
04Run
AWS Systems Manager Automation
Approved fixes run as Automation runbooks in your own account, under a dedicated CloudFix role. Every execution has its own ID and log.
In detail
What a security review will ask.
How CloudFix connects
During onboarding you deploy a CloudFormation stack in your own account. It creates the IAM roles CloudFix uses, scoped to least privilege.
- Scoped IAM roles: the templates define tightly scoped roles that allow only the actions CloudFix needs, such as reading Cost and Usage Reports and resource configurations, and applying the specific fixes you approve.
- Cross-account access control: access uses AWS’s recommended cross-account pattern, so account boundaries stay intact and every call is attributable.
- Audit and monitoring: actions CloudFix takes are recorded in AWS CloudTrail in your account, where your own tooling can monitor them.
What happens when a fix runs
Approved fixes run as AWS Systems Manager Automation runbooks in your own account, under a dedicated CloudFix role.
- Snapshots first: where the fix supports it, CloudFix takes a snapshot before making the change, so you can restore the previous state.
- Every execution is logged: each Automation execution carries a full record of what ran, where and when, which supports your own audit requirements.
- Based on AWS’s own guidance: each fixer implements a documented AWS best practice or advisory.
Your compliance obligations
Inside the controls you already operate.
CloudFix works within the AWS shared responsibility model. Because changes run in your account, through your approval workflow and your logging, they stay inside the controls you already operate for frameworks such as GDPR or HIPAA. Whether a given change fits your obligations is your call, which is why nothing runs without your approval.
Walk through the access model with your security team.
The SOC 2 Type 2 report, policies and security questionnaire answers are at trust.cloudfix.com.

