AWS Security Hub · Claude · IaC
Turn Security Hub findings into reviewed infrastructure fixes
PostureForge triages each finding, finds the CDK or SAM stack that owns the resource, and opens a pull request with cdk diff and a rollout runbook. A human approves every change.
The loop that burns engineer time
Hundreds of findings. Each one becomes a ticket.
Cloud teams drown in Security Hub alerts: KMS keys with public policies, Lambdas callable by anyone, APIs without WAF. Someone has to ask—which stack created this, is it really exposed, what is the safe fix, and how do we roll it out from sandbox to production?
Manual triage across accounts and regions
Hard to map a resource ARN back to CDK or SAM
Fixes without a reviewed diff scare production
How it works
From finding to approved pull request
01
Ingest
Security Hub findings flow through EventBridge into SQS with a DLQ, then into DynamoDB for durable triage state.
02
Triage
Claude returns structured JSON: exposure, severity, and whether the finding is a true positive worth remediating.
03
Trace to IaC
Read-only AWS MCP tools and repo search locate the CDK or SAM stack that owns the resource.
04
PR + runbook
CodeBuild runs cdk synth/diff. A pull request and sandbox→staging→prod runbook open for human approval.
Triage → remediation
Structured output, not vibes
{
"GeneratorId": "security-control/KMS.5",
"Title": "KMS keys should not be publicly accessible",
"Severity": "CRITICAL",
"Resources": [{ "Type": "AwsKmsKey" }]
}Safety by design
Nothing lands in production without a human
Read-only IAM
Based on SecurityAudit. The agent describes and gets; it never applies changes itself.
Config metadata only
No application data. Secrets, account IDs, and sensitive tags are redacted before the model sees them.
Human approval gate
Every remediation is a pull request. Approve in your normal review flow—or leave it closed.
Audit log
Every agent action is written down so you can prove what Claude saw and suggested.
Waiting for human approval
Controls we start with
The findings that already show up as tickets
Founder
Built by someone who remediates these tickets for real
I'm Oğuzhan Sarı—a senior software engineer with 9 years in IT and a BSc from Istanbul Technical University. Since 2024 I've built serverless AWS systems for a regulated US healthcare platform, including a shared WAF layer across nine repositories and Security Hub remediations like KMS.5 and Lambda.1. PostureForge is the tool I wished I had while doing that work.
AWS certifications
FAQ
Straight answers
Does PostureForge change my AWS account automatically?+
No. It opens pull requests and drafts runbooks. A human merges and deploys.
Which IaC tools do you support?+
CDK and SAM first. Terraform is on the months 7–12 roadmap.
Do you send application data to Claude?+
No. Only configuration metadata after redaction. No secrets, no PHI, no customer payloads.
Where does Claude run?+
First-party Claude API from your AWS compute (Lambda/ECS). Credits from Anthropic programs do not apply to Bedrock.
Early access
Join the waitlist for design partners
Tell us about your AWS footprint and which Security Hub controls hurt the most. We reply from hello@postureforge.dev.