Skip to content
PostureForge

AWS Security Hub · Claude · IaC

Turn Security Hub findings into reviewed infrastructure fixes

PostureForge triages each finding, finds the CDK or SAM stack that owns the resource, and opens a pull request with cdk diff and a rollout runbook. A human approves every change.

The loop that burns engineer time

Hundreds of findings. Each one becomes a ticket.

Cloud teams drown in Security Hub alerts: KMS keys with public policies, Lambdas callable by anyone, APIs without WAF. Someone has to ask—which stack created this, is it really exposed, what is the safe fix, and how do we roll it out from sandbox to production?

Manual triage across accounts and regions

Hard to map a resource ARN back to CDK or SAM

Fixes without a reviewed diff scare production

How it works

From finding to approved pull request

01

Ingest

Security Hub findings flow through EventBridge into SQS with a DLQ, then into DynamoDB for durable triage state.

02

Triage

Claude returns structured JSON: exposure, severity, and whether the finding is a true positive worth remediating.

03

Trace to IaC

Read-only AWS MCP tools and repo search locate the CDK or SAM stack that owns the resource.

04

PR + runbook

CodeBuild runs cdk synth/diff. A pull request and sandbox→staging→prod runbook open for human approval.

Triage → remediation

Structured output, not vibes

Security Hub finding
{
  "GeneratorId": "security-control/KMS.5",
  "Title": "KMS keys should not be publicly accessible",
  "Severity": "CRITICAL",
  "Resources": [{ "Type": "AwsKmsKey" }]
}
cdk diff

Safety by design

Nothing lands in production without a human

Read-only IAM

Based on SecurityAudit. The agent describes and gets; it never applies changes itself.

Config metadata only

No application data. Secrets, account IDs, and sensitive tags are redacted before the model sees them.

Human approval gate

Every remediation is a pull request. Approve in your normal review flow—or leave it closed.

Audit log

Every agent action is written down so you can prove what Claude saw and suggested.

Waiting for human approval

fix(kms): restrict key policy principal

Controls we start with

The findings that already show up as tickets

KMS.5Lambda.1S3.1IAM.1APIGateway.4EC2.1CloudTrail.1Config.1GuardDuty.1WAF.1RDS.2SecretsManager.1KMS.5Lambda.1S3.1IAM.1APIGateway.4EC2.1CloudTrail.1Config.1GuardDuty.1WAF.1RDS.2SecretsManager.1

Founder

Built by someone who remediates these tickets for real

I'm Oğuzhan Sarı—a senior software engineer with 9 years in IT and a BSc from Istanbul Technical University. Since 2024 I've built serverless AWS systems for a regulated US healthcare platform, including a shared WAF layer across nine repositories and Security Hub remediations like KMS.5 and Lambda.1. PostureForge is the tool I wished I had while doing that work.

AWS certifications

FAQ

Straight answers

Does PostureForge change my AWS account automatically?+

No. It opens pull requests and drafts runbooks. A human merges and deploys.

Which IaC tools do you support?+

CDK and SAM first. Terraform is on the months 7–12 roadmap.

Do you send application data to Claude?+

No. Only configuration metadata after redaction. No secrets, no PHI, no customer payloads.

Where does Claude run?+

First-party Claude API from your AWS compute (Lambda/ECS). Credits from Anthropic programs do not apply to Bedrock.

Early access

Join the waitlist for design partners

Tell us about your AWS footprint and which Security Hub controls hurt the most. We reply from hello@postureforge.dev.