Gold Fig Checkup

Hands-on cloud security checks with guided fixes across code, terminal, and AWS
Rating
Your vote:
No screenshots
Visit Website
goldfiglabs.com
Loading

Start by wiring Gold Fig Checkup into the places you already work. Connect your cloud accounts through a read-only role, link your Git repos, and pick the environments you care about most. Kick off an initial scan from the terminal or CI to build a live inventory and surface the riskiest gaps first. Findings arrive with plain-language context, an impact summary, and exact steps to fix—no hunting through docs. You can bookmark critical items, mute accepted risks with expiration dates, and schedule recurring runs so the system keeps watch while you focus on delivery.

If you manage infrastructure as code, add the CLI and a pre-commit hook so unsafe patterns never leave your laptop. Run targeted checks on Terraform or CloudFormation folders, and let pull request annotations highlight problems right in the diff. Each alert includes code-ready snippets: least-privilege IAM examples, hardened S3 policies, or secure defaults for security groups. Approve the suggested patch or let Gold Fig open a remediation PR for you. In CI, enforce thresholds by severity, gate merges on must-fix items, and map checks to your internal policies or common benchmarks—without turning every build into red ink.

Operating in live cloud? Sync your AWS organization to enumerate resources across accounts and regions, then work a prioritized queue: publicly exposed buckets, wide-open network rules, over-permissioned roles, missing encryption, stale access keys, and more. Each item provides a deep link to the exact console screen plus copy-paste terminal commands for quick remediation. Batch-fix repetitive issues, set nightly scans to catch drift, and compare runtime to what’s defined in code so you can tell when production strays from your intentions. Send alerts to Slack or email, track acknowledgments, and record approvals with reason codes for a clean audit trail.

For leads and auditors, the reporting suite turns raw checks into decision-ready summaries. Use prebuilt templates you can tailor by team, environment, or framework, schedule weekly digests, and export CSV or PDF for evidence. Team management assigns owners, sets due dates, and measures SLA performance, so nothing gets lost between security and engineering. When a big push lands, spin up a live review using the built-in video conferencing, walk through the highest-impact items together, capture action items on the spot, and convert them into tickets in Jira. Over time, trends dashboards reveal recurring trouble spots—use them to plan targeted training and trim noise by fixing root causes instead of chasing alerts.

Review Summary

Features

  • Customizable reporting with prebuilt templates and scheduled exports
  • Built-in video conferencing for live reviews and training sessions
  • Team management with roles, ownership, SLAs, and approvals
  • CLI, pre-commit hooks, and CI gates for code-first workflows
  • Scanning for Terraform and CloudFormation with autofix snippets
  • AWS organization integration and multi-account resource inventory
  • Policy library with mapping to internal standards and benchmarks
  • Pull request annotations and automated remediation PRs
  • Drift detection between code and runtime
  • Slack, email, and Jira integrations for alerts and ticketing
  • Exception handling with expiration and audit notes
  • Scheduled scans and prioritized issue queues

How It’s Used

  • Shift-left security for infrastructure-as-code during local development
  • Block high-severity misconfigurations in CI before merge
  • Continuously audit AWS accounts and remediate risky settings
  • Generate evidence-ready reports for leadership and compliance
  • Run live, guided fix sessions with engineers using video conferencing
  • Assign owners and due dates, track SLAs, and measure closure rates
  • Detect and resolve drift between declared code and running resources
  • Prepare new cloud accounts with baseline hardening playbooks
  • Triage incidents with a prioritized queue and one-click console deep links
  • Reduce repeat issues through trends analysis and targeted training

Plans & Pricing

Solo

Free

Limited to one user on team
Maximum of one AWS account
Once per week account rescanning

Standard

$200.00 per month

Add up to 25 users on team
Maximum of three AWS accounts
On-demand and unlimited rescans

Advanced

$790.00 per month

Up to 100 users on team
Maximum of 10 AWS accounts
Support for GovCloud accounts
Quarterly prioritization video call
Includes support for custom reports

Comments

User

Your vote: