Evidence & Findings
What each collector captures
Five collectors, the exact fields each one gathers, and the AWS calls behind them, every one traceable to a line of collector source.
Account metadata
Which account was scanned, its alias, whether it belongs to an organisation and whether it is the management account. Context, not a governance position.
Errors are recorded rather than swallowed, so a permission failure produces a visible gap instead of a metadata file that looks successful.
Security Hub posture
Whether Security Hub is enabled, whether a delegated administrator is configured, whether cross-region finding aggregation is on, and how many active failed findings exist.
The finding count is null when it cannot be retrieved, rather than silently reported as zero.
Cost telemetry
30-day spend from your billing data, plus evidenced waste from unattached storage volumes, unassociated static IP addresses and snapshots stale beyond a year. Each waste item carries the evidence that produced it.
When no idle resources are found, waste is zero. When every probe fails, waste is null and the domain is not rated rather than guessed at.
Resilience posture
Coverage ratios across five configuration signals over databases, auto scaling groups, load balancers and object storage, collected across every enabled region.
Control checks
The scanner's control results across every enabled region at critical, high and medium severity, with both passing and failing results collected.
Delivery evidence
Only when a source repository is explicitly supplied. Collected, not scored. It makes no AWS call and requires no AWS permission.
Every call is accounted for
A machine-readable manifest names every AWS call the assessment makes and the source file that makes it. A test fails if the role grants something no collector calls, or if a collector calls something the role does not grant. See What the role can read.
