Cloud Security Prevention Platform (CSPP) for AWS Organizations
Traditional Cloud Security Posture Management (CSPM) tools monitor environments and generate alerts after misconfigurations have already been deployed into production. This leads to alert fatigue, persistent backlogs, and exposed attack surfaces.
Fleet Marshal introduces Cloud Security Posture Prevention (CSPP)—a security-first model that focuses on establishing organizational guardrails, enforcing immutable Service Control Policies (SCPs), and eliminating vulnerabilities at the source through automated, verifiable remediation.
Connects entire AWS Organizations via cross-account IAM roles with External IDs. Automatically discovers member accounts and detects existing AWS Control Tower setups.
Preview remediation changes with dry-run diffs and cross-account impact assessments before applying fixes like S3 Block Public Access, EBS default encryption, or Root lockdown.
Every remediation action captures an immutable pre-state snapshot in DynamoDB, enabling instant one-click rollback if operational dependencies are discovered.
EventBridge schedules automated 24-hour compliance scans across all connected member accounts, generating historical compliance trends and tracking score changes over time.
Maintains a comprehensive audit log of all user actions, remediation events, and invitations with category filtering and instant CSV export for SOC 2 & ISO compliance.
Amazon Cognito authentication with fine-grained Admin, Viewer, and ReadOnly roles, email team invitations, and demo mode with nightly automated test resets.
Fleet Marshal scans and remediates baseline security guardrails across 6 critical operational domains:
| Domain | Control ID | Security Guardrail | Remediation Mechanism |
|---|---|---|---|
| Storage | storage-1 |
S3 Account-Level Block Public Access | AWS API + Organization SCP Enforcement |
| Storage | storage-2 |
S3 Bucket Default Encryption (AES256) | Terraform S3 Bucket Policy Module |
| Storage | storage-3 |
EBS Encryption by Default (All Regions) | EC2 API Cross-Region Automation |
| IAM | iam-1 |
Root User Lockdown | Service Control Policy (SCP) via Management Acct |
| IAM | iam-5 |
Account Password Policy Enforcement | IAM Account Alias & Credential Baseline |
| Database | db-1 |
DynamoDB Point-in-Time Recovery (PITR) | DynamoDB Continuous Backup Policy |
| Logging | logging-1/2/3 |
Multi-Region CloudTrail + Log Validation | CloudTrail Baseline + S3 Access Logging |
| Monitoring | monitor-1 |
Unauthorized API Call CloudWatch Alarms | CloudWatch Metric Filter + SNS Topic Alarm |
Fleet Marshal is built entirely on a modern serverless, event-driven architecture designed for high scalability and zero idle cost:
Open Fleet Marshal MVP Explore All Open Source Projects Back to Home