FEATURES / Security

/// Security

Understand your exposure. Enforce your policies.

Audit public access settings across every bucket. Inspect bucket policies and IAM permissions. Generate time-limited presigned URLs. Built for teams that take storage security seriously.

Start for free
Security auditAll connected accounts · Last scanned: just now5 secure1 exposed↻ Rescan allPublic access detected — staging-mediaThis bucket has a public ACL. Objects may be readable by anyone on the internet.ReviewPrivateprod-assetsus-east-1Bucket policyPrivateIAM accessRead/WriteCORS rules2 rulesView full policy →Privateprod-uploadsus-east-1Bucket policyPrivateIAM accessWrite-onlyCORS rulesNoneView full policy →Publicstaging-mediaus-west-2Bucket policy⚠ Public ACLIAM accessFull accessCORS rules1 ruleView full policy →Privatebackups-eueu-west-1Bucket policyPrivateIAM accessRead-onlyCORS rulesNoneView full policy →Privatedev-sandboxus-east-1Bucket policyPrivateIAM accessFull accessCORS rulesNoneView full policy →Privatelogs-archiveap-southeast-1Bucket policyPrivateIAM accessWrite-onlyCORS rulesNoneView full policy →

Your entire S3 posture. One view. Every account.

/// How it works

01

Connect your accounts

Add credentials for all your AWS accounts. Storafleet scans Public Access Block settings, bucket policies, and IAM permissions across every bucket.

02

Audit your exposure

The security dashboard surfaces every misconfiguration: public buckets, wildcard policies, and over-permissioned credentials — all in one view.

03

Share objects securely

Generate time-limited presigned URLs for any object. Set expiry. Copy link. No bucket policy changes, no public access required.

Public access audit

See which buckets have public access enabled — intentionally or not. Flag misconfigurations across all your accounts in one view.

Bucket policy viewer

Read raw bucket policy JSON. Storafleet highlights grants that permit public access or cross-account access so you don't miss them.

IAM permission checker

Verify what your connected credentials can actually do on each bucket. Understand effective permissions before you hit an access denied.

AES-256-GCM credential storage

Your AWS Access Keys and Secrets are encrypted at rest using AES-256-GCM with a per-user derived key. Never stored in plaintext. Never shared.

Presigned URLs with expiry control

Share any object securely with a time-limited presigned URL. Set expiry from minutes to days. No bucket policy changes. No public access.

CORS configuration viewer

View CORS rules per bucket. Understand which origins have cross-origin access to your objects — useful when debugging web app S3 integrations.

/// Without Storafleet

Security misconfigurations in S3 are invisible until something breaks — or gets breached.

  • Check public access settings by clicking through each bucket individually
  • Bucket policies are JSON nobody re-reads after initial setup
  • No unified view of what your credentials can actually do across all buckets
  • Sharing a file means making it public (permanent) or 3+ Console clicks per object
  • CORS misconfigurations discovered during production browser debugging

/// With Storafleet

A security audit dashboard across all accounts. Misconfigurations surface in seconds.

  • Public access audit across all accounts in one dashboard view
  • Bucket policy viewer highlights dangerous grants without you parsing raw JSON
  • IAM permission checker shows effective permissions per bucket
  • One-click presigned URL with expiry control — no public access ever needed
  • CORS viewer per bucket — understand cross-origin rules instantly

/// Common S3 security failures

The three misconfigurations we see most.

01

The public bucket you forgot about

Created in 2022 for a one-off asset share. Public Access Block never set. Still sitting there, fully readable by anyone with the URL — or a scanner.

Storafleet

Storafleet flags every bucket with public access enabled across all connected accounts. One view, zero guessing.

*
02

The wildcard bucket policy from 2019

Resource: "*", Principal: "*", Effect: Allow. Written during a late-night incident. Nobody touched it since. It's granting access to more than you think.

Storafleet

The bucket policy viewer highlights grants with public or cross-account access in plain language — without you needing to parse JSON by hand.

03

The shared credential everyone uses

One IAM key. Five engineers. A contractor. An old CI job that nobody shut down. When something goes wrong, nobody knows who did what — or when.

Storafleet

Storafleet workspaces give each person their own session with the right permission level. No shared keys. Revoke any member instantly. Full audit trail on Business plan.

/// Credential security

Your AWS keys are encrypted. Always.

When you connect an AWS account, your Access Key ID and Secret Access Key are encrypted before they touch our database — using AES-256-GCM with a per-user key derived via HKDF-SHA256. The same algorithm used in TLS 1.3.

Team members who accept your workspace invite operate on your buckets through Storafleet's backend. They never receive, see, or store your AWS credentials. Access is managed by Storafleet session tokens — revocable in one click.

  • AES-256-GCM encryption at rest
  • Per-user derived keys via HKDF-SHA256
  • Never stored in plaintext. Never exposed to the frontend.
  • Team members never see your Access Key or Secret
  • Revoke workspace access instantly — no key rotation needed
AES-256-GCM🔑ENCRYPTEDPER-USER KEYHKDF-SHA256

/// When you'll use this

DevOps Engineer01

Pre-audit security sweep

Your company is undergoing a SOC 2 audit next month. You need to prove no bucket has unintended public access. Storafleet scans all accounts in seconds and gives you the exact list — pass it to your auditor.

Key featureCross-account public access audit

SaaS Founder02

Answering a customer security questionnaire

An enterprise prospect asks: 'How are your S3 credentials secured?' You point to Storafleet's AES-256-GCM vault and per-user key derivation. You also run a quick public bucket check — everything looks clean.

Key featureEncrypted credential vault + public access audit

Platform Engineer03

Sharing a staging artifact with a client

A client needs to download a specific build artifact from staging. Making the bucket public is not an option. You generate a presigned URL with a 4-hour expiry, send it, done. No policy changes, no IAM user created.

Key featurePresigned URL with time-limited expiry

Your storage estate deserves a control plane.

Join the DevOps teams and founders who run every cloud's buckets from one control plane.

Free plan  ·  No credit card  ·  50+ cloud providers  ·  Cancel any time