FEATURES / Security
/// Security
Understand your exposure. Enforce your policies.
Audit public access settings across every bucket. Inspect bucket policies and IAM permissions. Generate time-limited presigned URLs. Built for teams that take storage security seriously.
Start for freeYour entire S3 posture. One view. Every account.
/// How it works
Connect your accounts
Add credentials for all your AWS accounts. Storafleet scans Public Access Block settings, bucket policies, and IAM permissions across every bucket.
Audit your exposure
The security dashboard surfaces every misconfiguration: public buckets, wildcard policies, and over-permissioned credentials — all in one view.
Share objects securely
Generate time-limited presigned URLs for any object. Set expiry. Copy link. No bucket policy changes, no public access required.
Public access audit
See which buckets have public access enabled — intentionally or not. Flag misconfigurations across all your accounts in one view.
Bucket policy viewer
Read raw bucket policy JSON. Storafleet highlights grants that permit public access or cross-account access so you don't miss them.
IAM permission checker
Verify what your connected credentials can actually do on each bucket. Understand effective permissions before you hit an access denied.
AES-256-GCM credential storage
Your AWS Access Keys and Secrets are encrypted at rest using AES-256-GCM with a per-user derived key. Never stored in plaintext. Never shared.
Presigned URLs with expiry control
Share any object securely with a time-limited presigned URL. Set expiry from minutes to days. No bucket policy changes. No public access.
CORS configuration viewer
View CORS rules per bucket. Understand which origins have cross-origin access to your objects — useful when debugging web app S3 integrations.
/// Without Storafleet
Security misconfigurations in S3 are invisible until something breaks — or gets breached.
- Check public access settings by clicking through each bucket individually
- Bucket policies are JSON nobody re-reads after initial setup
- No unified view of what your credentials can actually do across all buckets
- Sharing a file means making it public (permanent) or 3+ Console clicks per object
- CORS misconfigurations discovered during production browser debugging
/// With Storafleet
A security audit dashboard across all accounts. Misconfigurations surface in seconds.
- Public access audit across all accounts in one dashboard view
- Bucket policy viewer highlights dangerous grants without you parsing raw JSON
- IAM permission checker shows effective permissions per bucket
- One-click presigned URL with expiry control — no public access ever needed
- CORS viewer per bucket — understand cross-origin rules instantly
/// Common S3 security failures
The three misconfigurations we see most.
The public bucket you forgot about
Created in 2022 for a one-off asset share. Public Access Block never set. Still sitting there, fully readable by anyone with the URL — or a scanner.
Storafleet flags every bucket with public access enabled across all connected accounts. One view, zero guessing.
The wildcard bucket policy from 2019
Resource: "*", Principal: "*", Effect: Allow. Written during a late-night incident. Nobody touched it since. It's granting access to more than you think.
The bucket policy viewer highlights grants with public or cross-account access in plain language — without you needing to parse JSON by hand.
The shared credential everyone uses
One IAM key. Five engineers. A contractor. An old CI job that nobody shut down. When something goes wrong, nobody knows who did what — or when.
Storafleet workspaces give each person their own session with the right permission level. No shared keys. Revoke any member instantly. Full audit trail on Business plan.
/// Credential security
Your AWS keys are encrypted. Always.
When you connect an AWS account, your Access Key ID and Secret Access Key are encrypted before they touch our database — using AES-256-GCM with a per-user key derived via HKDF-SHA256. The same algorithm used in TLS 1.3.
Team members who accept your workspace invite operate on your buckets through Storafleet's backend. They never receive, see, or store your AWS credentials. Access is managed by Storafleet session tokens — revocable in one click.
- AES-256-GCM encryption at rest
- Per-user derived keys via HKDF-SHA256
- Never stored in plaintext. Never exposed to the frontend.
- Team members never see your Access Key or Secret
- Revoke workspace access instantly — no key rotation needed
/// When you'll use this
Pre-audit security sweep
Your company is undergoing a SOC 2 audit next month. You need to prove no bucket has unintended public access. Storafleet scans all accounts in seconds and gives you the exact list — pass it to your auditor.
Key featureCross-account public access audit
Answering a customer security questionnaire
An enterprise prospect asks: 'How are your S3 credentials secured?' You point to Storafleet's AES-256-GCM vault and per-user key derivation. You also run a quick public bucket check — everything looks clean.
Key featureEncrypted credential vault + public access audit
Sharing a staging artifact with a client
A client needs to download a specific build artifact from staging. Making the bucket public is not an option. You generate a presigned URL with a 4-hour expiry, send it, done. No policy changes, no IAM user created.
Key featurePresigned URL with time-limited expiry
Your storage estate deserves a control plane.
Join the DevOps teams and founders who run every cloud's buckets from one control plane.
Free plan · No credit card · 50+ cloud providers · Cancel any time