Know your AWS risk.Prove you fixed it.

The MSP operating system for AWS — assess posture, decide rebuild vs remediate, govern every change, and deliver proof your board and auditors read. Built by TeckPath, running in production today.

Assess· Decide· Approve· Apply· Prove

Scanning stacks & threats

52 POSTURE SCORE

For founders

Inherited AWS from a contractor or acquihire?

Get a founder-readable assessment — security, topology, DR gaps, and a prioritized fix path — without CIS jargon on page one.

The closed loop

Scanners find problems. Sentinel closes the loop.

Every step is one workflow, from a read only connection to a board ready proof of improvement, with governed remediation in between.

01
Connect
read only role
02
Scan
31 scanners
03
Understand
AI enrichment
04
Decide
rebuild vs fix
05
Approve
dual approval
06
Apply
with rollback
07
Verify
rescan gate
08
Report
proof pack
09
Improve
trend over time

The platform

Five jobs, one operating system for AWS.

Full platform tour →
01

Connect & onboard

Read only IAM role, external ID, preflight permission checks and org wide multi account scans. Five minutes to connect.

02

Assess & scan

31 read only scanners across identity, S3, network, RDS, logging and detection, scheduled, micro scanned, delta compared.

03

Understand

Findings enriched with impact, framework refs and remediation. Posture score, Well Architected lens, MITRE mapping, anomaly detection.

04 · differentiator

Decide

Path A vs B, rebuild TCO, migration waves, DR/RTO and landing zone readiness, the architecture answer scanners skip.

05

Remediate & govern

Propose → approve → apply → verify → rollback. 8 auto apply playbooks, change windows, Halo PSA sync.

06

Prove & report

Proof Pack, QBR, Startup and Architecture assessments. Branded, share linked, 15+ export formats.

Architecture economics

Rebuild or remediate? We answer the question scanners skip.

Two paths, side by side, with a TCO band, migration waves and a landing zone readiness score. So the decision comes with a price tag, not a hunch.

PATH Agreenfield

Rebuild & migrate

Move to a clean landing zone. Highest ceiling, real project cost.

Rebuild TCO band$$$
Migration waves3 phases
Landing zone readiness64%
PATH Bbrownfield

Remediate in place

Fix what you have with governed playbooks. Fastest to a passing posture.

Remediation cost$
Time to passing2 weeks
Auto apply playbooks8 ready
ADR export Strangler fig runbook DR / RTO assessment Network topology export Terraform skeleton

Governed remediation

Every change approved, auditable, and reversible.

MSP safe by design. Fixes move through dual approval and change windows, apply with rollback, and rescan to verify, then sync to Halo PSA as tickets.

8
AUTO APPLY PLAYBOOKS
29
REMEDIATION GUIDES
REMEDIATION LIFECYCLE
ProposedAI drafted fix attached to finding
01
Pending 2nd approvalAwaiting second reviewer
02
ApprovedCleared inside change window
03
AppliedCloudFormation / API change live
04
VerifiedRescan confirms · rollback ready
05

Deliverables

Reports your board reads, not JSON dumps.

15+ export formats · branded · share links
Proof Pack / QBR

Quarterly proof of posture

Branded, narrative + governance, with the score delta that proves improvement quarter over quarter.

Board · CISO · auditors
Architecture Assessment

The migration business case

Path A vs Path B, rebuild TCO, migration waves and landing zone readiness, the decision document.

CTO · architects
Executive summary Compliance matrix CSV Password protected share links SIEM export (NDJSON) White label Evidence hub

Two ways to start

One closed loop. Two ways in.

SENTINEL PLATFORM

Run AWS as a practice

For MSPs and cloud teams. Multi tenant workspaces, portfolio heatmap, white label reports and role scoped API keys, scale delivery without hiring.

Multi tenant isolation & cross-tenant switch
Portfolio improvement rollup
Halo PSA sync · GitHub Action · Terraform
Request a demo
STARTUP ASSESSMENT

Peace of mind in one report

For founders. Connect AWS read only, get a founder ready report on security, network, DR and a roadmap, typically within 24 to 48 hours.

Read only IAM role, one-click deploy
Plain-English report investors trust
Optional governed fixes + rescan to prove it
Get assessed →

For MSPs

Built for MSPs who sell outcomes.

Replace the scanner plus spreadsheet stack with the AWS Cloud Advisor TeckPath runs in production today.

31
AWS security scanners
9
Closed loop phases
80+
Platform services
100%
Read only by default
Capability
Scanner + PSA
Sentinel
Branded QBR / Proof Pack
Manual assembly
One click + share links
Rebuild vs remediate economics
Ad hoc spreadsheets
Architecture paths + TCO
Approval before production change
Ticket queue only
Dual approval + windows
Portfolio across clients
Per account login
MSP heatmap + improvement rollup
Prove remediation to client
Screenshots
Verify after apply + audit trail

Platform security

Read only by default

Cross account IAM role with external ID. You stay in control.

RBAC & MFA

Admin, operator, viewer roles. SSO, TOTP, SCIM provisioning.

Full audit log

Who did what, exportable as NDJSON. Nothing happens unseen.

Hardened deployment

AWS ECS Fargate, Multi-AZ RDS, WAF, data residency pin.

FAQ

Common questions, answered.

Sentinel complements your AWS native detection, it doesn't replace it.

What is TeckPath Sentinel?

TeckPath's AWS Cloud Advisor. It assesses cloud environments, supports governed remediation, and produces Client Proof Packs and QBR reports for stakeholders.

Is Sentinel a replacement for AWS Security Hub?

No. Sentinel complements AWS native detection. It adds MSP workflow, client deliverables, approval governance, and migration consulting layers Security Hub does not provide.

How do customers connect AWS accounts?

A least privilege IAM role with external ID (CloudFormation template provided). Access keys are supported but de emphasized. Scans are read only by default; remediation requires explicit tenant opt in.

Can we white label reports for clients?

Yes. tenant branding (logo, accent, display name) flows into QBR, executive exports, and Proof Pack share links.

Your AWS posture, explained to your board.

Connect read only today. Governed fixes when you're ready. Proof your stakeholders can read.