Find AWS security risks before attackers do.

GoNinja is a read-only security & compliance scanner for AWS. Connect in minutes, get prioritized findings mapped to CIS, SOC 2 and PCI-DSS, and board-ready reports โ€” now with AI agent & shadow-AI discovery and internet-exposure analysis, daily monitoring, and an alert the moment something new appears.

โ— No credit card โ— Read-only access โ— Data stays in AWS Sydney
CIS AWS Foundations SOC 2 PCI-DSS v4.0 Essential Eight Amazon Web Services
Features

Everything you need to prove your AWS is secure

Built for teams who want clear answers, not another dashboard to babysit.

๐Ÿ”Ž

Multi-region scanning

Checks IAM, S3, EC2, RDS, CloudTrail and GuardDuty across every enabled AWS region โ€” read-only, no agents to install.

๐Ÿ“Š

Posture score & grade

A clear 0โ€“100 score and letter grade, with findings ranked by severity and step-by-step remediation.

๐Ÿ“‹

Compliance mappings

Every finding is cross-referenced to CIS AWS Foundations, SOC 2 criteria and PCI-DSS v4.0 to support your audits.

๐Ÿ› ๏ธ

One-click Terraform fixes

Generate ready-to-apply Terraform to remediate findings in your own account โ€” turn a report into a pull request.

๐Ÿ“ก

Continuous monitoring

Automated daily scans at a time you choose, with an email alert the moment a new risk appears.

๐Ÿงพ

Board-ready reports

One-click HTML / PDF reports with an executive summary and compliance coverage โ€” and posture trends over time.

๐Ÿค–

AI agent & shadow-AI discovery NEW

Maps the non-human identities in your account โ€” AI agents, bot users, model API keys โ€” and flags the ones nobody approved: who created them, whether they're over-privileged, and when they last acted.

๐Ÿ”ฅ

Internet exposure analysis NEW

Beyond "port 22 is open": reachability-aware firewall analysis that scores what's actually reachable from the internet โ€” a running workload with a public IP behind the rule โ€” mapped to Essential Eight.

How it works

Connected in minutes

No software to install. No write access. You stay in control.

1

Sign in

Create a free account โ€” no credit card. Your 7-day trial starts instantly.

2

Deploy the read-only role

Download a one-click CloudFormation template, pre-filled with your unique ID, and create the read-only role in your AWS account.

3

Scan & monitor

Run a full scan, review prioritized findings and reports, and switch on daily monitoring.

Security & data residency

The safest thing you'll connect to your cloud

Read-only by design, credential-free, and hosted entirely in Australia.

โœ“Read-only, always. GoNinja uses a cross-account IAM role with AWS's managed SecurityAudit policy. It can never modify, create or delete anything in your account.
โœ“We never see your credentials. No access keys, secrets or passwords are ever sent to or stored by GoNinja. Access is via a role you create, bound to your account with a private external ID.
โœ“Your data stays in Australia. All processing and storage runs in the AWS Asia Pacific (Sydney) region โ€” ap-southeast-2.
โœ“Revoke anytime. Delete the CloudFormation stack and GoNinja's access is removed immediately and permanently.
โœ“Secure sign-in. Authentication via Amazon Cognito with optional two-factor authentication.

Read our full Privacy & Data Policy โ†’

Pricing

Simple, honest pricing

Start free. Upgrade when you're ready. Cancel anytime.

GoNinja
$9.95 / user / month
  • Unlimited scans across all AWS regions
  • Continuous monitoring & drift alerts
  • CIS / SOC 2 / PCI-DSS mapped findings
  • AI agent & shadow-AI discovery
  • Internet exposure analysis (Essential Eight)
  • One-click Terraform remediation
  • Board-ready reports & posture trends
  • Email support
Start your 7-day free trial

No credit card required to start.

See your AWS security posture today

Minutes to set up. Read-only. Free for 7 days.