iam
Safeguard articles tagged "iam" — guides, analysis, and best practices for software supply chain and application security.
47 articles
Public Cloud Computing Security: Architecture and Practices
Public cloud computing security comes down to one idea that teams keep relearning the hard way: the provider secures the cloud, but you secure what you put in it.
AWS Permission Boundary: How to Cap IAM Privileges Safely
An AWS permission boundary sets the maximum permissions an IAM identity can ever have. Here is how boundaries work, when to use them, and the mistakes that quietly defeat them.
How to Secure the Public Cloud: A Practical Guide
The public cloud can be secured well, and often more securely than a self-run data center. The catch is the shared responsibility model, where most breaches actually originate.
AWS Hack: How Attackers Break Into AWS and How to Stop Them
Most AWS breaches don't start with a clever exploit. They start with a leaked key or a misconfigured bucket. Here is how an AWS hack actually unfolds and how to shut down each step.
Public Cloud Protection: Securing Workloads Across AWS, Azure, and GCP
Public cloud protection starts with the shared responsibility model and ends with the boring controls that stop most breaches: identity, configuration, and visibility.
AWS Service-Linked Role Abuse Techniques, 2025
Service-linked roles are the soft underbelly of AWS IAM. We catalogue the 2024-2025 abuse primitives and the detection queries that catch them.
AWS DevOps Security Best Practices: A Practical Guide
The AWS DevOps security best practices that matter most are least-privilege IAM, immutable pipelines, and shifting scanning left into CI. Here is how to apply them without slowing delivery.
How to Secure Cloud Applications: A Practical Guide
Securing cloud applications means protecting the code, the dependencies, the identities, and the runtime together. Here is a practical way to think about all four.
Public Cloud Security: A Practical Guide to Protecting Workloads
Public cloud security is a shared responsibility, and most breaches trace back to the customer's half of that split rather than a failure by the cloud provider.
AWS IAM Roles Anywhere and the Supply Chain
IAM Roles Anywhere lets workloads outside AWS assume IAM roles using X.509 certificates. It is also becoming the authentication layer for supply chain tools. Here is what the threat model looks like.
AWS Step Functions Workflow Security
Step Functions workflows orchestrate everything from data pipelines to security automations. The workflow IAM role is almost always the most powerful thing in the stack. Here is how to lock it down.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.