Posture, spend & inventory
Overall posture
health score · vs. last month
Solid posture trending up. Close the resilience gaps (Multi-AZ, server EDR) and finish SOC 2 to reach an A.
Why this grade: 1 critical and 3 high findings are the main drag — clearing the criticals lifts the grade fastest.
2 critical findings open, down from 5 last month.
Single-AZ database and inference fleet without autoscaling.
92% MFA, 85% on SSO; 5 stale accounts to clean up.
SOC 2 Type II 78% ready; ISO 27001 not yet started.
Jamf + Jamf Protect on Macs; a few unencrypted/no-EDR.
Spend tracking ~8% under last month; GPU is top driver.
Not enterprise-ready
4
Spend (MTD)
$38,271
Cloud resources
147
Devices compliant
20%
Servers compliant
20%
Public-facing servers
3
Entra app hygiene — retiring what isn't used.
The highest-exposure findings, ranked by severity, internet reach, data sensitivity, privileged access & age.
AWS::EC2::Instance · ga-inference-gpu-01 · us-east-1
AWS::EC2::Volume · ga-data-pipeline-01 · us-west-2
AWS::RDS::DBInstance · ga-app-db · us-east-1
container.googleapis.com/NodePool · ga-data-gke · us-central1
AWS::S3::Bucket · gatherai-model-artifacts · us-east-1
Audit readiness across the frameworks that matter to the business.
71/91 controls · Observation window closes Sep 2026
13/114 controls · Scoping planned Q4 2026
47/56 controls · audited Jun 1, 2026 · Remediate 9 medium controls
Who can get in, and how well that access is controlled.
Update posture across cloud services, user devices, and servers.
0 of 5servers assessed — Azure & on-prem via Update Manager (Arc), AWS via Systems Manager Patch Manager. 5 not yet assessed (enable a periodic assessment / patch baseline scan).
Can we get the business back if something fails?
Last successful backup Jun 27, 2026.
The human layer — training and phishing resilience.
Critical & high-severity alerts from endpoint security and watched Teams channels.
Jamf Protect flagged and quarantined a known-malicious binary on mbp-ml-07 (Jamf Protect). Awaiting analyst review.
Jamf Protect analytic tripped: Gatekeeper disabled on mbp-eng-14, allowing unsigned apps to run (Jamf Protect). Remediation policy queued.
Tickets your team manages in GASD.
Monitored workloads and your key services — live uptime and vendor status pages.
Findings, spend & resources across connected clouds.
Production inference runs on standalone GPU EC2 instances with no Auto Scaling Group. Capacity can't track demand and a failed instance isn't replaced automatically.
Fix: Move inference behind an ALB + Auto Scaling Group (or managed endpoint) with target-tracking on GPU utilization.
AWS::EC2::Instance · ga-inference-gpu-01 · us-east-1
since 2026-05-14
Primary application database is single-AZ. A zone outage takes the API down with no automated failover.
Fix: Enable Multi-AZ and confirm automated backups + PITR retain 14+ days.
AWS::RDS::DBInstance · ga-app-db · us-east-1
since 2026-05-20
A staging data-pipeline EC2 host has unencrypted EBS volumes, failing the encryption-everywhere baseline.
Fix: Re-create volumes as KMS-encrypted and enable EBS encryption-by-default on the account.
AWS::EC2::Volume · ga-data-pipeline-01 · us-west-2
since 2026-05-30
The bucket holding trained model artifacts has no versioning or lifecycle policy — no protection against overwrite and unbounded storage growth.
Fix: Enable versioning + a lifecycle policy transitioning old artifacts to IA/Glacier.
AWS::S3::Bucket · gatherai-model-artifacts · us-east-1
since 2026-06-01
A production web app runs on a Basic App Service Plan — no autoscale, no deployment slots, no zone redundancy.
Fix: Move to Premium v3 with autoscale rules and a staging slot for zero-downtime deploys.
Microsoft.Web/sites · app-gatherai-web · eastus
since 2026-06-10
The data-pipeline GKE cluster runs a fixed-size node pool with cluster autoscaler disabled — batch jobs queue at peak and idle capacity is paid for off-peak.
Fix: Enable cluster autoscaler on the node pool (min/max) and set workload resource requests so it can scale on demand.
container.googleapis.com/NodePool · ga-data-gke · us-central1
since 2026-06-15
The pipeline metadata Cloud SQL instance is zonal (single zone) with no HA failover replica — a zone outage means downtime and possible data loss.
Fix: Switch to a regional (HA) Cloud SQL configuration and verify automated backups + PITR.
sqladmin.googleapis.com/Instance · ga-pipeline-meta · us-central1
since 2026-06-19
vs $33,180 last month (-27%)
vs $5,641 last month (-27%)
vs $13,421 last month (-27%)
Active endpoints from Intune & Jamf (seen in the last 30 days), grouped by device class — encryption, EDR coverage, and patch status.
| Device | User | OS | MDM | Encrypted | EDR | Updated | Last seen |
|---|---|---|---|---|---|---|---|
GA-MBP-ENG-014 C02XADBMA1 | a.shah@gather.ai | macOS 15.5 | Jamf | FileVault: yes FileVault | EDR: yes Jamf Protect | Updated: yes | today |
GA-MBP-ML-007 C02ZZ9KCLVDQ | r.iyer@gather.ai | macOS 15.4 | Jamf | FileVault: yes FileVault | EDR: yes Jamf Protect | Updated: no | 3d ago |
GA-MBP-OPS-021 C02GH4LMQ6L4 | j.nguyen@gather.ai | macOS 14.4 | Jamf | Encrypted: no | EDR: yes Jamf Protect | Updated: no | 12d ago |
GA-MBP-SALES-003 C02DJ2ABFH00 | m.gomez@gather.ai | macOS 15.5 | Jamf | FileVault: yes FileVault | EDR: no | Updated: yes | 1d ago |
| Device | User | OS | MDM | Encrypted | EDR | Updated | Last seen |
|---|---|---|---|---|---|---|---|
GA-IPAD-FIELD-09 | field-kit-09@gather.ai | iPadOS 18.5 | Jamf | Data Protection: yes Data Protection | EDR: unknown | Updated: yes | 4d ago |
Cloud & on-prem hosts by environment — encryption, EDR, patch status, and public exposure.
| Host | OS | Env | Encrypted | EDR | Updated | Public IP(s) |
|---|---|---|---|---|---|---|
ga-api-prod-01 us-east-1 | Amazon Linux 2023 | prod | EBS KMS: yes EBS KMS | EDR: no | Updated: yes | none |
ga-inference-gpu-01 us-east-1 | Ubuntu 22.04 LTS | prod | EBS KMS: yes EBS KMS | EDR: no | Updated: yes | 54.210.18.44 |
ga-inference-gpu-02 us-east-1 | Ubuntu 22.04 LTS | prod | EBS KMS: yes EBS KMS | EDR: no | Updated: no | 54.210.18.45 |
ga-data-pipeline-01 us-west-2 | Ubuntu 20.04 LTS | staging | Encrypted: no | EDR: no | Updated: no | none |
| Host | OS | Env | Encrypted | EDR | Updated | Public IP(s) |
|---|---|---|---|---|---|---|
ga-web-azure-01 eastus | Ubuntu 22.04 LTS | prod | Azure Disk Encryption: yes Azure Disk Encryption | EDR: yes Microsoft Defender | Updated: yes | 20.84.112.9 |
How each workload is wired across AWS, Azure & GCP — internet-facing entry points down to data services.