AWS and Source CodeFree Security AssessmentNot just the issues, but how to fix them and what it costs.
With cyberattacks making headlines one after another, is your system really protected?
After signing an NDA, we review your source code and AWS with read-only access
and deliver the results as a report.
Does this sound familiar?
Your system has not been updated in years
You worry that your programming language or framework is no longer supported.
You rely entirely on your development vendor
They say everything is fine, but you have no way to verify it.
A business partner asked about your security
You received a security checklist but cannot answer it with confidence.
Your AWS bill seems too high
You have never checked for unused resources or oversized servers.
If any of these apply,
start by understanding where you stand.
What the assessment reveals
Security
We read both your AWS configuration and your source code to find weaknesses that could lead to attacks or data leaks.
- Permissions that are too broad or shared with other systems
- Databases or admin screens exposed to the internet
- Whether databases and backups are encrypted
- Whether operation and access logs are kept for an appropriate period
- Whether attack protection (WAF) and threat detection are working
- Long-lived access keys with powerful permissions
- Passwords or keys written into the code
- Libraries with known vulnerabilities or ended support
- Whether users can see other users' data
- Login strength (password length, lockout, automatic logout)
- Input weaknesses such as SQL injection and XSS
- Personal data left in logs, external services, or other unexpected places
AWS costs
Oversized servers, resources billed but unused, and room for discount plans. We show the estimated monthly savings.
Database performance
We point out processing that slows down your pages and improvements based on database usage.
品質責任者:西川 雄三(AWS認定 Security – Specialty)
- セキュリティ
- 外部から他の会員のデータを見られる穴は見つかりませんでした。一方で、ログイン用の暗号鍵がプログラムに書かれており、管理者になりすませる状態です。最優先で対応をおすすめします。
- 運用コスト
- 削減見込み 月 約7.6万円(年 約91万円)。最も大きいのは、サポートが終わったデータベースに課金されている延長サポート料金です。
- 性能
- 予約一覧と会員一覧の表示が遅くなる原因になっている処理を3か所確認しました。データ量が増えるほど遅くなる作りです。
| # | 指摘 | 確認 | 起こり得ること | 対応 |
|---|---|---|---|---|
| 1 | ログイン状態を守る暗号鍵が、プログラムの設定例ファイルに書かれている | 実測 | プログラムを見られる人が、ログイン情報を偽造し、管理者を含む誰にでもなりすませる | 暗号鍵を新しいものに入れ替える。設定例ファイルにはダミー値を書く |
| 2 | アプリの実行権限が他のシステムと共用で、ファイル保管庫(S3)と設定値保管庫の全権限が付いている | 実測 | アプリの弱点が1つ突かれると、他のシステムの機密値やファイルまで読み書きされる | このシステム専用の権限を作り、必要な操作だけに絞る |
| 3 | 本番のログに、会員の氏名・電話番号・メールアドレスがそのまま記録され、保管期間の上限がない | 実測 | ログを見られる人が個人情報をまとめて取得できる。ログが溜まり続ける | ログに残す項目を絞る。保管期間を90〜180日に設定する |
* The company, system, and figures are fictional. Reports are written in Japanese for your system.
Each finding is labeled as confirmed, inferred from the code, or not checked.
We can fix
what we find
A common problem is receiving a report from an assessment company and then having no one to fix the issues.
System development and operations are our core business, so we can carry out the fixes in the report ourselves.
Find
The free assessment reports the issues, how to fix them, and the cost.
Fix
We fix and update only the items you order.
Protect
Monthly maintenance keeps your system updated and regularly checked.
You can choose what to order, item by item, after reading the report.
How we protect your information
Because we handle your source code and AWS information, we make clear how we treat it.
We sign a non-disclosure agreement (NDA) first
The scope, period, method, and data deletion are written into the agreement, and the assessment starts only after it is signed. The agreement is in Japanese.
We use read-only access only
You run a configuration file we provide once in your AWS account to create read-only access. When the assessment ends, deleting that configuration removes our access. This access cannot read password or key values, or the contents of your database.
We change neither settings nor data
We do not change system settings, connect to your database, or run attack tests. You can use your system as usual.
About our use of generative AI
We use generative AI (Claude by Anthropic) under commercial terms for business use, so your information is not used to train the AI. Our staff always review the AI's findings before writing the report.
We delete your data within 90 days of the report
Copies of your code and records made for the assessment are deleted within 90 days of delivering the report, and we confirm the deletion on request.
How it works
Depends on the consultation schedule and the size of your system.
Free consultation
In an online meeting (30–60 minutes, in Japanese), we hear about your concerns and system. We do not ask for confidential information at this stage.
Sign the NDA
Signed electronically via the CloudSign e-contract service.
Preparation
Please create the read-only access and grant read access to your source code.
Assessment
Depending on the size of your system, we assess it over 1–3 business days.
Report and quote
We explain the report (in Japanese) and provide a quote for the fixes.
Decide whether to order anything after reading the report.
Our team
- Quality lead
- Yuzo NishikawaCTO / AWS Certified Security – SpecialtyReviews every report before delivery
- Your contact
- Takeshi MinamiRepresentative Director / AWS Certified Solutions Architect – ProfessionalHandles everything from the free consultation to the proposal
- AWS Partner (Select Tier)
- ISMS (ISO/IEC 27001) certified company
- Track record in developing, renewing, and maintaining web systems such as Ruby on Rails
MOOBON, Inc. (Toshima-ku, Tokyo; founded 2016). Contract development, AWS operations, and DX support.Company profile
Pricing
- Consultation, NDA, assessment, and report
- Free
- Follow-up work (fixes, updates, maintenance)
- Quoted in the report
There is no charge if you decline after the assessment.
Frequently asked questions
Q.Do you support English?
All meetings, the NDA, emails, and reports are in Japanese only. If you need English, please use a translation tool or interpreter on your side.
Q.Is it really free? Do we have to order anything afterwards?
The consultation, NDA, assessment, and report are all free. You are free to decline after reading the report. We offer this for free because we hope it leads to fixes or maintenance work.
Q.How long does it take?
About one week at the earliest from your application to the report. It depends on the consultation schedule and the size of your system.
Q.What do we need to prepare?
Read-only access to AWS and read access to your source code. For AWS, you only run a configuration file we provide once, which takes about 30 minutes. We will guide you through the steps.
Q.You use generative AI. Is our information safe?
We use Claude by Anthropic under commercial terms for business use, so your information is not used to train the AI. These conditions are also written into the NDA. Our staff always review the AI's findings, and information obtained in the assessment is deleted within 90 days of the report.
Q.Do you run attack tests (penetration testing)?
No. We review your configuration and source code by reading them.
Q.Can we use our system during the assessment?
Yes. We only read, and change neither settings nor data, so you can use your system as usual.
Q.Which systems do you cover?
Systems running on AWS built with Ruby on Rails, PHP (Laravel, WordPress), or JavaScript/TypeScript (such as Next.js). We currently do not accept environments other than AWS.
Q.Will you find every issue?
The assessment finds the major issues within a limited number of days. We do not guarantee that every issue will be found. Anything we could not check is stated in the report.
Q.Why only 5 companies per month?
Each assessment takes 1–3 business days, and our quality lead reviews every report. We limit the number to maintain quality. Depending on applications, the first meeting may be scheduled for the following month or later.
Apply for a free consultation
We accept up to 5 companies per month.
We usually contact you within 2 business days to arrange a date.
* Depending on applications, the first meeting may be scheduled for the following month or later.
* All meetings, the NDA, emails, and reports are in Japanese only.
