MOOBON
MOOBON Security Team

AWS and Source CodeFree Security AssessmentNot just the issues, but how to fix them and what it costs.

With cyberattacks making headlines one after another, is your system really protected?

After signing an NDA, we review your source code and AWS with read-only access and deliver the results as a report.

For systems running on AWSAfter signing an NDARead-only, no changesUp to 5 companies per monthAll communication in Japanese
Is This You?

Does this sound familiar?

Risk: High

Your system has not been updated in years

You worry that your programming language or framework is no longer supported.

Risk: Medium

You rely entirely on your development vendor

They say everything is fine, but you have no way to verify it.

Risk: Medium

A business partner asked about your security

You received a security checklist but cannot answer it with confidence.

Risk: Low

Your AWS bill seems too high

You have never checked for unused resources or oversized servers.

If any of these apply,
start by understanding where you stand.

What You Get

What the assessment reveals

Security

We read both your AWS configuration and your source code to find weaknesses that could lead to attacks or data leaks.

AWS configuration
  • Permissions that are too broad or shared with other systems
  • Databases or admin screens exposed to the internet
  • Whether databases and backups are encrypted
  • Whether operation and access logs are kept for an appropriate period
  • Whether attack protection (WAF) and threat detection are working
  • Long-lived access keys with powerful permissions
Source code
  • Passwords or keys written into the code
  • Libraries with known vulnerabilities or ended support
  • Whether users can see other users' data
  • Login strength (password length, lockout, automatic logout)
  • Input weaknesses such as SQL injection and XSS
  • Personal data left in logs, external services, or other unexpected places
Along with security, we also report on

AWS costs

Oversized servers, resources billed but unused, and room for discount plans. We show the estimated monthly savings.

Database performance

We point out processing that slows down your pages and improvements based on database usage.

Sample report (excerpt, in Japanese)
SAMPLE ── 架空のシステムを想定したサンプル報告書です
株式会社サンプル 御中
株式会社MOOBON
品質責任者:西川 雄三(AWS認定 Security – Specialty)
会員予約管理システム 調査報告書
セキュリティ・運用コスト・性能
1. 結論
セキュリティ
外部から他の会員のデータを見られる穴は見つかりませんでした。一方で、ログイン用の暗号鍵がプログラムに書かれており、管理者になりすませる状態です。最優先で対応をおすすめします。
運用コスト
削減見込み 月 約7.6万円(年 約91万円)。最も大きいのは、サポートが終わったデータベースに課金されている延長サポート料金です。
性能
予約一覧と会員一覧の表示が遅くなる原因になっている処理を3か所確認しました。データ量が増えるほど遅くなる作りです。
2. セキュリティ
優先度1:すぐに、小さな作業で対応できるもの
#指摘確認起こり得ること対応
1ログイン状態を守る暗号鍵が、プログラムの設定例ファイルに書かれている実測プログラムを見られる人が、ログイン情報を偽造し、管理者を含む誰にでもなりすませる暗号鍵を新しいものに入れ替える。設定例ファイルにはダミー値を書く
2アプリの実行権限が他のシステムと共用で、ファイル保管庫(S3)と設定値保管庫の全権限が付いている実測アプリの弱点が1つ突かれると、他のシステムの機密値やファイルまで読み書きされるこのシステム専用の権限を作り、必要な操作だけに絞る
3本番のログに、会員の氏名・電話番号・メールアドレスがそのまま記録され、保管期間の上限がない実測ログを見られる人が個人情報をまとめて取得できる。ログが溜まり続けるログに残す項目を絞る。保管期間を90〜180日に設定する
── 以下、優先度1の残り2件、優先度2・3、運用コスト、性能、できている点、確認できなかったこと、お見積もり ──

* The company, system, and figures are fictional. Reports are written in Japanese for your system. Each finding is labeled as confirmed, inferred from the code, or not checked.

From Report to Fix

We can fix
what we find

A common problem is receiving a report from an assessment company and then having no one to fix the issues. System development and operations are our core business, so we can carry out the fixes in the report ourselves.

1

Find

Free

The free assessment reports the issues, how to fix them, and the cost.

2

Fix

Only what you choose

We fix and update only the items you order.

3

Protect

If you wish

Monthly maintenance keeps your system updated and regularly checked.

You can choose what to order, item by item, after reading the report.

Your Data, Protected

How we protect your information

Because we handle your source code and AWS information, we make clear how we treat it.

1.

We sign a non-disclosure agreement (NDA) first

The scope, period, method, and data deletion are written into the agreement, and the assessment starts only after it is signed. The agreement is in Japanese.

2.

We use read-only access only

You run a configuration file we provide once in your AWS account to create read-only access. When the assessment ends, deleting that configuration removes our access. This access cannot read password or key values, or the contents of your database.

3.

We change neither settings nor data

We do not change system settings, connect to your database, or run attack tests. You can use your system as usual.

4.

About our use of generative AI

We use generative AI (Claude by Anthropic) under commercial terms for business use, so your information is not used to train the AI. Our staff always review the AI's findings before writing the report.

5.

We delete your data within 90 days of the report

Copies of your code and records made for the assessment are deleted within 90 days of delivering the report, and we confirm the deletion on request.

How It Works

How it works

From application to the assessment report
About 1 week at the earliest

Depends on the consultation schedule and the size of your system.

01

Free consultation

In an online meeting (30–60 minutes, in Japanese), we hear about your concerns and system. We do not ask for confidential information at this stage.

Scheduled with you
02

Sign the NDA

Signed electronically via the CloudSign e-contract service.

2–3 business days
03

Preparation

Please create the read-only access and grant read access to your source code.

About 30 minutes of work
04

Assessment

Depending on the size of your system, we assess it over 1–3 business days.

1–3 business days
05

Report and quote

We explain the report (in Japanese) and provide a quote for the fixes.

2–3 business days after

Decide whether to order anything after reading the report.

Our Team

Our team

Quality lead
Yuzo Nishikawa
CTO / AWS Certified Security – Specialty
Reviews every report before delivery
Your contact
Takeshi Minami
Representative Director / AWS Certified Solutions Architect – Professional
Handles everything from the free consultation to the proposal
  • AWS Partner (Select Tier)
  • ISMS (ISO/IEC 27001) certified company
  • Track record in developing, renewing, and maintaining web systems such as Ruby on Rails

MOOBON, Inc. (Toshima-ku, Tokyo; founded 2016). Contract development, AWS operations, and DX support.Company profile

Pricing

Pricing

Consultation, NDA, assessment, and report
Free
Follow-up work (fixes, updates, maintenance)
Quoted in the report

There is no charge if you decline after the assessment.

FAQ

Frequently asked questions

Q.Do you support English?

All meetings, the NDA, emails, and reports are in Japanese only. If you need English, please use a translation tool or interpreter on your side.

Q.Is it really free? Do we have to order anything afterwards?

The consultation, NDA, assessment, and report are all free. You are free to decline after reading the report. We offer this for free because we hope it leads to fixes or maintenance work.

Q.How long does it take?

About one week at the earliest from your application to the report. It depends on the consultation schedule and the size of your system.

Q.What do we need to prepare?

Read-only access to AWS and read access to your source code. For AWS, you only run a configuration file we provide once, which takes about 30 minutes. We will guide you through the steps.

Q.You use generative AI. Is our information safe?

We use Claude by Anthropic under commercial terms for business use, so your information is not used to train the AI. These conditions are also written into the NDA. Our staff always review the AI's findings, and information obtained in the assessment is deleted within 90 days of the report.

Q.Do you run attack tests (penetration testing)?

No. We review your configuration and source code by reading them.

Q.Can we use our system during the assessment?

Yes. We only read, and change neither settings nor data, so you can use your system as usual.

Q.Which systems do you cover?

Systems running on AWS built with Ruby on Rails, PHP (Laravel, WordPress), or JavaScript/TypeScript (such as Next.js). We currently do not accept environments other than AWS.

Q.Will you find every issue?

The assessment finds the major issues within a limited number of days. We do not guarantee that every issue will be found. Anything we could not check is stated in the report.

Q.Why only 5 companies per month?

Each assessment takes 1–3 business days, and our quality lead reviews every report. We limit the number to maintain quality. Depending on applications, the first meeting may be scheduled for the following month or later.

Apply

Apply for a free consultation

We accept up to 5 companies per month.
We usually contact you within 2 business days to arrange a date.
* Depending on applications, the first meeting may be scheduled for the following month or later.
* All meetings, the NDA, emails, and reports are in Japanese only.

Please use your company email address

We currently accept only systems running on AWS

What concerns you?Optional, multiple choice

We use the information you provide only to respond to your inquiry.Privacy Policy

MOOBONISO/IEC 27001 CertificationAWS Partner Select Tier ServicesKinsta Agency Partner Badge
Copyright © 2026 MOOBON, Inc. All Rights Reserved.
Standard: ISO/IEC 27001:2022
Scope: Web system design support / Development, operation, and maintenance of in-house cloud services / Contract system development, operation, and maintenance / Server construction, operation, and maintenance