Done Dynamics performs cloud security audits and hardening work: enumerating the existing
cloud account, finding misconfigurations, simplifying the identity and permission
structure, secrets management, logging and monitoring design, backup verification, and clarifying data
residency for compliance purposes. The work is not tied to a single provider; the same control set is
applied on AWS, Cloudflare, Hetzner, Google Cloud and comparable platforms.
The starting point of this page is the shared responsibility model. The cloud provider protects the data
centre, the hardware and the virtualisation layer — and that side is genuinely done well. But which resource
in your account faces the internet, who can reach what, whether the data is encrypted and where the keys
live all stay with you. This is where we meet the most common misunderstanding in the field: the sentence
"it is in the cloud, so it is safe" treats a responsibility that was never handed over as if it had been.
The audit runs with read-only permissions, production is not touched, and the output is a finding list
ordered by severity. The work can run as part of a broader
cyber security
engagement or on its own; when it is planned alongside the hosting layer it is consolidated with
hosting services
into the same document.