Redacted copy — read this first

This is a real evidence pack, produced by a real scan of a real AWS account, published so you can see the shape of the output rather than a description of it. The account number, organisation identifiers and IAM principal identifiers have been replaced with synthetic values of the same form.

The hashes below are from the unredacted original and therefore do not verify against this altered copy. They are left in place because they are genuine output and show the real structure — but a redacted document cannot honestly claim its own chain verifies, and this one does not claim it. The original verifies; this copy is an illustration of it.

Evidence pack — 01JEXAMP0RG000000000000000

Period: 2026-08-25 00:00:00 UTC to 2026-08-27 00:00:00 UTC (inclusive of the start, exclusive of the end)
Framework: soc2
Connections in scope: 01JEXAMPCNN000000000000000

Ledger verification

Coverage disclosure

Every scan segment recorded in this period completed.

Control status

ControlIn-scope resource typesStatus
configuration_changes_are_detectedconfig.recorderViolation(s) observed during this period.
console_users_have_mfaiam.userContinuously compliant.
database_storage_encrypted_at_restrds.instanceContinuously compliant.
deployed_artifacts_are_immutableecr.repository, ecs.task_definitionContinuously compliant.
detected_anomalies_reach_an_ownercloudwatch.alarmContinuously compliant.
iam_no_unrestricted_administrative_accessiam.group, iam.policy, iam.role, iam.userViolation(s) observed during this period.
object_storage_encrypted_at_rests3.bucketContinuously compliant.
s3_bucket_not_publicly_accessibles3.bucketContinuously compliant.
tls_listeners_reject_obsolete_protocolselasticloadbalancing.listenerContinuously compliant.

Findings detail

06a7d506eb1b06feae4daa65cdc5ab506de644f734f0302e6497cc936264406f

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0009XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

167b07a7cea452a25c2e5789e8730a070bea3ec7454598e3fbdbd7bf0af57413

Resource type: iam.user   Kind: control_failure   Field: attached_policy_arns   Control: iam_no_unrestricted_administrative_access
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.user:AIDAEXAMPLE0000XXXXXX

TimestampEventDetail
2026-08-25 19:14:57 UTCfinding_created

36b7a7cfca0444e2a25b26d173e67cf446e40995ca29f821c3856e05716e9557

Resource type: iam.access_key   Kind: contract_violation   Field: last_used_date   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.access_key:AKIAEXAMPLE0001XXXXX

TimestampEventDetail
2026-08-25 19:15:18 UTCfinding_created

4618623e9ef24f1f4a61c5ddbb011a35296e726cfc21290622ba77eedaadba38

Resource type: config.recorder   Kind: control_failure   Field: recording   Control: configuration_changes_are_detected
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012/us-east-1:config.recorder:us-east-1

TimestampEventDetail
2026-08-25 19:16:14 UTCfinding_created

4a0ce909c46b554f5ca0e76ebf36ad9a218788665ac822a8b4663244005b714a

Resource type: ec2.security_group   Kind: contract_violation   Field: egress_rules   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012/us-east-1:ec2.security_group:sg-0e5a1c7b39f4d2a86

TimestampEventDetail
2026-08-25 19:15:21 UTCfinding_created

582dd906c0c46231dca36f1ffd109c0ce8d373f52c542d7343fa750c4de2316f

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0003XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

68a64fef14f30a0587b7db178342505267a4fef570d9a70e3ef0d138fad031ec

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0006XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

8d83b3e54da9c71006053036dfd8bf0e7114af958de0bc4f84a88642ea17bfb7

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0008XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

9295e3fee3038732aac2bb6390f55727bb41f3fe34da0388c1360f3bcc08d639

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0010XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

9684ea47ea15a4b6d90d70d0e8d759f5d0d68561e72cf08f332bb7b6fdf27553

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0004XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

bd2026d96e64001e687798afbbfa2bd9a8d313cb5f1a0278c74093eb534e0372

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0005XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

cb8bc1a69c6884f3ecf6bd4fdc547c6685540d8b2d1b30801c06a65232974a8f

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0012XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

d77f7ca3f92be30d0bdabccec48496faa616ae76e4d2b1b2facff990880b3f20

Resource type: ec2.security_group   Kind: contract_violation   Field: ingress_rules   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012/us-east-1:ec2.security_group:sg-0e5a1c7b39f4d2a86

TimestampEventDetail
2026-08-25 19:15:21 UTCfinding_created

e12149e45c291f5a01357a17308b5f5ecf929f3dbef528ecbe56033d95c0c62d

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0002XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

e1c4fb8e8e0314c42a37a32c2c335e1f755b8d23ae3722e894163c00daaf1f9f

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0007XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

f632397e1e901350f51af73c6485d14019a3e2f0771831fc39d2c67d89f44eb5

Resource type: iam.user   Kind: contract_violation   Field: mfa_devices_active   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.user:AIDAEXAMPLE0000XXXXXX

TimestampEventDetail
2026-08-25 19:14:57 UTCfinding_created

f783ecda3559a0d05a062727877f645e8c252f51547d85b0092d8fe6747c8f88

Resource type: iam.role   Kind: contract_violation   Field: max_session_duration   Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0011XXXXXX

TimestampEventDetail
2026-08-25 19:15:13 UTCfinding_created

Control-mapping table used

Shipped verbatim so the derivations above can be re-run independently. Not filtered to this pack's framework — this is the whole table Assemble was given.

Controls

IDDescriptionCitations
object_storage_encrypted_at_restData stored in an object storage service is encrypted at rest, using either a provider-managed or customer-managed encryption key.soc2 CC6.6 (pending-review)
database_storage_encrypted_at_restData stored in a managed database instance is encrypted at rest, using either a provider-managed or customer-managed encryption key.soc2 CC6.6 (pending-review)
s3_bucket_not_publicly_accessibleAn S3 bucket's own policy does not grant access to everyone on the internet. A statement whose effect would otherwise be a public grant, but carries a Condition or a NotPrincipal, is not evaluated -- AXON does not interpret condition keys or NotPrincipal semantics and reports those as indeterminate rather than guessing. This control does not see the account-level S3 Block Public Access setting (a separate resource, s3.account_public_access_block) or object ACLs -- neither is joined here.soc2 CC6.1 (pending-review)
console_users_have_mfaEvery IAM user who can sign in to the AWS Management Console (has a login profile) has at least one active MFA device. A programmatic-only user with no console password is not evaluated by this control -- it has no business carrying an MFA device. This control does not see the AWS account root user (not an IAM user, not ingested), the account password policy, or access key rotation -- none are joined here.soc2 CC6.2 (pending-review)
iam_no_unrestricted_administrative_accessNo IAM identity (user, role, group or customer-managed policy) is granted unrestricted administrative access -- an Allow statement whose Action and Resource are both the literal wildcard "*", found in a stored policy document or an inline policy, or the AWS-managed AdministratorAccess policy attached by reference. This is NOT a least-privilege analysis: a narrower-but-still-broad grant (s3:* scoped to one bucket, a role that happens to be justified) is out of scope and never flagged. AWS service-linked roles (path beginning /aws-service-role/) pass unconditionally -- the customer did not create them and cannot modify them. This control does not see AWS-managed policy documents other than AdministratorAccess by exact ARN (their content is never stored), non-default policy versions, permission boundaries, SCPs, or group-inherited permissions on the member user.soc2 CC6.3 (pending-review)
tls_listeners_reject_obsolete_protocolsNo load-balancer listener negotiates TLS 1.0 or TLS 1.1 -- an HTTPS or TLS listener's own resolved SSL policy protocol list must never contain TLSv1 or TLSv1.1. A listener whose protocol is not HTTPS or TLS (HTTP, TCP, UDP, TCP_UDP, GENEVE) has no TLS policy at all and is out of scope, never flagged. A listener whose policy name this codebase does not recognise is indeterminate, never a pass -- an unfamiliar name is not evidence of a modern policy. This control does not see certificate expiry (needs a clock, which internal/controls may never read), cipher suites (the protocol list says nothing about which ciphers a policy permits), whether the load balancer is internet-facing (an internal listener permitting TLS 1.0 still fails), or CloudFront/API Gateway/any other TLS terminator (a different resource type with its own field, not joined here).soc2 CC6.7 (pending-review)
configuration_changes_are_detectedAWS Config is actively recording configuration changes in every scanned region -- a configuration recorder exists and its own recording status is true. This control does NOT see CloudTrail, which records WHO made a change (AXON has no CloudTrail adapter at all -- Config only records WHAT changed); whether anyone reads or acts on the detections it records (a separate control); Config rules (config.rule is a different question -- a recorder with zero rules still records changes); delivery-channel health beyond the recorder's own last-delivery status; a narrow-scope recorder that records only an explicitly-listed subset of resource types (a real customer configuration whose serialised shape is not independently measured); or any region AXON does not scan at all.soc2 CC7.1 (pending-review)
detected_anomalies_reach_an_ownerA CloudWatch alarm that transitions to ALARM can actually notify someone: its own actions are enabled, and at least one action (an SNS topic, an Auto Scaling policy, or another target) is configured to fire. This control evaluates every metric alarm the account has; it does NOT judge whether the account has adequate monitoring coverage for the resources it runs, and an account with zero alarms produces zero findings from this control. This control does NOT see whether an SNS topic named in alarm_actions has any subscribers -- a different resource AXON does not ingest, and an alarm firing into an empty topic passes this control; whether the alarm's own threshold is sensible (not judgeable from configuration alone); whether a human actually reads a delivered notification; composite alarms (a structurally different SDK type, not ingested under this resource type); or other detection sources such as CloudTrail, GuardDuty or Security Hub, none of which AXON ingests.soc2 CC7.2 (pending-review)
deployed_artifacts_are_immutableWhat runs in production cannot change identity without a new, recorded version. This control does NOT see who approved a change -- that needs CloudTrail plus a ticketing system, neither of which AXON ingests -- nor whether a git repository, a pull-request review, or any approval process exists at all; it also does not see Lambda functions, EC2 AMIs, or any other deployable artifact besides these two AWS resource types; whether the digest a task definition pins actually points at a GOOD image (immutable and vulnerable is still immutable); ecr.repository's own registry-level scanning configuration, which is a different API and is not ingested; or repositories in another account that a task definition's image string names -- that string is not resolved against AXON's own observed resources. Within that scope: an ECR repository whose image tags are not exactly IMMUTABLE fails, because anyone with push rights can later make an already-approved tag resolve to different code; an ECS task definition whose container pins a mutable tag rather than a content digest fails for the identical reason, regardless of how the tag is spelled -- a semver-looking tag is exactly as overwritable as "latest".soc2 CC8.1 (pending-review)

Rules

Resource typeFinding kindFieldControl
s3.bucketcontract_violationencryptionobject_storage_encrypted_at_rest
s3.bucketcontrol_failureencryptionobject_storage_encrypted_at_rest
rds.instancecontract_violationstorage_encrypteddatabase_storage_encrypted_at_rest
rds.instancecontrol_failurestorage_encrypteddatabase_storage_encrypted_at_rest
s3.bucketcontrol_failurepolicys3_bucket_not_publicly_accessible
iam.usercontrol_failuremfa_devices_activeconsole_users_have_mfa
iam.policycontrol_failuredocumentiam_no_unrestricted_administrative_access
iam.usercontrol_failureattached_policy_arnsiam_no_unrestricted_administrative_access
iam.usercontrol_failureinline_policiesiam_no_unrestricted_administrative_access
iam.rolecontrol_failureattached_policy_arnsiam_no_unrestricted_administrative_access
iam.rolecontrol_failureinline_policiesiam_no_unrestricted_administrative_access
iam.groupcontrol_failureattached_policy_arnsiam_no_unrestricted_administrative_access
iam.groupcontrol_failureinline_policiesiam_no_unrestricted_administrative_access
elasticloadbalancing.listenercontrol_failuressl_policy_protocolstls_listeners_reject_obsolete_protocols
config.recordercontrol_failurerecordingconfiguration_changes_are_detected
cloudwatch.alarmcontrol_failureactions_enableddetected_anomalies_reach_an_owner
cloudwatch.alarmcontrol_failurealarm_actionsdetected_anomalies_reach_an_owner
ecr.repositorycontrol_failureimage_tag_mutabilitydeployed_artifacts_are_immutable
ecs.task_definitioncontrol_failurecontainersdeployed_artifacts_are_immutable