Skip to content
Refine

Product · AWS Advanced Tier Services Partner

Find 380+ AWS security risks. Know exactly how to fix each one.

IAM, storage, network, compute, and logging — checked across every region of every connected account. Severity-tiered, AI-narrated, and every finding carries the AWS Console steps that close it.

  • 380+ Checks

    Catalog below

  • 15+ Regions

    Auto-discovered

  • Fix Guides

    Console steps + AWS doc

  • AI Commentary

    On every finding

Refine's Security Findings page: 8 critical, 73 high, 200 medium and 21 low findings, with each finding naming the resource, the region and a fix
302 findings on one account — 8 critical, 73 high, 200 medium, 21 low — as Refine found them, not a tidied example. Every row names the resource and region; 'Fix available' means Refine has a remediation guide for it, with console steps and the AWS doc — the change itself stays yours to make. Filter by severity, category, region or resource type.

The 380+ Checks Catalog

Five categories × four severities. A sample of representative checks per cell — the full catalog ships with the product.

CriticalHighMediumLow

"Fix Available" — the steps, not a ticket

A finding that tells you something is wrong and stops there is a to-do, not a fix. Where Refine holds a vetted remediation for a check, the finding carries a Fix Available badge and opens the numbered AWS Console steps that close it — for that resource, in that region.

  • Numbered AWS Console steps, in order, with the official AWS documentation linked at the end
  • Scoped to the finding: the resource ID, resource type and region are on the row you are reading
  • Where the scan returns its own remediation, those steps are shown instead of the curated guide
  • Your IAM role stays read-only. Refine never writes to your AWS account — you apply the change, and you can revoke access at any time

Findings we hold no guide for say so plainly rather than showing an empty panel.

Example finding

Block Public Access to S3 Bucket

acme-prod-logs · s3 · us-east-1

High

How to Fix This (AWS Console Steps)

  1. 1.Open AWS Console and navigate to S3 service
  2. 2.Find and click on the bucket name from the list
  3. 3.Click on "Permissions" tab
  4. 4.Scroll to "Block public access (bucket settings)" section

…5 more steps

View Official AWS Documentation

Multi-Region Coverage

Refine auto-discovers active regions in each connected account and scans them. Findings are tagged with the region so multi-region orgs can route by ownership.

us-east-1

N. Virginia

us-east-2

Ohio

us-west-1

N. California

us-west-2

Oregon

ca-central-1

Central Canada

eu-central-1

Frankfurt

eu-west-1

Ireland

eu-west-2

London

eu-north-1

Stockholm

ap-south-1

Mumbai

ap-south-2

Hyderabad

ap-southeast-1

Singapore

ap-southeast-2

Sydney

ap-northeast-1

Tokyo

ap-northeast-2

Seoul

sa-east-1

São Paulo

global

Global services

Security Score

A single 0–100 number that tracks posture trend. Same calibration as the Optimization Score next to it.

Inputs:
All active findings, weighted by severity.
Weighting:
Critical 8× · High 4× · Medium 2× · Low 1×.
Trend:
30-day rolling window with daily snapshots so you see whether posture is improving or eroding.
Filter:
Mute checks you have explicitly accepted (e.g. legacy systems); score recomputes without them.

Example

82/ 100

+4 in 30 days. Driven by closing 3 Critical IAM findings and enabling EBS encryption defaults org-wide.

How we compare

Refine vs. The Alternatives

Honest assessment — Wiz and Prisma are deep CNAPP products, and Security Hub can apply fixes we deliberately cannot. Refine is an AWS-native pairing of security and cost with a free tier and flat paid plans. Different jobs, different prices. Pick the one that fits.

Frequently Asked Questions

  • A combination of AWS-best-practice checks (Well-Architected Framework, AWS Foundational Security Best Practices), CIS Benchmarks, and Refine-curated checks we've seen catch real issues across customer engagements.

Find the security risks already in your AWS account

60-second setup. Free under $2,000/month of AWS spend. Read-only access.

Refine is built and supported by HabileLabs, an AWS Advanced Tier Services Partner.