Alliances

The same terms, and the same scrutiny.

We hold a Google Cloud Marketplace private-offer relationship on the same terms as AWS — wholesale pricing on security software through an agreement you already have, and assessment of the estate it runs on.

What private offers change

Security software, on your Google Cloud agreement.

Private offers let us extend negotiated pricing on third-party security software through Google Cloud Marketplace. The effect is procedural as much as commercial: the spend runs through an agreement and an approval path you already have, rather than starting a new vendor contract for every tool. Where an estate spans more than one hyperscaler, the same relationship covers AWS Marketplace as well, so governance does not fork by platform.

01
One procurement path

Security tooling billed through the Google Cloud account your finance team already reconciles, instead of a separate contract, PO and vendor onboarding for each product.

02
Wholesale pricing

Negotiated rates on third-party security software, reaching you through the private-offer mechanism rather than a list-price Marketplace purchase.

03
Advice stays separate

Buying through us does not decide what we recommend. We will say when a tool is not worth the money, including one this route could sell you — and where we resell, we tell you so.

Securing the estate itself

Assess the posture, then hold it.

GCP estates drift the way every cloud does: projects multiply, service accounts outlive the workloads they were made for, and the diagram stops matching the console. We assess estates as they are configured today and rank findings by exploitability rather than scanner severity.

IAM & service accounts

Roles, keys and cross-project bindings that accumulate quietly — usually where the real exposure sits, and rarely where the org chart says it should be.

VPC Service Controls

Perimeter configuration as deployed rather than as diagrammed, including the paths out of a service perimeter that nobody meant to leave open.

Storage & BigQuery exposure

What is reachable, by whom, and whether that matches what the data classification says it should be — buckets and datasets both.

Logging & detection coverage

Whether an incident would actually be visible after the fact — the question that matters most and gets asked last.

Configuration is measured against CIS Benchmarks, and findings map back to the same risk language as the rest of your program.

Where it hands off

Measured once, or watched continuously.

An assessment tells you where you stand today. When you want the posture held rather than re-measured next year, the same findings seed Managed CloudSec — which watches GCP alongside the rest of your estate rather than as a separate console.

Cloud Security Assessment · Managed CloudSec · All alliances