Cloud security, in practice.
Guides on posture management, cloud misconfigurations, compliance benchmarks and attack paths — written by the team building Sovereign Observer, and kept to things we can show running.
Is AI-Generated Terraform Secure? We Scanned It (2026)
We scanned the Terraform an AI assistant writes when you do not mention security: 40 findings across 6 common resources, 10 of them critical or high. Here is what fails, why, and how to catch it in the editor.
A Terraform Security MCP Server for Claude Code, Cursor and Copilot
Install a free, local MCP server that scans Terraform for security misconfigurations while your AI assistant writes it. Setup for Claude Code, Cursor, VS Code and Windsurf, and what each tool does.
CSPM vs CNAPP: What’s the Difference? (2026)
CSPM vs CNAPP explained: what each acronym means, how they relate (CSPM is one pillar of CNAPP), what CWPP and CIEM add, and which one a startup actually needs first.
Wiz Alternatives for Startups and Small Teams (2026)
Looking for a Wiz alternative that fits a startup budget? Compare Prowler, Aikido, Orca, Prisma Cloud, and Sovereign Observer on pricing, setup, and who each one actually fits.
How to Find and Fix Over-Permissive IAM Roles in AWS (2026 Guide)
Step-by-step guide to finding IAM roles and policies with wildcard "*" permissions in AWS and cutting them down to least privilege — console, CLI, IAM Access Analyzer, and how to stay clean.
Best CSPM Tools for Startups and Small Teams (2026)
Comparing CSPM options for startups in 2026: Wiz, Orca, Prisma Cloud, open-source Prowler, and Sovereign Observer — pricing models, setup time, and who each one fits.
CIS AWS Foundations Benchmark: What It Is and How to Pass It
What the CIS AWS Foundations Benchmark covers, which controls matter most, how scoring works, and the fastest way to get compliant — manually or with automated scanning.
How to Find and Fix Public S3 Buckets in AWS (2026 Guide)
Step-by-step guide to finding every public S3 bucket in your AWS account and locking it down — console, CLI, and account-wide Block Public Access, plus how to stay clean.
What Is CSPM? Cloud Security Posture Management, Explained
CSPM (Cloud Security Posture Management) continuously scans AWS, Azure, and GCP for misconfigurations. Learn how it works, what it catches, and when you need one.