Cloud security, in practice.

Guides on posture management, cloud misconfigurations, compliance benchmarks and attack paths — written by the team building Sovereign Observer, and kept to things we can show running.

Is AI-Generated Terraform Secure? We Scanned It (2026)

We scanned the Terraform an AI assistant writes when you do not mention security: 40 findings across 6 common resources, 10 of them critical or high. Here is what fails, why, and how to catch it in the editor.

5 min read

A Terraform Security MCP Server for Claude Code, Cursor and Copilot

Install a free, local MCP server that scans Terraform for security misconfigurations while your AI assistant writes it. Setup for Claude Code, Cursor, VS Code and Windsurf, and what each tool does.

4 min read

CSPM vs CNAPP: What’s the Difference? (2026)

CSPM vs CNAPP explained: what each acronym means, how they relate (CSPM is one pillar of CNAPP), what CWPP and CIEM add, and which one a startup actually needs first.

3 min read

Wiz Alternatives for Startups and Small Teams (2026)

Looking for a Wiz alternative that fits a startup budget? Compare Prowler, Aikido, Orca, Prisma Cloud, and Sovereign Observer on pricing, setup, and who each one actually fits.

4 min read

How to Find and Fix Over-Permissive IAM Roles in AWS (2026 Guide)

Step-by-step guide to finding IAM roles and policies with wildcard "*" permissions in AWS and cutting them down to least privilege — console, CLI, IAM Access Analyzer, and how to stay clean.

4 min read

Best CSPM Tools for Startups and Small Teams (2026)

Comparing CSPM options for startups in 2026: Wiz, Orca, Prisma Cloud, open-source Prowler, and Sovereign Observer — pricing models, setup time, and who each one fits.

3 min read

CIS AWS Foundations Benchmark: What It Is and How to Pass It

What the CIS AWS Foundations Benchmark covers, which controls matter most, how scoring works, and the fastest way to get compliant — manually or with automated scanning.

3 min read

How to Find and Fix Public S3 Buckets in AWS (2026 Guide)

Step-by-step guide to finding every public S3 bucket in your AWS account and locking it down — console, CLI, and account-wide Block Public Access, plus how to stay clean.

4 min read

What Is CSPM? Cloud Security Posture Management, Explained

CSPM (Cloud Security Posture Management) continuously scans AWS, Azure, and GCP for misconfigurations. Learn how it works, what it catches, and when you need one.

7 min read