Tarek Cheikh
Founder & AWS Cloud Architect
I launched KloudSec.
If you've followed Toc Consulting for a while, you know why: across years of AWS security consulting, I kept watching the same unfair pattern play out. Big companies could afford real security, a team, a stack of tools, the budget to tie it all together. Small companies got left with whatever they could scrape together, or nothing at all. Not because they cared less about security. Because the tools were built for people with enterprise budgets, not for them.
That's the fight KloudSec is here for. Giving small and growing companies the same depth of protection that only the richest organizations could afford until now. Agentless, live in 5 minutes, real pricing you can see instead of "contact sales," a genuine free tier instead of a crippled trial.
KloudSec brings cloud posture management, Infrastructure as Code scanning, application code scanning, secrets detection, and compliance mapping into a single platform, agentless, connected through a read-only CloudFormation stack in about 5 minutes.
AWS is where it starts, not where it stops. GCP and Azure support are already on the roadmap.
I'm asking you to try it, and to help it grow.
Connect one AWS account, free, no credit card, and see what it finds. If it's useful, tell someone. Share it with a founder, a DevOps lead, anyone fighting the same uphill battle you are. That's how something like this grows, not through a large marketing budget, but through people who believe the same thing I do passing it along.
If you've got more than one AWS account and want to put it through its paces properly, email me directly at hello@kloudsec.io. I'll set you up with coupons myself, no sales call, no back and forth, just making sure you can actually test it the way you need to.
This is a small fight against very large, very well-funded competitors. I don't have their budget. What I have is a product built by someone who's lived this problem, and a community of people who might believe, like I do, that good security shouldn't be a privilege reserved for whoever can afford it.
Try it. Break it. Tell me what's wrong with it. That's how we win this.
This article is just the start. Get the full picture with our free whitepaper - 8 chapters covering IAM, S3, VPC, monitoring, agentic AI security, compliance, and a prioritized action plan with 50+ CLI commands.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.
Part 16 of 16 in the AWS Security Agent: From Zero to Hero series. Closing the series: the numbers this whole project is built on, the honest verdict distilled to its essentials, what AWS has shipped since my hands-on testing, and an evidence-based look at how AI pentesting stacks up against traditional consultancy today.
Part 15 of 16 in the AWS Security Agent: From Zero to Hero series. What AWS Security Agent leaves behind in your own account. CloudTrail events, Secrets Manager entries, and VPC Flow Logs, with the commands to audit and observe every run yourself.
Part 14 of 16 in the AWS Security Agent: From Zero to Hero series. What AWS itself documents about AWS Security Agent as its own attack surface: the guardrails it publishes, how it limits its own blast radius, and how domain ownership and data handling are enforced. Sourced entirely from AWS's public documentation, not hands-on testing.