About this pilot

C4C runs this as a supervised learning exercise for a maximum of six pre-qualified small businesses. It is not a commercial audit and not a university-certified assessment.


What you get

  • An independent second set of eyes on your AWS security configuration

  • One Executive Risk Chart in business language (Critical / High / Medium findings + recommended next steps)

  • Zero software or agents installed on your systems

  • Temporary, least-privilege access only — you create and delete the role yourself

  • Fixed scope, fixed time — one AWS account, one primary region, about two hours

  • Helps a supervised student build portfolio evidence while giving you point-in-time visibility

What This Is


A time-boxed (max 120 minutes active work; role lifetime 3 hours), read-only review of AWS security services and configuration findings (Security Hub, GuardDuty, Access Analyzer, Config, IAM credential report, Prowler, and similar metadata sources).

What This Is Not


Not a penetration test, not a code review, not incident response, not remediation, and not a comprehensive audit. Findings are point-in-time and limited to what the temporary read-only role can see. This is not a guarantee of security and is not evidence for cyber-insurance or a compliance certification.

Client eligibility (important)

This pilot is designed for straightforward small-business AWS environments that you own and administer.

Please do not request a slot if:

  • The account contains protected health information (HIPAA), payment cardholder data (PCI-DSS), or federal Controlled Unclassified Information (CUI / CMMC / ITAR)

  • You are a bank, broker-dealer, insurer, or other entity with its own financial-services examiners

  • An external IT provider or MSP owns or administers the AWS account

  • You cannot create a temporary IAM role (or do not have someone who can, in about 15 minutes)

  • You need more than one AWS account, a multi-region review, or anything beyond a read-only configuration review

If any of the above apply, this pilot is not the right fit. Do not submit the form.

How It Works

  • 1. Submit the short form on this page. Do not create an IAM role yet.

  • 2. C4C confirms you are in the six-slot pilot set and emails the Educational Waiver.

  • 3. After the waiver is signed, C4C sends the one-page Access Setup Guide. You create a temporary IAM role (about 10–15 minutes) with the exact policies supplied. No access keys. No permanent permissions.

  • 4. A supervised student practitioner assumes the role from their own hardened lab, runs the standardized checklist, and drafts the Executive Risk Chart. A C4C reviewer checks the draft before you receive it.

  • 5. You delete the role within 15 minutes of notification. Session closed.

Access & Liability Summary

  • The student receives only a temporary role ARN + External ID.

  • Maximum session duration is hard-limited to 2 hours. Role lifetime is 3 hours.

  • An explicit data-plane deny policy is attached (no object downloads, no secrets, no log content, no write actions).

  • The student works only from their own account / lab — nothing is installed on your systems.

  • The Educational Waiver is between you and C4C. It includes limitation-of-liability language and states this is not a guarantee of security.

  • A C4C reviewer must clear the report before delivery. The student is not your contractor.

Request a Pilot Slot