About this pilot
C4C runs this as a supervised learning exercise for a maximum of six pre-qualified small businesses. It is not a commercial audit and not a university-certified assessment.
What you get
An independent second set of eyes on your AWS security configuration
One Executive Risk Chart in business language (Critical / High / Medium findings + recommended next steps)
Zero software or agents installed on your systems
Temporary, least-privilege access only — you create and delete the role yourself
Fixed scope, fixed time — one AWS account, one primary region, about two hours
Helps a supervised student build portfolio evidence while giving you point-in-time visibility
What This Is
A time-boxed (max 120 minutes active work; role lifetime 3 hours), read-only review of AWS security services and configuration findings (Security Hub, GuardDuty, Access Analyzer, Config, IAM credential report, Prowler, and similar metadata sources).
What This Is Not
Not a penetration test, not a code review, not incident response, not remediation, and not a comprehensive audit. Findings are point-in-time and limited to what the temporary read-only role can see. This is not a guarantee of security and is not evidence for cyber-insurance or a compliance certification.
Client eligibility (important)
This pilot is designed for straightforward small-business AWS environments that you own and administer.
Please do not request a slot if:
The account contains protected health information (HIPAA), payment cardholder data (PCI-DSS), or federal Controlled Unclassified Information (CUI / CMMC / ITAR)
You are a bank, broker-dealer, insurer, or other entity with its own financial-services examiners
An external IT provider or MSP owns or administers the AWS account
You cannot create a temporary IAM role (or do not have someone who can, in about 15 minutes)
You need more than one AWS account, a multi-region review, or anything beyond a read-only configuration review
If any of the above apply, this pilot is not the right fit. Do not submit the form.
How It Works
1. Submit the short form on this page. Do not create an IAM role yet.
2. C4C confirms you are in the six-slot pilot set and emails the Educational Waiver.
3. After the waiver is signed, C4C sends the one-page Access Setup Guide. You create a temporary IAM role (about 10–15 minutes) with the exact policies supplied. No access keys. No permanent permissions.
4. A supervised student practitioner assumes the role from their own hardened lab, runs the standardized checklist, and drafts the Executive Risk Chart. A C4C reviewer checks the draft before you receive it.
5. You delete the role within 15 minutes of notification. Session closed.
Access & Liability Summary
The student receives only a temporary role ARN + External ID.
Maximum session duration is hard-limited to 2 hours. Role lifetime is 3 hours.
An explicit data-plane deny policy is attached (no object downloads, no secrets, no log content, no write actions).
The student works only from their own account / lab — nothing is installed on your systems.
The Educational Waiver is between you and C4C. It includes limitation-of-liability language and states this is not a guarantee of security.
A C4C reviewer must clear the report before delivery. The student is not your contractor.
