
Security · Every plan
Priya
Priya’s job is to find the security issues that matter most across the company’s code, GitHub and AWS, and prepare the evidence reviewers and auditors ask for.
On this page
What Priya does
- Dependabot, code scanning and Security Hub alerts, and how exposed each one is
- AWS account security: root and console MFA, administrator access, CloudTrail, GuardDuty and Security Hub
- Access reviews across GitHub and AWSStudio
- Audit evidence packs mapped to SOC 2 criteriaStudio
- Draft answers to security questionnaires, each cited or left for a personPro
- Fix deadlines for security alerts, with a warning before one is missedStudio
- GitHub Actions workflows checked for unpinned actions, broad token permissions and long-lived AWS keysStudio
- A monthly record of who approved each change merged to mainStudio
- Checking that people who left no longer hold accessStudio
- A notice within minutes of a risky change, such as a root sign-in or a repository made public, and a weekly digest of how long controls were offStudio
- Open vulnerabilities ranked by exploit riskPro
- Weekly evidence snapshots across an audit periodEnterprise
What you can ask
You ask Grant, and he brings in Priya for questions like these. On Free, he answers from Priya’s saved briefs.
- “Which security alerts should we fix first?”
- “Does anyone who left still have access?”Studio
- “Prepare evidence for our SOC 2 audit.”Studio
- “Fill in this security questionnaire.”Pro
What you get
Two critical Dependabot alerts are open in api, a prototype pollution in lodash and a path traversal in tar, both with a fixed version available. The lodash one is 3 days past its 7-day fix deadline; owner @acme/platform. Root has MFA; two console users do not. Security Hub is off in eu-west-1, so findings there are unknown.
What Priya reads
- GitHub security alerts
- AWS Security Hub
- Repository context
- GitHub accessStudio
- AWS security posturePro
- GitHub deliveryStudio
- AWS changesStudio
- GitHub seatsStudio
- AI provider members and keysStudio
- Slack usersStudio
When Priya works
At each scheduled check-in, on Dependabot alerts and code scanning alerts and when you ask Grant. On Free, only at the monthly check-in you start.
What Priya may do
Read-only: reads the approved sources and reports findings.
What Priya never does
- Start a scan or change code
- Read the contents of a secret
- Say the company is compliant
- Remove access: removals are suggestions for a person to approve


