Automated AWS IAM security provisioning via CloudFormation. 10 IAM groups, expanded service roles, assumable roles, policy coverage across S3, ECR, SageMaker, Lambda, and Bedrock. Docker-based.
SEC Provisioner by Axon Tech Labs is a Docker-based tool that automates AWS IAM security infrastructure provisioning via CloudFormation. It bridges the gap between data science agility and enterprise security requirements - creating IAM groups, service roles, assumable roles, and least-privilege policies from a single YAML configuration file. By shifting security left, teams can build compliant ML environments in minutes rather than weeks.
The Medium-10 tier is designed for growing teams with multiple workloads. It includes 10 IAM groups, expanded service roles, assumable roles, and broader policy coverage across S3, ECR, SageMaker, Lambda, and Bedrock.
Note: Medium-10 and Enterprise-12 tiers generate CloudFormation templates that exceed the 51,200-byte inline limit. An S3 bucket is required for template storage. Use the S3 Provisioner to create this bucket or create it manually.
Deploy across multiple AWS accounts, environments, and regions with consistent results. Every step - from configuration validation to deployment - produces auditable artifacts for compliance and team visibility.
Designed for DevOps engineers, MLOps engineers, security architects, and platform teams who need standardized, repeatable IAM infrastructure across ML projects, environments, and accounts.
Key Capabilities:
Automated Least-Privilege Governance: Secure your environment from the start by automatically generating granular IAM policies and standalone service role documents across S3, ECR, SageMaker, Lambda, and Bedrock. No manual JSON policy writing required.
Safe Deployment Pipeline: Move confidently from configuration to production with a multi-stage validation workflow. Validate YAML schemas, perform structural CloudFormation checks, and utilize isolated test-deploy namespaces to verify permissions before touching live environments.
Pre-Deployment Visibility: Eliminate surprises by generating detailed Change Sets to preview exactly how security modifications will impact your environment. This allows security teams to audit infrastructure updates before they are executed.
Continuous Compliance and Auditability: Maintain a transparent security posture by exporting IAM roles and groups into individual JSON files for external auditing. Use built-in drift detection to identify unauthorized manual changes and ensure your live stack remains aligned with your defined security baseline.
Streamlined Lifecycle Orchestration: Manage the entire security stack through a single interface - from synthesizing CloudFormation templates to executing full resource tear-downs.
12 Actions:
validate-config - Validate configuration YAML template before deployment
export-iam-policy - Generate a least-privilege IAM policy document for provisioning IAM security infrastructure
export-service-policies - Generate standalone JSON policy documents for each AWS service role
export-roles - Extract IAM role definitions into individual JSON files for auditing
export-groups - Export IAM group definitions as individual JSON files
create-prov-template - Synthesize the configuration into a CloudFormation template
validate-prov-template - Perform structural and semantic validation on the generated template
show-changes - Generate a Change Set to preview security infrastructure modifications
check-drift - Detect configuration drift on deployed CloudFormation stack resources
test-deploy - Deploy to an isolated namespace to verify permissions and resource creation
deploy - Provision or update the AWS security infrastructure stack
delete-stack - Tear down the CloudFormation stack and remove all associated security resources
How It Works:
Configure: Define your IAM security infrastructure in a simple YAML file
Execute: Run the Docker container with your config mounted
Review: Generate CloudFormation templates, IAM policies, and service role documents, then validate before deploying
Deploy: Deploy to AWS via CloudFormation for immediate, reliable resource creation
Technical Requirements:
Docker 20.10 or later
AWS account with IAM, CloudFormation, and S3 permissions
Expanded IAM Security - 10 IAM groups, expanded service roles, assumable roles, and 20+ policy templates across S3, ECR, SageMaker, Lambda, and Bedrock. 12 actions cover the full lifecycle from policy generation and audit exports to drift detection and stack teardown.
Audit-Ready Exports - Export IAM policies, service roles, and group definitions as individual JSON files for external security reviews. Built-in drift detection identifies unauthorized manual changes to your deployed infrastructure.
Safe Deployment Pipeline - Multi-stage validation workflow with schema checks, CloudFormation template validation, and isolated test deployments. Preview security changes via Change Sets before touching live environments. Docker-based execution fits any CI/CD system.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one license for SEC Provisioner Medium-10. You buy it under a contract as a set number of units. Each unit covers the Medium-10 configuration, which includes 10 IAM groups, expanded service roles, and assumable roles. There are no separate size or usage tiers to choose from within this listing. Pricing scales only by how many units you buy. The tool provisions AWS IAM infrastructure such as groups, roles, and policies through a single CloudFormation stack.
Top-of-mind questions for buyers
What does the Medium-10 license provision compared to the tool's other configurations?
The Medium-10 license sets up 10 IAM groups, 5 service roles, and multiple assumable roles. Service roles cover functions like SageMaker, Lambda, Glue, CodeBuild, and CI/CD. The tool deploys these as a single CloudFormation stack, with policies drawn from pre-built templates across several AWS services.
If I outgrow Medium-10, do I pay more units or switch configurations?
Within this listing, cost scales only by how many Medium-10 units you buy. The tool supports tier upgrade paths through its update procedures, but moving to a different configuration is a separate purchase. Adding units does not automatically expand the number of IAM groups or roles beyond the Medium-10 setup.
Does the license cover the AWS resources the tool creates?
No. The license covers the SEC Provisioner software only. The IAM groups, roles, and policies it deploys are AWS resources. Per the vendor's cost notes, IAM itself carries no charge, though related services such as CloudFormation, SSM Parameter Store, and S3 template storage may incur separate AWS fees.
docs.axontechlabs.com+1
Helpful?
Vendor refund policy
30-day money-back guarantee for monthly subscriptions. Pro-rated refunds for annual subscriptions within first 30 days.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Version 1.2.1 Release Notes
Documentation Fix
Removed internal development reference from Application Architecture documentation
Replaced test account identifier with standard placeholder in sample reports
Compatibility
Fully backward compatible with all 1.2.0 configurations and commands
No functional changes
Additional details
Usage instructions
Quick start:
docker run --rm
-v ~/.aws:/home/secuser/.aws:ro
sec-provisioner:medium-10 --help
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Automate S3, VPC, and IAM infrastructure for growing ML teams. 40 actions with expanded IAM roles and broader policy coverage across 5+ AWS services. 15% bundle savings.
Automated AWS IAM security provisioning via CloudFormation. 12 IAM groups, full service roles, assumable roles, cross-account roles, 31 policy templates across 9 AWS services. Docker-based.
The SEC Filings Analyzer, powered by Amazon Bedrock, allows users to interrogate public company annual reports (10ks) that are available in the SEC EDGAR database. This powerful solution can accurately retrieve and analyze public company filings in seconds.
AlgoSec, a global cybersecurity leader, enables organizations to automate security policy management, risk mitigation, and compliance across hybrid and multi-cloud network environments. By providing centralized visibility and control over application connectivity, network security policies, and infrastructure, AlgoSec helps reduce risk, streamline security operations, and automate workflows. With two decades of expertise, over 2,200 of the worlds most complex organizations trust AlgoSec to secure and manage their critical workloads at scale.
This course covers fundamental AWS cloud security concepts, including AWS access control, data encryption methods, and how network access to your AWS infrastructure can be secured. We will address your security responsibilities in the AWS cloud and provide a brief introduction to the different security-oriented AWS services available.
Research agents over the A2A protocol: complete cited valuations and SEC filing research in one call. Choose the reasoning model per request (Claude Haiku included, Sonnet premium, or none/BYO). Every figure computed by deterministic engines - the LLM cannot invent numbers.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.