bearhug is cloud security posture management (CSPM) built only for AWS, for teams that do not have a dedicated security engineer.
It builds on AWS Security Hub and Amazon GuardDuty. bearhug continuously checks your AWS accounts for misconfigurations, exposed resources and threats, and explains every finding in plain English: what is wrong, why it matters and how to fix it. Switch to the technical view at any time for the original finding, resource ARN and region.
Common fixes, such as blocking public access on an S3 bucket, closing open and insecure ports or enabling CloudTrail logging, take one click, with rollback. Nothing changes until you approve it. Findings that need a human decision come with step-by-step guidance.
Findings are mapped to SOC 2, ISO 27001, PCI DSS, GDPR and Cyber Essentials controls. New critical and high findings trigger a plain-English email alert, and a multi-account dashboard shows every connected account in one place.
Set-up takes under five minutes. You deploy a CloudFormation stack that creates a read-only IAM role and an EventBridge rule, and enables Security Hub and GuardDuty. A separate remediation role is requested only when you choose to use one-click fixes.
$100 per AWS account per month, with every feature included and no per-asset counting. Security Hub and GuardDuty usage is billed separately by AWS. The monthly plan has a one-month minimum term and no long-term commitment. 12, 24 and 36-month contracts are available at the same price.
14-day free trial with full access. The trial does not convert to a paid plan automatically.
Highlights
AWS CSPM for $100 per AWS account per month, with every feature included. No per-asset pricing and no long-term commitment.
Plain-English findings from Security Hub and GuardDuty, with one-click fixes and rollback for common misconfigurations.
Set up in under five minutes with a CloudFormation stack. Findings mapped to SOC 2, ISO 27001, PCI DSS, GDPR and Cyber Essentials.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay based on a single dimension: the number of AWS Accounts you link to your bearhug dashboard. Pricing scales per account, so your cost grows with each account you connect. There is no per-asset counting, meaning one flat price covers an account regardless of how many resources run inside it. You can add or remove accounts at any time, and billing adjusts to the number of accounts linked.
Top-of-mind questions for buyers
What counts as one AWS Account for billing?
Each linked AWS account is one billable unit, regardless of how many resources run inside it. There is no per-asset counting. One account is one price, whether it holds a few resources or many. You link accounts to your bearhug dashboard to bring them under monitoring.
How does my cost change if I add or remove accounts?
You are billed per linked AWS account. Adding an account increases your cost by one account's charge. Removing an account reduces it. You can add or remove accounts at any time from the dashboard, and billing adjusts to the current number of linked accounts.
What does each linked account include for monitoring and fixes?
Each account gets all security checks and findings, plain English and technical views, one-click remediation, real-time monitoring and alerts, and a multi-account dashboard. Monitoring pulls in findings from AWS-native security services. Compliance alignment support is also included for each linked account.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Cancel at any time from AWS Marketplace; your plan stays active until the end of the current billing period. For refund questions, email support@bearhug.cloud.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
The Sonrai Cloud Permissions Firewall brings cloud access under control by automating least privilege enforcement through AWS-native policies, including Service Control Policies (SCPs) and Resource Control Policies (RCPs). It continuously analyzes permission usage to apply centralized, default-deny guardrails without slowing DevOps. With one click, unused sensitive permissions are restricted across your cloud environment, while just-in-time permission exceptions are automatically granted as new needs arise-keeping teams productive and secure.
InstaSecure enables DevSecOps, platform, and cloud security teams to enforce enterprise-wide baselines, stop misconfigurations, and prevent privilege creep-hardening your cloud with stronger security, faster compliance, and cost savings with zero friction, and zero code changes.
We help teams enforce enterprise-wide baselines, stop misconfigurations, and prevent privilege creep-hardening your cloud with stronger security, faster compliance, and cost savings with zero friction, and zero code changes.
Identify and remediate high-risk IAM access across both human and non-human identities.
Deploy preventive guardrails to stop misconfigurations and privilege drift before they happen again.
Deliver tangible, reference-ready outcomes: a hardened cloud identity posture you can trust
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.