AuditForge · v0.1
● LIVE

Azure audit data,
collected in hours, not weeks.

AuditForge automates the data collection layer of Azure environment audits across 9 categories — IAM, networking, security, cost, reliability, and more. So your architect spends time on judgment calls, not query runs.

Book an Audit → See how it works
9
AUDIT CATEGORIES
IAM to Architecture & Sizing
5
SEVERITY LEVELS
Critical → Informational
Reader
ACCESS REQUIRED
read-only, zero risk
2
SEPARATE ENGAGEMENTS
audit first, remediation second
The problem

Manual audits don't scale.

Two architects can't run 15 Azure audits simultaneously when every data collection step is done by hand. AuditForge removes the bottleneck.

The bottleneck is data collection, not expertise

A senior Azure architect running an environment audit spends the majority of their time running CLI queries, cross-referencing portal views, and collating raw data — before any real analysis begins. AuditForge automates exactly that layer: data in, structured findings out. The architect applies judgment where it matters.

Engagement model

Two engagements. Deliberately separate.

The audit and the remediation are always separate commercial engagements. This is not a structural quirk — it is the model. You don't buy conclusions before you have findings.

How it works

Automated collection. Architect judgment.

AuditForge handles the data layer. The architect handles the analysis. Three phases, three mandatory human checkpoints.

01

Access & Scope

Client grants Reader access via a dedicated vendor account. AuditForge never requests Contributor or Owner permissions. Scope is locked — no changes outside the agreed subscription boundary.

Reader Only Vendor Account Zero Write Access
02

Automated Data Collection

AuditForge runs structured Azure CLI and Python queries across 9 audit categories. Raw data is collected, normalized, and surfaced as structured findings with preliminary severity flags for architect review.

Azure CLI 9 Categories Human Checkpoint
03

Report Generation

The architect reviews all findings, applies contextual judgment, confirms or adjusts severity scores, and triggers the Word report generator. Client receives a structured report — executive summary, technical detail, and remediation priority matrix.

Word Report Priority Matrix Human Checkpoint
Coverage

9 audit categories.
Nothing left unchecked.

Every AuditForge engagement covers all 9 categories by default. Category 9 is architect-only — AuditForge surfaces utilization metrics; sizing decisions require business context only your team has.

CAT-01

Identity & Access Management

Entra ID roles, privileged assignments, service principals, MFA coverage, Conditional Access, guest account posture.

RBAC sprawl PIM gaps MFA status SPN audit
CAT-02

Networking

VNet topology, NSG rule analysis, peering posture, Private DNS zones, public IP exposure, NVA coverage.

Open NSG rules Public IPs DNS hygiene Hub-Spoke gaps
CAT-03

Security & Compliance

Defender for Cloud coverage and recommendations, Policy assignments, secure score by subscription, Key Vault access patterns.

Defender gaps Policy drift Secure score KV access
CAT-04

Compute

VM inventory, SKU utilization, availability set vs zone coverage, unmanaged disks, orphaned resources, patch compliance.

Unmanaged disks AV coverage Orphaned NICs Patch status
CAT-05

Data & Storage

Storage account security posture, public blob access, encryption at rest, soft delete, SQL TDE, Cosmos DB configuration.

Public access TLS versions Soft delete Encryption
CAT-06

Monitoring & Observability

Log Analytics workspace coverage, diagnostic settings per resource, alert rule audit, Azure Monitor gaps, Activity Log retention.

Diag gaps Alert coverage Log retention Monitor gaps
CAT-07

Cost & Governance

Tagging compliance across subscriptions, budget alert coverage, idle resource detection, Advisor cost recommendations, orphaned resource audit.

Tag coverage Idle VMs Unattached disks Budget alerts
CAT-08

Reliability & Business Continuity

Backup coverage per VM and database, Recovery Services vaults, availability zone distribution, SLA exposure analysis.

Backup gaps Zone spread RSV coverage SLA exposure
CAT-09

Architecture & Sizing Review

Raw utilization metrics surfaced by AuditForge — CPU, memory, IOPS, Reserved Instance coverage. Sizing conclusions require architect judgment and client business context.

CPU p95 Memory avg RI coverage IOPS flags
ARCHITECT JUDGMENT REQUIRED
Severity framework

Five levels. Clear action thresholds.

Every finding is scored by probability × impact. The architect reviews all preliminary scores before report generation — no automated severity is final.

Level Definition Example Expected action
Critical Active risk, likely exploitable, regulatory breach Public SA with sensitive data, no MFA on Global Admin Remediate within 24–48 hours
High Significant exposure, not immediately exploitable NSG allows 0.0.0.0/0 inbound on non-standard port Remediate within 1–2 weeks
Medium Deviation from best practice, limited direct impact Missing diagnostic settings on 30% of resources Address in next sprint cycle
Low Hygiene gap, minor risk, no compliance impact Incomplete resource tagging, soft delete disabled Include in ongoing governance backlog
Informational Observation only, no action required Legacy SKU in use but within support lifecycle Document for future planning

Reader access only. Always via vendor account.

AuditForge requires a Reader role assigned to a dedicated HelixLab vendor account — never Contributor, never Owner, never your own credentials. The principle: if data collection requires write access, it's not audit data collection. All access is revoked at engagement close.

Deliverables

What you receive
at engagement close.

Every AuditForge engagement delivers a structured, professional report alongside all underlying data — no findings without evidence, no evidence without traceability.

Structured Audit Report

A professional Word document with executive summary and full technical section. Organized by category, severity-sorted, with finding IDs for traceability.

  • Executive summary — non-technical, board-ready
  • Technical findings by category
  • Finding IDs — AF-CAT-001 format
  • Remediation priority matrix — Critical first

Raw Findings Dataset

The structured JSON findings file behind the report. Every flag, every metric, every data point that informed the report — delivered in machine-readable format for your own tooling.

  • Structured JSON — all 9 categories
  • Resource IDs per finding
  • Severity + probability + impact breakdown
  • Remediation effort estimates per item

Remediation Priority Matrix

A prioritized action list — sortable by severity, category, or effort. Designed to feed directly into Engagement 2 scoping if the client proceeds to remediation.

  • All findings ranked by priority score
  • Effort estimation per finding (S/M/L/XL)
  • Dependency mapping — what blocks what
  • Quick wins identified separately

Architect Review Session

A structured walkthrough of the findings with the lead architect. Review the report, ask questions about any finding, and align on which items require immediate action before Engagement 2 is considered.

  • 60-minute structured walkthrough
  • Q&A on any finding in the report
  • Prioritization guidance from the architect
  • Decision checkpoint — proceed or hold
Pricing

Engagement 1. Fixed price.

The audit engagement is fixed-price. No hourly rates, no scope creep, no surprises. Engagement 2 is scoped and quoted separately after findings are reviewed.

AuditForge — Engagement 1
$2,500 / environment

A complete Azure environment audit delivered as a structured report with severity-ranked findings, a remediation priority matrix, and a 60-minute architect review session.

9-category audit coverage — automated + architect-reviewed
Structured Word report — executive + technical sections
Raw findings dataset in structured JSON
Remediation priority matrix with effort estimates
60-minute architect review session included
Engagement 2 scoping — only if client proceeds
Book an Audit → Talk to an architect
CloudForge + AuditForge bundle available
Start with clarity

Know what's in your
Azure environment.

Most Azure environments accumulate technical debt in silence. AuditForge makes it visible — prioritized, structured, and actionable — before it becomes a breach or a budget problem.

Book an Audit → See CloudForge