Features
Fix AWS security issues in one click
Finding a misconfiguration is only half the job. bearhug gives each supported finding a Fix button that applies the change for you, with a rollback option if anything behaves unexpectedly. For findings that need a human decision, bearhug gives step-by-step remediation guidance generated with Amazon Bedrock.
We'll remove the overly permissive inbound and outbound rules on this security group and replace them with rules that only allow traffic on ports your application is actively using.
Every supported finding shows the proposed fix before you apply it.
How one-click remediation works
Every supported finding in the bearhug dashboard has a Remediate button. Before anything changes, bearhug describes the proposed fix in plain English, such as which bucket it will block public access on or which security group rules it will remove. Review the change, click to apply it, and bearhug makes the change in your AWS account for you. If anything behaves unexpectedly, roll the change back from the same screen.
bearhug starts with a read-only IAM role, so it can see your security configuration but cannot change it. When you choose to use one-click fixes, bearhug asks you to grant a separate role with the permissions those fixes need. You stay in control of when bearhug can make changes.
Some findings need a human decision, such as whether a port should stay open for a partner integration. For those, bearhug gives step-by-step remediation guidance generated with Amazon Bedrock, so your team knows exactly what to change.
Examples of one-click fixes
Common AWS misconfigurations that bearhug can fix for you.
Secure S3 buckets from public access
Block public access on buckets that should never be reachable from the internet, such as buckets that hold backups or customer data.
Close open and insecure ports
Remove security group rules that allow unrestricted inbound traffic, so only the ports your applications actually need stay open.
Enable CloudTrail logging
Turn on AWS CloudTrail so you keep a record of API activity in your account for investigations and audits.
Why teams use one-click remediation
No console, no scripts
Apply fixes from the bearhug dashboard. There is no need to find the right setting in the AWS console or write a script for each change.
Rollback if you need it
Every one-click fix can be rolled back from the dashboard, which helps you recover quickly if a change affects your application unexpectedly.
Hours saved on every finding
Reading documentation, working out the fix and testing it can take hours for each finding. A reviewed one-click fix takes minutes.
One-click remediation questions
bearhug shows you exactly what will change before you apply a fix, and nothing changes until you click. If a change behaves unexpectedly, you can roll it back from the dashboard.
Not at first. bearhug connects with a read-only IAM role. When you decide to use one-click fixes, bearhug asks you to grant a separate role with the permissions those fixes need.
bearhug gives step-by-step remediation guidance generated with Amazon Bedrock, so your team knows exactly what to change and can make the fix with confidence.
Explore more bearhug features
Fix your first AWS misconfiguration today
Connect your AWS account, review the recommended fixes and apply them in one click. 14-day free trial. The paid plan is $100 per AWS account per month.
No credit card. No procurement. Starts from your AWS console.