How it works
How bearhug checks your AWS security, set up in under five minutes
bearhug does not install agents or ask you to hand over credentials. It uses a CloudFormation stack in your own AWS account, so you can see exactly what it deploys.
Three steps to a secure AWS account
No consultants. No complex setup. No learning curve.
Connect your AWS account
Deploy the bearhug CloudFormation stack from the onboarding screen. It creates a read-only IAM role and an Amazon EventBridge rule that sends security findings to bearhug, and it enables AWS Security Hub and Amazon GuardDuty in your account.
See your findings in plain English
Findings from Security Hub and GuardDuty appear in your dashboard as Security Hub completes its first checks, usually within a couple of hours, grouped by severity and resource, with a plain-English explanation of each one.
Fix issues and stay protected
Use one-click fixes for supported findings, follow step-by-step guidance for the rest, and receive real-time alerts when something new appears.
What bearhug can and cannot access
bearhug starts with read-only access. It can only make changes to your account after you grant a separate remediation role, and it removes everything it created when you leave.
| What | What it does | When |
|---|---|---|
| Read-only IAM role | Lets bearhug read your account’s security settings and findings. It cannot change anything. | Created at setup |
| Amazon EventBridge rule | Streams Security Hub and GuardDuty findings to bearhug as they are raised. | Created at setup |
| AWS Security Hub and Amazon GuardDuty | The AWS services that produce the findings bearhug explains. AWS bills their usage separately. | Enabled at setup |
| Remediation role | Grants the permissions needed to apply one-click fixes. | Only when you choose to use one-click fixes |
| Data sent to bearhug | Security settings and findings from your account, which bearhug reviews and explains. | Continuously while connected |
| Removal | bearhug removes the roles and configuration it created, so nothing is left in your account. | When you cancel in AWS Marketplace |
bearhug does not install agents on your servers, and it does not ask for AWS access keys or passwords.
Architecture
Findings flow from the AWS security services in your account to bearhug, where they are explained and made actionable.
How it works questions
No. bearhug uses AWS-native services and a CloudFormation stack. There is nothing to install on your servers or containers.
Not at first. bearhug connects with a read-only IAM role. A separate role with remediation permissions is only requested when you choose to use one-click fixes.
Cancel your subscription in AWS Marketplace. bearhug then removes the IAM roles and configuration it created, so nothing is left in your account.
bearhug works in any AWS Region where Security Hub is available. Findings come from the controls enabled in each Region, and some controls are not available in every Region.
Connecting takes under five minutes for most accounts: you deploy one CloudFormation stack from the onboarding screen. Security Hub then begins most of its checks within 25 minutes and all of them within two hours, so findings build up over that time.
Connect your first AWS account
Deploy one CloudFormation stack in under five minutes, and your first findings follow as Security Hub completes its first checks, usually within a couple of hours. 14-day free trial. The paid plan is $100 per AWS account per month.
No credit card. No procurement. Starts from your AWS console.