Everything you need to know.
How does the trial license work?
Yes. We run the complete, 280+ point enterprise audit on your agency's internal AWS infrastructure at no cost. No credit card. No commitment. It allows you to hold the exact executive PDF report in your hands and validate our engine's capabilities before you offer it to your clients.
How safe is giving you read-only access?
Extremely safe. We use the AWS-managed SecurityAudit policy — a well-known, widely-trusted read-only policy. We cannot modify resources, delete data, or see encrypted content. You control the CloudFormation stack and can delete it instantly, revoking all access.
How does the compliance mapping work?
Every one of our 280+ checks is mapped to specific control IDs in CIS, SOC 2, ISO 27001, PCI-DSS, HIPAA, GDPR, and NIS2. When a check passes, it counts as evidence for that control. Your report shows a compliance posture card per framework — exactly what auditors need to see.
Will my clients ever know LeapScan is running the audit?
No. We are a 100% invisible backend engine. Your clients will never see our logo, receive emails from our domain, or be prompted to create a LeapScan account. The CloudFormation template and the final PDF are completely white-labeled under your agency's brand.
How does the white-label branding actually work?
When you run a scan, you simply pass your agency's name, your client's name and your logo URL into the engine. The resulting PDF is dynamically generated to look like a bespoke document created entirely by your internal consulting team.
What if I need to scan more accounts than my tier allows?
The $299/mo tier covers the vast majority of mid-sized IT agencies. If you are an enterprise MSP managing 50+ AWS environments, reach out to us at support@leaptrix.com. We can spin up a dedicated, high-volume Enterprise instance with custom volume pricing.
Do you store my clients' AWS data or source code?
Never. Our engine only reads metadata (e.g., "Is port 22 open?" or "Is bucket X encrypted?"). We never have access to the data inside your S3 buckets, RDS databases, or application code. Because LeapScan runs entirely within your own Docker environment, all findings and report data remain on your infrastructure. We do not store your scan data.
Does the GDPR scan guarantee GDPR compliance?
No automated tool can guarantee GDPR compliance — that's an important limitation to understand. LeapScan covers all automatable technical controls (Art.5, Art.25, Art.32, Art.33, data residency). However, GDPR also requires organisational controls like privacy notices, DPIAs, DPO appointment, and staff training — these are documented as "Company Responsibility" items in your report with a checklist for auditors.
What does the NIS2 framework check cover?
Our NIS2 module maps AWS infrastructure findings to the binding cybersecurity obligations in NIS2 Directive (EU) 2022/2555 Art.21. This includes: incident handling readiness (Art.21(2)(b)) via EventBridge rules, business continuity & backup coverage (Art.21(2)(c)), supply chain security via ECR Enhanced Scanning (Art.21(2)(d)), vulnerability management via Inspector v2 (Art.21(2)(e)), effectiveness evaluation via Security Hub standards (Art.21(2)(f)), cryptographic policy via KMS key rotation (Art.21(2)(h)), network security via WAF & Shield (Art.21(2)(a)), and MFA enforcement (Art.21(2)(j)). NIS2 applies to essential and important entities operating in the EU — non-compliance can result in fines up to €10M or 2% of global annual turnover.
Does the scan add any cost to my AWS bill?
Zero. All 280+ checks use free read-only AWS APIs — DescribeInstances, ListBuckets, GetBucketEncryption, etc. We never spawn EC2 instances, invoke Lambda functions, or write data. Your AWS bill will not change by a single cent.
What's included in the 30-minute findings review?
For Agency Starter customers, we include an async or live session where we walk through your top 5 critical findings, explain the business risk in plain English, and guide you through the CLI remediation commands. Most customers resolve their top issues within 48 hours of the review.