AWS Security Tools, built in the open.

A curated catalogue of open-source security tooling contributed to aws-samples and beyond by the India Security Specialist Team. Each card opens the project's collateral — overview, architecture, capabilities and links.

Open source AWS-native GenAI & Agentic security India regulatory compliance
MCP Server

AWS India Compliance MCP Server

Read-only assessment of AWS infrastructure against Indian regulatory frameworks — DPDP Act 2023, RBI IT Governance, SEBI CSCRF and CERT-In. 7 MCP tools; works with Kiro, Claude and Cursor.

DPDPRBISEBICERT-In
Open details
Reference Architecture

AI Enclave

Securing GenAI & agentic workloads on AWS — "a deterministic boundary around a probabilistic system." An interactive walkthrough of the four objectives: secure WHERE, HOW, WHAT and WHEN.

GenAI securityAgenticBank compliance
Open interactive diagram
Governance Platform

Zero-Trust Agent Identity Governance

Continuous zero-trust governance for AI agent identities at organizational scale. Detects drift, enforces tagging, verifies permissions boundaries and trust policies, and monitors behaviour via CloudTrail Lake.

AgentCore IdentityStrands SDKCDK
Open details
Coming soon
aws-samples

Next contribution

Placeholder for a further aws-samples security tool from the Admin team. Details and repository URL to be added.

Preview

Repositories & packages

Every open-source contribution from the India Security Specialist Team, in one place.
Featured projects
AWS India Compliance MCP Server
Zero-Trust Agent Identity Governance
AI Enclave
More contributions from the team
AI Agent Jailbreak → Cloud Takeover (workshop)
Cedar Policy Management Platform
Cognito Session Lifecycle Manager
VIGIL — Access Recertification Engine
Cognito Adaptive Authentication
Cognito + API Gateway Authorization
IAM Roles Anywhere Demo
MCP Server · Apache 2.0

AWS India Compliance MCP Server

Read-only assessment of AWS infrastructure against Indian regulatory requirements.
Architecture — local, read-only, no data exfiltration
ONE-TIME DOWNLOAD (install) RUNTIME DATA FLOW PyPI.org Package Registry (.whl ~100KB) PyPI involvement ends here. Never runs code, receives telemetry, or sees your data. LLM-Powered Agent Amazon Quick / Kiro Claude Desktop / Cursor Any MCP Client pip / uvx install Source code only (~100KB) ✖ NO DATA FLOWS BACK stdio (MCP protocol) aws-india-compliance (Python process) ✅ Runs locally via stdio ✅ No network listener ✅ No ports exposed output (local only) Scan Results • In-memory only • Discarded on exit • Optional: save to local dir NEVER sent to PyPI or any third party 🔒 Zero data exfiltration 🔒 Runs entirely on your machine 🔒 No network listener / no ports 🔒 Open source — fully auditable YOUR AWS Account(s) Control Tower · CloudTrail · Security Hub Config · GuardDuty · Inspector · Macie · WAF READ-ONLY API calls · Never modifies resources READ-ONLY API calls (your AWS credentials) Regulatory Search Engine Tier 1: Live HTTPS GET → crawls gov sites Tier 2: Embedded Mappings → offline fallback regulatory lookup Tier 1: Live crawl (if site reachable) HTTPS GET only (Public text) Regulatory Sources (public websites) dpdpact.in · rbi.org.in sebi.gov.in · cert-in.org.in Tier 2: Embedded mappings (fallback) Embedded Control Mappings • Bundled in package • Section refs + penalties • AWS control → regulation domain mapping • Works offline
What it does
Capabilities at a glance
🔍 Scan
Control Tower guardrails & account resources against Indian regulations
📊 Assess
Compliance posture across DPDP, RBI, SEBI, CERT-In
📖 Search
Regulatory text — exact sections, penalties, requirements
🛠️ Generate
Deployable AWS Config conformance packs (YAML)
📄 Report
Formatted DOCX / Markdown for auditors & management
📋 List
Control domains per framework for structured assessments
One tool. Four frameworks. Minutes, not weeks.
For SAs & Account Teams
Value for SAs and Account Teams
Use caseBenefit
Pre-meeting prepWalk in with posture scores & gap list
SIP / SHIP engagementsAutomated scan replaces manual spreadsheets
Architecture recommendations"Here's a deployable template to close your gaps"
Compliance workshopsLive demo: scan → gaps → remediation in one session
Customer-ready reportsDOCX for CISOs / auditors in minutes, not days
💬 Positioning line: "We have an automated compliance assessment that maps your AWS environment directly to DPDP, RBI, SEBI, and CERT-In — with deployable remediation templates. Want me to run it against your landing zone?"
For Technical Account Managers
Value for TAMs
Use caseBenefit
Proactive governance reviewsCatch drift before auditors do
SIP Phase 1 complementIndia-specific regulatory mapping (vs. SRA Verify's architectural view)
SIP Phase 2 complementMaps findings to Indian regulatory domains (vs. CIS / NIST)
Quarterly business reviewsShow compliance posture trends over time
Escalation-free remediationGenerate conformance packs customers deploy themselves
Multi-framework coverageOne scan → DPDP + RBI + SEBI + CERT-In
🔄 Key workflow: Run monthly → save reports → show improvement trend in QBRs
Regulatory knowledge at your fingertips
Instant regulatory lookup

❌ The problem

Customer asks: "What does RBI say about data localization?" — and you either say "I'll get back to you" (kills momentum), fumble through 200-page PDFs, or give a vague answer and hope it's right.

✅ The solution

"search DPDP breach notification timeline"  exact sections + penalty
"what does RBI say about encryption"  Chapter IV requirements
"SEBI CSCRF MII obligations"  tiered control requirements
"CERT-In log retention"  180-day mandate + specifics
Result: Answer customer questions in real time with exact section citations and penalty figures.
The difference
Before vs. after

❌ Before (today's reality)

SA:

"I believe the DPDP Act requires encryption… let me check and get back to you."

Customer:

"Okay, send me an email."
← Momentum lost. Follow-up takes 3 days.

✅ After (with the MCP)

SA:

"DPDP Act Section 8(4), Rules 2025 Rule 6.1(d) mandates encryption of personal data. Non-compliance penalty is up to ₹250 Crore per contravention. Your scan shows 6 unencrypted RDS instances. Here's a conformance pack to fix it."

Customer:

"When can we start?"
← Deal acceleration. Instant credibility.
Coverage
Supported frameworks & penalty exposure
FrameworkRegulated entitiesDomainsKey requirements
DPDP Act 2023 + Rules 2025Everyone processing Indian PII10Encryption, breach notification, retention, cross-border transfer
RBI Master DirectionBanks (SBI, HDFC, Canara…)8Secret rotation, IT governance, data localization
SEBI CSCRFBrokers, MIIs (NSE, BSE), AMCs8Tiered controls: MII vs Qualified RE vs Other RE
CERT-In Directions 2022All entities86-hour incident reporting, 180-day log retention

DPDP penalty exposure

Missing security safeguards₹250 Crore
Failure to notify breach₹200 Crore
Children's data violations₹200 Crore
Any other contravention₹50 Crore
Why this tool
Key differentiators
This MCPManual assessment
⚡ 1,091 resources in seconds🐌 Weeks of manual review
🎯 Direct technical checks📋 Questionnaire-based
🛠️ Generates deployable conformance packs📄 PDF of problems
🔄 Repeatable monthly for trend tracking📸 One-off point-in-time
📖 Cites exact Act sections & ₹ penalties💬 Generic best practices
🔒 Open source, local-only, zero data exfiltration⚠️ Vendor tools with data sharing
🤖 Works with any MCP client (Quick, Kiro, Claude, Cursor)🖥️ Single vendor lock-in
Read before you demo
Important caveats
🔒 Advisory onlySA doesn't run in customer environments — customer / TAM provides SecurityAudit role
⚖️ Not a legal opinionTechnical controls assessment, not compliance certification
🤝 Complements, doesn't replaceWorks alongside SRA Verify (architecture) and SATv2 / Prowler (CIS / NIST)
🏗️ Best paired withWell-Architected Security Pillar review for a complete picture
🔓 Open sourceFully auditable, no telemetry, no data leaves your machine
📡 No external runtime depsOnly talks to YOUR AWS account + public regulatory websites
Built with ❤️ for the India FSI SA & TAM community
Click to advance

Overview

An MCP (Model Context Protocol) server that evaluates AWS infrastructure against Indian regulatory frameworks. It performs read-only assessments and works with Kiro, Claude Desktop, Cursor and other MCP-compatible clients. Findings carry confidence ratings and evidence, but the tool does not constitute legal advice or compliance certification.

DPDP Act 2023 + Rules 2025 RBI Master Direction on IT Governance 2023 SEBI CSCRF 2024 CERT-In Directions 2022

MCP tools

ToolWhat it does
scan_aws_accountDiscovers resources via AWS Config and assesses all frameworks; returns a compact (~2–3K token) summary with posture scores, gap counts and top critical findings. Supports tag filtering, exceptions, SEBI tiering and file saving.
scan_control_towerEnumerates enabled guardrails per OU, recommends missing ones per framework, with a domain-coverage breakdown.
get_compliance_gapsPaginated drill-down into gaps from the latest scan; filter by framework, risk level or domain (default 20/page, max 50).
search_regulatory_textSearches regulatory text from government sources, falling back to bundled mappings if sites are unreachable.
list_control_domainsLists framework domains: DPDP (10), RBI (7), SEBI (6), CERT-In (4).
generate_conformance_packProduces deployable AWS Config conformance-pack YAML for a framework.
format_reportCreates auditor-grade DOCX (default) or Markdown reports; can reuse cached scan results automatically.

Maintainer tools (regulatory updates, mapping management) are CLI-only and not exposed via MCP.

Quick start

No install needed — uvx handles it. Add to your MCP config:

{
  "mcpServers": {
    "aws-india-compliance": {
      "command": "uvx",
      "args": ["aws-india-compliance@latest"],
      "env": { "AWS_PROFILE": "my-sso-profile" }
    }
  }
}

Config locations: Kiro .kiro/settings/mcp.json, Claude Desktop claude_desktop_config.json, Claude Code ~/.claude/mcp.json. Requires uv (macOS: brew install uv).

Prerequisites

  • Python 3.10+
  • AWS Config recorder enabled
  • Read-only IAM credentials (IAM Identity Center / SSO recommended)
  • Config Aggregator for org-wide scans (auto-discovered)

Key features

  • Confidence scoring — every gap rated High / Medium / Low with evidence, timestamps and rationale.
  • CERT-In checks — incident pipeline (GuardDuty / EventBridge / SNS), 180-day log retention, NTP sync, Security Hub.
  • Per-account breakdown for org-wide scans, each with its own posture score.
  • SEBI entity tiering — MII (C-SOC + BYOK), qualified_re (BYOK), other_re (baseline).
  • Nuanced data localization — storage outside India high-risk; compute medium-risk advisory; global services excluded.
  • Exception management — auto-suppresses AWSControlTowerExecution roles; custom rules by pattern/tag.
  • Tag filtering — include (filter_tags) or exclude (exclude_tags) resources.
  • Reports — DOCX with cover page, colour-coded scores and per-OU sections; or Markdown.

Control domains

DPDP (10)

Lawful Processing, Data Minimization, Privacy Notices, Data Principal Rights, Breach Notification, Security Safeguards, Retention Limits, Cross-Border Transfer, Children's Data, Significant Data Fiduciary Obligations.

RBI (7)

IT Governance, IT Infrastructure, IT Risk Management, Information Security, Cyber Security, BC/DR, IS Audit.

SEBI (6)

Cyber Governance, Risk Identification, Protection, Detection, Response, Recovery.

CERT-In (4)

Incident Reporting Readiness, Log Retention (180 days), NTP Sync, Reportable Incident Awareness.

Resource checks

S3 (encryption, Block Public Access, versioning, logging, Object Lock, TLS), RDS (encryption, public access, Multi-AZ, SSL), DynamoDB (KMS, TTL, PITR), Lambda (env secrets, DLQ), EC2 (public IP, IMDSv2, EBS encryption), EKS (secrets encryption, endpoint visibility, control-plane logging), ECS (Container Insights), CloudTrail (validation, KMS, CW Logs), KMS (rotation, BYOK), API Gateway / CloudFront (WAF), SQS / SNS (encryption), SageMaker (internet access, KMS, VPC), IAM roles (over-privileged policies), VPC Flow Logs, Security Groups (open SSH/RDP), Secrets Manager (rotation), AWS Backup (plans, Vault Lock), Inspector (enablement). RBI scans also flag resources outside ap-south-1 / ap-south-2.

Sample prompts

  • "Scan my AWS account in ap-south-1 for DPDP and RBI compliance"
  • "Scan my AWS organization for compliance"
  • "Scan my AWS account as a SEBI MII entity"
  • "Show me all critical DPDP gaps"
  • "Scan my Control Tower and check guardrail coverage"
  • "What does DPDP say about breach notification timelines?"
  • "Format my last scan as a Word document"
  • "Generate an AWS Config conformance pack for RBI"
Reference Architecture

AI Enclave: Securing GenAI & Agentic Workloads on AWS

"A deterministic boundary around a probabilistic system."
The Enclave doesn't control
what the model thinks
It controls what it can
REACH / DO / SEE / PRODUCE / OBSERVE
AI Enclave Boundary
AI Enclave: Securing GenAI &
Agentic Workloads on AWS
"A deterministic boundary around a probabilistic system"
The Enclave doesn't control what the model thinks —
it controls what it can REACH / DO / SEE / PRODUCE / OBSERVE
Security Agent  |  DevOps Agent  |  GuardDuty Investigation Agent  |  AgentCore  |  Bedrock Guardrails  |  Inspector + Continuum
Bank Compliance Mapping
Regulatory alignment across the lifecycle
WHERE
RBI FREE-AI Framework
SEBI Cloud Framework
AWS Control Tower Foundations
HOW
Secure AI-DLC
Shift Left (Steering Files)
AI-BOM
WHAT
Continuous PT
Validation
Compliance Gate
WHEN
CERT-In 6hr
SOC Integration
IR at machine speed
Objective 1
Secure WHERE (AI runs)
Infrastructure & Network Boundary
Network Isolation
VPC, PrivateLink, Bedrock VPC Endpoints
Compute Isolation
SageMaker Isolated, Nitro Enclaves, KMS
Identity Boundary
IAM Roles, SCPs, Permission Boundaries
Data Boundary
Data Localization, Encryption, Macie
Objective 2
Secure HOW (Artefacts produced)
Design & Development Lifecycle
Threat Modeling
Security Agent (STRIDE), Design Docs / Confluence
Code Review + PR Scan
Claude Code Plugin, Kiro Power, MCP
Dependency / SCA
SBOM, CVE Scanning, Inspector + Continuum
Repo Integration
GitHub, GitLab, Bitbucket (self-hosted)
Objective 3
Secure WHAT (Reaches production)
Deploy & Release Gate
Pen Testing (GA)
Security Agent, On-Prem + Cloud
Release Testing
DevOps Agent, Autonomous UAT
Exploit Validation
Continuum sandbox, Proof of exploitability
Compliance Gate
Org Security Standards, Graduated Trust Model
Objective 4
Secure WHEN (It's running)
Detect & Respond at Runtime
Threat Investigation
GuardDuty Investigation Agent, MITRE ATT&CK
Continuous Monitoring
Security Hub, CloudTrail AI Events
Automated Response
EventBridge to SIEM, Auto-remediation
Runtime Guardrails
AgentCore + Bedrock Guardrails, PII, Filters
The people behind the enclave
Team Work
FSI Team ProServ Team GenAI Team
Click to advance

Four objectives

  • Secure WHERE — infrastructure & network boundary (VPC, PrivateLink, SageMaker isolation, Nitro Enclaves, IAM/SCP identity boundary, data localization).
  • Secure HOW — design & development lifecycle (STRIDE threat modeling, PR scanning, SCA/SBOM, repo integration).
  • Secure WHAT — deploy & release gate (pen testing, release testing, exploit validation, compliance gate).
  • Secure WHEN — detect & respond at runtime (GuardDuty investigation agent, Security Hub, EventBridge auto-remediation, runtime guardrails).

Bank compliance mapping

WHERE
RBI FREE-AI Framework, SEBI Cloud Framework, AWS Control Tower Foundations
HOW
Secure AI-DLC, Shift Left (steering files), AI-BOM
WHAT
Continuous PT, validation, compliance gate
WHEN
CERT-In 6hr, SOC integration, IR at machine speed

Team work

FSI TeamProServ Team GenAI Team

AWS services in the enclave

Security AgentDevOps Agent GuardDuty Investigation AgentAgentCore Bedrock GuardrailsInspector + Continuum
Governance Platform

Zero-Trust Agent Identity Governance

Continuous zero-trust governance for AI agent identities at organizational scale on AWS.

What it does

Treats every AI agent as an untrusted principal that must continuously prove its identity, justify its permissions and have its behaviour monitored. It detects drift, enforces tagging compliance, verifies IAM permissions boundaries, validates sourceIdentity trust policies, monitors behavioural drift via CloudTrail Lake, and verifies SCP enforcement — automatically.

Active governance checks

Runs twice daily.

CheckSeverity
Tag compliance — IdentityType, AgentType, AgentScopeMEDIUM · auto
Permissions boundary attached to agent IAM rolesHIGH
sourceIdentity enforcement in trust policiesHIGH
Behavioural monitoring (scope vs CloudTrail Lake)HIGH
SCP enforcement of aws:PrincipalTag/IdentityTypeCRITICAL

Real-time lifecycle governance

Event-driven.

EventAction
CreateRole matching agent patternAuto-attaches standard permissions boundary
AttachRolePolicy with unauthorized policyAuto-detaches the policy

Zero-trust principles

  • No implicit trust — every request re-authenticates via short-lived credentials.
  • Least privilege — permissions boundary + SCP + minimal identity policy.
  • Continuous verification — actions logged, monitored, alerted.
  • Assume breach — blast radius contained, attribution immutable.
  • Micro-segmentation — unique identity per agent, layered authorization.

Architecture

Deploys across two AWS accounts — a management account for organization-level controls and a governance (child) account for all governance infrastructure.

┌─────────────────────────────────────────────────────────────┐
│                    Management Account                         │
│  OrganizationStack:                                           │
│    - SCPs denying actions without IdentityType tag            │
│    - Cross-account EventBridge forwarding rules               │
│    - Delegated Security Hub administrator config              │
└──────────────────────────────┬──────────────────────────────┘
                               │
┌──────────────────────────────▼──────────────────────────────┐
│                Governance (Child) Account                     │
│  IdentityStack:      AgentCore workload identities            │
│  GovernanceIAMStack: IAM roles + permissions boundaries       │
│  MonitoringStack:    DynamoDB + Drift Agent + EventBridge     │
│                      + IAM Lifecycle Lambda + CloudTrail      │
│  DashboardStack:     CloudFront + Cognito + API Gateway       │
│                      + Lambda handlers (5 endpoint groups)    │
│  AgentCoreStack:     Strands SDK supervisor on Runtime        │
└─────────────────────────────────────────────────────────────┘

Tech stack

Identity
Amazon Bedrock AgentCore Identity
Governance agents
Strands SDK (Python) on AgentCore Runtime
Infrastructure
AWS CDK (TypeScript)
Backend
Lambda (Node.js 22, TypeScript)
Dashboard
React 18 + Cloudscape Design System
Auth
Amazon Cognito
Storage
DynamoDB
Monitoring
CloudTrail Lake, EventBridge, Security Hub

Key services used

  • AgentCore Identity — workload identity lifecycle (create, tag, list, delete).
  • AgentCore Runtime — hosting governance agents with A2A protocol.
  • AgentCore Policy — Cedar-based application-layer authorization.
  • AWS IAM — permissions boundaries, SCPs, session tags for ABAC.
  • CloudTrail Lake — behavioural monitoring via SQL on agent activity.
  • Security Hub — centralized finding aggregation (dual-write with DynamoDB).
  • EventBridge — real-time IAM lifecycle automation.
  • DynamoDB — findings and orchestration-run storage.

Project structure

packages/
├── agents/          # Python - Strands SDK governance agents
│   └── src/         # Supervisor + sub-agents (drift, rotation, provisioning, decommission)
├── backend/         # TypeScript - Lambda handlers + services
│   └── src/
│       ├── handlers/   # Lambda entry points (drift-agent, identities, findings, agents, policies)
│       ├── models/     # Data models (drift findings, workload identities)
│       └── services/   # Check modules (permissions boundary, sourceIdentity, behavioral, SCP)
├── dashboard/       # TypeScript + React - Cloudscape UI
│   └── src/
│       ├── pages/      # Home, Identities, Findings, Agents, Policies
│       └── api/        # API client
└── infrastructure/  # TypeScript - CDK stacks
    ├── bin/            # CDK app entry point
    └── lib/            # Stack definitions
aws-samples

Next contribution

Placeholder for a further aws-samples security tool.

Coming soon

This slot is reserved for an additional security tool from the Admin team's aws-samples contributions. Provide the repository URL and collateral and it will be filled in here — the card, detail page and GitHub links row are already wired up.