FAQ

Everything you need to know

Still wanna know more? Just Chat us, dr. Turtle will assist you

So what exactly is TurtleScan?
+
The short version: we keep your cloud secure. We scan your entire cloud setup, whatever platforms you use, find the risky stuff, and tell you what to fix first. This is not a one-shot deal like traditional audits. We keep watching and reporting progress, so your security gets stronger over time. End result: your business stays safer from hackers and data leaks, and compliance gets sorted along the way.
What services do you offer?
+
We cover 4 main protection areas: (1) strengthening your security foundation, (2) preventing hacker attacks, (3) protecting sensitive data from leaks, and (4) helping you pass audits and compliance. Pick one, combine several, or take the all-in-one package, all structured, measurable, and on a regular cycle.
Which clouds do you support?
+
Pretty much all the relevant ones: AWS, Google Cloud, Microsoft Azure, Alibaba Cloud, Oracle Cloud, and Tencent Cloud. Using a mix? No problem. We handle multi-cloud in a single setup, so you get one unified report for your entire environment.
Who actually needs TurtleScan?
+
If your business uses the cloud to store data, run apps, or host your website, you need us. Cloud providers handle the basics, but a lot of security is on you. We make sure that part does not slip through the cracks. Our packages are flexible, fitting for SMEs new to cloud all the way up to enterprises with strict compliance needs.
How is TurtleScan different from regular VAPT?
+
Traditional VAPT (Vulnerability Assessment and Penetration Testing) is like major surgery: long, sometimes months, needs lots of prep from your team, and produces a thick report that often is not specific to your business context. TurtleScan is different: report ready in 1 week, your prep takes only a few hours, and the output focuses on the critical issues you need to fix in the next 30 days. Plus, it is continuous, not one-shot.
Is it more expensive than VAPT?
+
Actually, it usually works out cheaper, even if the upfront price looks different. VAPT has hidden costs: your team prep time, scope reductions to save money, and follow-ups for missed parts. TurtleScan is transparent: pricing upfront, our team does the work, all cloud assets covered in one setup. You focus on the business, we handle security.
What plans do you have?
+
We offer 6 main plans, picked based on what worries you most: Iron for strengthening your security foundation, Halt for preventing hacker exploitation, Safe for protecting sensitive data from leaks, Defender for both at once (Halt + Safe), Zenith for complete defense (Iron + Halt + Safe), and Certify for passing audits (ISO, OJK, Indonesia PDP, etc.). Each plan has frequency options from Lite (3x per year) up to Ultra (continuous monitoring), depending on your business risk level.
How long does the whole process take?
+
About 5 business days. Day 1 is cloud integration (usually a few hours, via online meeting). Days 2 to 4, we scan and analyze all your assets. Day 5, the report and action plan land in your inbox. After that, you can start fixing right away, or chat with our team if anything needs clarifying.
What do you need from us?
+
Just one thing: read-only access to your cloud. That means we can see your assets, but we cannot modify, delete, or move anything. We give you exact permissions for each cloud platform, all transparent, documented, and revocable any time you are uncomfortable. One setup covers everything, even if you have multiple accounts or multi-cloud.
How does the cycle work?
+
Each package cycle gives you 2 reports: one before the fix (what is broken and the priority order), and one after the fix (what is now secure and your risk score progress). For the next cycle, we re-integrate with the same cloud, scan again, and report again. Target: your risk score drops at least 1 point per cycle. We also help you pick the right plan and reach the security level you want.
What kinds of security issues do you find?
+
A lot, but we do not focus on issue types. We look for what is riskiest for your business first, aligned with your chosen plan. Common findings: cloud misconfigurations, malware, weak access and passwords, sensitive data accidentally exposed, hidden attack paths, and app/infrastructure vulnerabilities. The point is not the count of findings, it is which ones to fix first.
Does the package include the actual fixes (remediation)?
+
Honest answer: no, your team handles the actual fixes. But our report is not just a list of "this is broken", we include step-by-step guidance on how to fix things. During the fix process, our team is on chat or call when you need to confirm something. Do not have an in-house IT team? No worries, we can recommend trusted implementation partners who can execute.
Is my data safe with you?
+
Very safe, here is how we make sure: (1) we sign an NDA with every engagement; (2) our access is read-only, we cannot change anything; (3) our system reads, analyzes, and gives the result, we do not store your data; (4) all analysis runs in our Indonesian Point of Presence, so your data does not leave the country and aligns with PDP law standards; (5) you can revoke our access any time. Five layers of protection, all verifiable.
Is there a free version?
+
Yes. You can get an initial picture of your cloud security for free, before committing to any plan. Here is how: chat with our sales team, sign an NDA, we run a quick integration, and give you initial insights. But because each free trial takes real team time, we cap the number of companies per week. Reach out while slots are still open.
Coverage

Complience Directory

Explore the cloud providers, operating systems, infrastructure technologies, and compliance frameworks TurtleScan maps into clear security reporting and audit-ready recommendations.

AWS logo
Cloud Providers

AWS

Microsoft Azure logo
Cloud Providers

Microsoft Azure

Google Cloud logo
Cloud Providers

Google Cloud

Alibaba Cloud logo
Cloud Providers

Alibaba Cloud

Oracle Cloud logo
Cloud Providers

Oracle Cloud

Tencent Cloud logo
Cloud Providers

Tencent Cloud

Linux logo
Operating Systems

Linux

AlmaLinux logo
Operating Systems

AlmaLinux

Bottlerocket logo
Operating Systems

Bottlerocket

CentOS logo
Operating Systems

CentOS

Debian logo
Operating Systems

Debian

Oracle Linux logo
Operating Systems

Oracle Linux

Red Hat logo
Operating Systems

Red Hat

Rocky Linux logo
Operating Systems

Rocky Linux

SUSE logo
Operating Systems

SUSE

Ubuntu logo
Operating Systems

Ubuntu

Windows 10 logo
Operating Systems

Windows 10

Windows 11 logo
Operating Systems

Windows 11

Windows Server logo
Operating Systems

Windows Server

Docker logo
Infrastructure

Docker

Kubernetes logo
Infrastructure

Kubernetes

Apache logo
Infrastructure

Apache

NGINX logo
Infrastructure

NGINX

PostgreSQL logo
Infrastructure

PostgreSQL

NIST logo
Security Frameworks

NIST

CIS logo
Security Frameworks

CIS

MITRE logo
Security Frameworks

MITRE

ISO logo
Security Frameworks

ISO

GDPR logo
Privacy & Governance

GDPR

Indonesia PDPL logo
Privacy & Governance

Indonesia PDPL

CSA logo
Privacy & Governance

CSA

NHI logo
Privacy & Governance

NHI

PCI DSS logo
Industry Assurance

PCI DSS

SOC logo
Industry Assurance

SOC

HITRUST logo
Industry Assurance

HITRUST

HIPAA logo
Industry Assurance

HIPAA

MPA logo
Industry Assurance

MPA

Dr. Turtle
TurtleScan Assistant

Meet Dr. Turtle, AI Assistant

I'm here to help you understand cloud security, answer questions about our service packages, Indonesian regulatory compliance, and help you choose the best solution for your business needs. What are you looking for today?