Free resource
SSH access risk checklist
Twelve yes/no checks security leads and founders should be able to answer about production SSH. No signup required to score — email is optional for a follow-up pack.
Live score
0/12 (0%)
High access risk
Check every statement that is true for your team today. Unchecked items are your backlog.
Priority gaps (12)
- •We do not use shared private keys across multiple people for production access — Attribution and offboarding break; key sprawl is almost guaranteed
- •We can list every human who can reach production servers today (name + path) — Access reviews and incident response will fail under pressure
- •Leavers lose production SSH access the same day (verified, not assumed) — Standing access after exit is a classic breach and audit finding
- •Engineers get role-scoped access — not “everyone has the prod key” — Blast radius of a laptop compromise is the entire fleet
- •Break-glass / emergency access is documented and rare — not the daily path — Emergency paths become permanent backdoors
Email me a follow-up pack
Optional: get a short recap of common fixes (keys, bastion, session audit) and Terminal tips. Score at submit: 0/12.
Related: use cases · Terminal · Teleport vs StrongDM