Setting Up Secure
Pump Secure requires a dedicated IAM role in your AWS account. This role is separate from the read-only and Autopilot roles used by Pump Save. Setup takes a few minutes using an AWS CloudFormation stack.
Prerequisites
Before setting up Pump Secure, you need:
An AWS account connected to Pump
Your account must already be linked via the standard Pump onboarding flow
AWS Console access
You need permission to deploy CloudFormation stacks and create IAM roles in the target account
Step 1: Start the Secure Setup
Navigate to Security in the Pump sidebar. If the PUMP_SECURE role has not been deployed yet, you will see a prompt to connect your account for security scanning.
Click Enable Pump Secure. Pump generates a pre-filled CloudFormation Quick-Create Stack URL specific to your account.
Step 2: Deploy the CloudFormation Stack
Clicking the setup link opens the AWS Console with a pre-configured CloudFormation stack. The stack creates a single IAM role with two components:
AWS-managed policy: SecurityAudit (read-only access to security-relevant AWS services).
Custom policy (PumpSecure): Additional read-only permissions covering services not included in SecurityAudit, such as:
Compute and containers
ec2:Describe*, ecs:Describe*, eks:Describe*, lambda:GetFunction*
Databases
rds:Describe*, elasticache:Describe*, redshift:Describe*, dynamodb:GetResourcePolicy
Storage and data
s3:GetAccountPublicAccessBlock, ecr:GetRegistryScanningConfiguration, backup:List*
Security services
securityhub:GetFindings, securityhub:BatchImportFindings, macie2:GetMacieSession
Networking
ec2:GetEbsEncryptionByDefault, ec2:GetSnapshotBlockPublicAccessState
Logging and monitoring
cloudtrail:GetInsightSelectors, cloudwatch:Get*, logs:FilterLogEvents
Identity
cognito-idp:GetUserPoolMfaConfig, ds:Describe*
API access
apigateway:GET (scoped to REST APIs and HTTP APIs only)
The role also includes:
A trust policy that allows Pump's AWS account to assume the role using sts:AssumeRole, gated by an External ID unique to your connection. No other AWS account or principal can assume this role.
A PumpPingResource (CloudFormation Custom Resource) that notifies Pump when the stack deployment completes. This triggers automatic activation.
Review the stack details in the AWS Console, then click Create stack.
Step 3: Automatic Activation
Once the CloudFormation stack completes, the PumpPingResource notifies Pump that the role is ready. Pump Secure activates automatically. No additional steps are required in the Pump UI.
Your first scan begins shortly after activation. Initial results typically appear within minutes.
What Pump Secure Can and Cannot Access
Can access (read-only):
Resource configuration
EC2 instances, security groups, RDS instances, S3 bucket policies, ECS/EKS clusters, Lambda functions, VPC settings, IAM configurations
Security service data
SecurityHub findings, GuardDuty results, CloudTrail insight selectors, Macie session status
Compliance metadata
Backup policies, encryption settings, public access configurations, network ACLs
Cannot access and never requests:
Data at rest
No access to S3 object contents, database records, application data, or secrets
Write operations
No ability to create, modify, or delete any resource in your account
Infrastructure changes
No ability to launch instances, modify security groups, or change configurations
Billing permissions
The PUMP_SECURE role does not include Cost Explorer or billing access (those belong to the separate read-only role)
Troubleshooting
Stack creation failed. The most common cause is insufficient IAM permissions in your AWS account. You need iam:CreateRole, iam:PutRolePolicy, iam:AttachRolePolicy, and cloudformation:CreateStack permissions. Check the CloudFormation Events tab for the specific error.
Scans not appearing after deployment. Allow a few minutes for the first scan to complete. If no results appear after 15 minutes, check that the CloudFormation stack status is CREATE_COMPLETE in the AWS Console. If the stack is still in progress or failed, review the Events tab for errors.
Role already exists error. If you previously deployed and then deleted a Pump Secure stack, the IAM role name may still be reserved. Contact Pump support to generate a new stack URL with a fresh role name.
Last updated
Was this helpful?

