Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Public Resources
51 controls
44 services covered
Surfaces resources that are public or reachable from the internet across storage, databases, compute, containers, APIs, AI, and messaging — including S3 and Glacier, RDS, EKS, ECS, API Gateway, AppSync, Redshift, EMR, load balancers, Bedrock AgentCore, and permissive IAM and KMS access policies.
What we check
EC2 Instances2
- No Public EC2 Instances
- No Public EBS Snapshots
EC2 Instance Roles2
- No Internet-Facing EC2 Instances with IAM Roles Attached
- No Internet-Facing EC2 Instances with IAM Roles Attached and IMDSv1 Allowed
RDS DB Instances2
- No Public RDS Instances/Clusters
- RDS DB instances should not be deployed in public subnets with routes to internet gateways
API Gateway REST APIs2
- No Public API Gateway Endpoints
- API Gateway Endpoints Protected by WAF
EMR Clusters2
- No Public EMR Instances
- EMR Block Public Access Enabled
Application Migration Service Replication2
- No Public Replication Instances
- AMS Replication Configuration Template is Not Configured to Assign Public IPs
EFS File Systems2
- No Public EFS Mount Targets
- EFS file systems should restrict public access
IAM Roles1
- No Publicly Assumable IAM Roles
S3 Public Access Controls1
- No Public Buckets
ECR Repositories1
- No Public Repositories
KMS Keys1
- No Public KMS Keys
Lambda Functions1
- No Public Functions
Lambda Function URLs1
- No Public Lambda URLs Without Authentication
OpenSearch Domains1
- No Public Elasticsearch Clusters
Glue Dev Endpoints1
- No Public Glue Dev Endpoints
SNS Topics1
- No Public SNS Topics
SQS Queues1
- No Public SQS Queues
EC2 AMIs1
- No Public AMIs
EC2 Launch Templates1
- EC2 Launch Templates Do Not Assign Public IPs
EBS Snapshots1
- EBS snapshots should not be publicly restorable
ECS Services1
- No Public ECS/Fargate Services
RDS Snapshots1
- No Public RDS Snapshots
AppSync GraphQL APIs1
- AppSync Endpoints Protected by WAF
Redshift Clusters1
- No Public Redshift Clusters
Backup Vaults1
- No Public Backup Vaults
Classic Load Balancers1
- No Public Classic Load Balancers
Load Balancers1
- ALBs Protected by WAF
SES Identities1
- No Publicly Accessible SES Identities
CloudFront WAF Protection1
- CloudFront Protected by WAF
Systems Manager Automation1
- No Public SSM Documents (Customer-Owned)
DMS Replication Instances1
- No Public Replication Instances
EKS Clusters1
- No Public EKS Clusters (Control Plane)
EKS Control Plane1
- EKS Control Plane Public Access is Restricted
DocumentDB Snapshots1
- No Public DocumentDB Snapshots
Neptune Snapshots1
- No Public Neptune Clusters
Amazon MQ Brokers1
- No Public Amazon MQ Brokers
CloudTrail S3 Log Buckets1
- CloudTrail S3 Bucket Not Publicly Accessible
Auto Scaling Launch Configurations1
- Auto Scaling Launch Configuration Instances Do Not Assign Public IPs
VPCs1
- Auto Assign Public IP is Disabled for Subnets
VPC Route Tables1
- VPC Route Tables Restrict Public Access to IGW
Bedrock AgentCore Runtimes1
- Bedrock AgentCore runtimes should be configured with VPC network mode
Bedrock AgentCore Browser Sessions1
- Bedrock AgentCore custom browsers should not use public network mode
MSK Clusters1
- MSK clusters should have public access disabled
S3 Glacier Vaults1
- Glacier vault should restrict public access
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
