Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Agentic AI Best Practices
12 controls
7 services covered
Checks Bedrock Agents, Flows, Knowledge Bases, and AgentCore — encryption, guardrails, authorization, VPC network mode, session recording, and data-retention posture for AI agents.
What we check
Bedrock Knowledge Bases3
- Bedrock Knowledge Bases Ingestion Logging Enabled
- Bedrock Knowledge Bases Resources Encrypted with Customer-Managed KMS Key
- Configure Data Deletion Policy for Bedrock Knowledge Base Data
Bedrock Agents2
- Agents for Amazon Bedrock Encrypted with Customer-Managed KMS Key
- Use Bedrock Guardrails to Protect Agent Sessions
Bedrock Flows2
- Bedrock Flows Resources Encrypted with Customer-Managed KMS Key
- Bedrock Flows Are Configured
Bedrock AgentCore Browser Sessions2
- Bedrock AgentCore custom browsers should not use public network mode
- Bedrock AgentCore custom browsers should have session recording enabled
Bedrock Prompt Management1
- Bedrock Prompt Catalog Implemented with Versioning
Bedrock AgentCore Runtimes1
- Bedrock AgentCore runtimes should be configured with VPC network mode
Bedrock AgentCore Gateways1
- Bedrock AgentCore Gateways should require authorization for inbound requests
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
