Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Compute Best Practices
30 controls
9 services covered
Reviews EC2 and Auto Scaling posture — IMDSv2, Systems Manager management and patch compliance, launch templates, user data, instance profiles, monitoring, public administration paths, and operational hygiene.
What we check
EC2 Instances8
- EC2 Instance Metadata Service v2 Enforced
- EC2 Instances in a VPC (No Classic EC2)
- EC2 Instance not launched with Key Pair
- EC2 Instances Older than 1 Year
- Ensure Restricted Remote Administration Ports (SSH/RDP) Access to EC2 Instances
- EC2 Detailed Monitoring Enabled
- EC2 Instances Managed by Systems Manager (SSM)
- EC2 Instances Compliant with SSM Patching Requirements
EC2 Instance Roles8
- IAM Instance Profile is Attached to EC2 Instance
- EC2 instance IAM should not allow pass role and lambda invoke function access
- EC2 instance IAM role should not allow management level access
- EC2 instance IAM role should not allow data destruction access
- EC2 instance IAM role should not allow cloud log tampering access
- EC2 instance IAM role should not allow database management write access
- EC2 instance IAM role should not allow destruction KMS access
- EC2 instance IAM role should not allow destruction RDS access
Auto Scaling Launch Configurations4
- Auto Scaling Launch Configuration Metadata Response Hop Limit is 1
- Auto Scaling Launch Configuration has IMDSv2 Enforced
- Auto Scaling Launch Configuration Instances Do Not Assign Public IPs
- Auto Scaling Launch Config User Data Has No Sensitive Data
Auto Scaling Groups3
- EC2 Auto Scaling Groups Should Use EC2 Launch Templates
- Auto Scaling Group Has No Suspended Processes
- Auto Scaling Group Propagates Tags to EC2 Instances
EC2 Network Interfaces2
- EC2 network interfaces should have source/destination checking enabled
- Ensure unused ENIs are removed
Systems Manager Automation2
- EC2 Instance Compliant SSM Association Status
- Systems Manager (SSM) Agent Auto-Update Enabled
EBS Volumes1
- EC2 Instance EBS Optimization Enabled
EC2 AMIs1
- Ensure Images (AMI) are not older than 90 days
EC2 User Data1
- EC2 instances user data should not have secrets
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
