Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Container Best Practices
29 controls
14 services covered
Covers ECS, EKS, and ECR — image scanning with Inspector, GuardDuty runtime protection, private endpoints, supported Kubernetes versions, logging, encryption, lifecycle policies, and risky task definitions.
What we check
GuardDuty EKS Protection6
- GuardDuty EKS Audit Logs Protection Enabled
- GuardDuty EKS Audit Logs Protection Auto-Enroll Accounts in the Organization
- GuardDuty EKS Runtime Protection Enabled
- GuardDuty EKS Runtime Protection Auto-Enroll Accounts in the Organization
- GuardDuty Runtime Protection EKS Automated Agent Configuration Enabled
- GuardDuty Runtime Protection EKS Automated Agent Configuration Auto-Enroll Enabled in the Organization
EKS Clusters5
- EKS Clusters Use Latest Supported Kubernetes Version
- EKS Control Plane Public Access Disabled
- EKS clusters should run on a supported Kubernetes version
- EKS clusters should not be configured within a default VPC
- EKS clusters should not use multiple security groups
Inspector ECR Scanning3
- Inspector Scanning Enabled for ECR
- ECR Repositories Covered by Inspector Vulnerability Scanning
- No active Inspector Findings for ECR Repositories
ECS Clusters2
- ECS Cluster Encryption at Rest Enabled
- ECS Container Insights Enabled Check
ECS Task Definitions2
- ECS Task Definition Containers Do Not Store Secrets in Environment
- ECS Task Definitions should use in-transit encryption for EFS volumes
EKS Control Plane2
- EKS Control Plane Public Access is Restricted
- EKS Control Plane Logging Enabled
GuardDuty Runtime Protection2
- GuardDuty Runtime Protection ECS Fargate Automated Agent Configuration Enabled
- GuardDuty Runtime Protection ECS Fargate Automated Agent Configuration Auto-Enroll Enabled in the Organization
ECS Services1
- No Public ECS/Fargate Services
ECS Capacity Providers1
- ECS capacity providers should have managed termination protection enabled
EKS Secrets1
- Kubernetes Secrets are Encrypted with KMS
EKS Node Groups1
- EKS node groups should run on a supported Kubernetes version
ECR Repositories1
- ECR Lifecycle Policies Enabled
VPC Endpoints1
- VPCs should be configured with an interface endpoint for ECR API
SageMaker Models1
- SageMaker models should use private registry in VPC for multi-container inference pipelines
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
