Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Data Protection Best Practices
30 controls
17 services covered
Covers sensitive-data protection — Macie discovery, S3 public-access guardrails, KMS key health, Secrets Manager, encrypted SSM parameters, secrets in EC2 user data and CodeBuild, CloudTrail data events, and data-access IAM risks.
What we check
Secrets Manager Secrets5
- Secrets Manager or Encrypted SSM Parameters Present
- Secrets Manager Secrets Automatic Rotation is Enabled
- Secret Resource Policy Configured
- Secrets Manager Secrets Use Custom KMS Key
- Secrets Manager Secrets Are Rotated Per Schedule
Macie Organization Settings3
- Macie Auto-Enroll Accounts in the Organization
- Macie Findings are Aggregated to a Dedicated Account
- Macie Management is Delegated in the Organization
IAM Policies3
- No IAM Principals with Unrestricted S3 Access
- No IAM Principals with Unrestricted S3 Read Access
- No IAM Principals with Access to Get All Secrets
IAM Identity Center Permission Sets3
- No SSO Permission Set with Unrestricted S3 Access
- No SSO Permission Set with Unrestricted S3 Read Access
- No SSO Permission Set with Access to Get All Secrets
S3 Public Access Controls2
- S3 Block Public Access is Enabled (Account-Level)
- S3 general purpose buckets should block public access
KMS Keys2
- Ensure that KMS Key Rotation is Enabled
- KMS Keys Not Pending Deletion
Systems Manager Automation2
- SSM Parameters Are Encrypted
- SSM Automation should have CloudWatch logging enabled
Macie Settings1
- Amazon Macie Enabled
Macie Findings1
- Amazon Macie Active Findings
Macie S3 Bucket Monitoring1
- Amazon S3 Buckets Are Protected by Macie
S3 Encryption1
- S3 Bucket Key is Enabled
EMR Security Configurations1
- EMR Security Configuration Encryption at Rest Enabled
Auto Scaling Launch Configurations1
- Auto Scaling Launch Config User Data Has No Sensitive Data
CodeBuild Project Environments1
- CodeBuild Environment Variables Do Not Contain Secrets
CloudFormation Stacks1
- CloudFormation Stack Outputs Do Not Contain Secrets
CloudTrail S3 Log Buckets1
- CloudTrail S3 Bucket Not Publicly Accessible
EC2 User Data1
- EC2 instances user data should not have secrets
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
