Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Edge & Application Best Practices
39 controls
20 services covered
Covers edge-facing services — CloudFront, WAF associations, API Gateway, AppSync, Route 53, SES, and ACM — for TLS policies, logging, certificate health, and encrypted origin connections.
What we check
ACM Certificates6
- ACM certificates will expire in 7 days or less
- ACM certificates have Certificate Transparency Logging Enabled
- ACM Certificates Have No Pending Validation
- ACM Certificates Not in FAILED State
- Check RSA Certificate Key Length Compliance
- Imported and ACM-issued certificates should be renewed within 30 days of expiration
WAF Resource Associations5
- WAF Classic (Global/CloudFront) Rule Has Condition(s) Attached
- WAF Classic (Regional) Rule Has Condition(s) Attached
- WAF Classic (Regional) Web ACL Has Rule(s) Attached
- WAF Classic Web ACL Associated to a Resource
- WAF Classic Web ACL Has Rule(s) Attached
Route 53 Domains5
- Route 53 domains auto renew should be enabled
- Route 53 domains should not expire within next 30 days
- Route 53 domains should not be expired
- Route53 domains privacy protection should be enabled
- Route 53 domains should have transfer lock enabled
CloudFront TLS and HTTPS3
- CloudFront Distribution does not Use Deprecated SSL protocols
- CloudFront Security Policy Check
- CloudFront SNI Enabled Check
CloudFront Logging2
- CloudFront Distribution has Access Logging Enabled
- CloudFront Distribution Real-Time Logging Enabled
CloudFront Origins2
- CloudFront Origin Failover Check
- CloudFront Traffic to Origin Encrypted Check
WAF Logging2
- WAF WebACL Logging Enabled
- WAFv2 Rule Group Logging Enabled
WAF Rule Groups2
- WAFv2 Rule Group Content Check
- WAF Classic Rule Group Contains Rule(s)
CloudFront WAF Protection1
- CloudFront Distribution is Protected by AWS WAF
CloudFront Field-Level Encryption1
- CloudFront Distribution has Field-Level Encryption Enabled
CloudFront Signed URLs and Cookies1
- CloudFront distributions should use trusted key groups for signed URLs and cookies
WAF Web ACLs1
- No Empty WAF Web ACLs
WAF Classic Web ACLs1
- WAF Classic WebACLs Found
API Gateway REST APIs1
- API Gateway Stage Protected by AWS WAF
API Gateway Custom Domains1
- API Gateway domain names should use recommended security policies
AppSync GraphQL APIs1
- AppSync is WAF protected
Route 53 Hosted Zones1
- Route53 Public Zones Logging Enabled
Route 53 DNS Firewall1
- Route53 DNS Firewall Mutation Protection Enabled
SES Identities1
- No Publicly Accessible SES Identities
SES Configuration Sets1
- SES configuration sets should have TLS enabled for sending emails
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
