Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Encryption in Transit
32 controls
23 services covered
Ensures data in transit is protected with modern TLS and HTTPS — secure listeners and policies on load balancers and CloudFront, HTTPS-only S3 and API Gateway, and in-transit encryption for RDS, Redshift, OpenSearch, MSK, ElastiCache, DocumentDB, EFS, EMR, Glue, SageMaker, DMS, and SES.
What we check
CloudFront TLS and HTTPS4
- CloudFront HTTPS Enforced
- CloudFront No Deprecated SSL Protocols
- CloudFront Security Policy Check
- CloudFront SNI Enabled Check
Classic Load Balancers3
- Load Balancers Encrypted Listeners Only
- Load Balancer TLS Listener Protocol Version
- Classic Load Balancers Use Secure Ciphers Only
OpenSearch Domains3
- OpenSearch In-Transit Encryption Enabled
- OpenSearch Requires HTTPS Connections
- Connections to OpenSearch domains should be encrypted using the latest TLS security policy
MSK Clusters2
- MSK TLS In-Transit Encryption Enabled
- MSK Cluster Node-to-Node Encryption Enabled
RDS DB Instances2
- RDS for SQL Server DB instances should be encrypted in transit
- RDS for MariaDB DB instances should be encrypted in transit
S3 Buckets1
- Bucket SSL is Enforced
Load Balancers1
- NLB TLS Listener Security Policy Configured
Application Load Balancers1
- Application Load Balancers HTTP to HTTPS Redirect Enabled
CloudFront Origins1
- CloudFront Traffic to Origin Encrypted Check
Redshift Clusters1
- Redshift In-Transit Encryption
Glue Data Catalog and Connections1
- Glue Database Connection SSL Encrypted
MSK Connect Connectors1
- MSK Connect connectors should be encrypted in transit
ElastiCache Replication Groups1
- ElastiCache Redis In-Transit Encryption
DMS Replication Instances1
- DMS Redis TLS/SSL Encryption
DynamoDB Accelerator (DAX) Clusters1
- DAX Cluster Encryption in Transit is Enabled
EFS File Systems1
- EFS File Systems Enforce SSL/TLS In Transit
SageMaker Training Jobs1
- SageMaker Training Job Inter-Container Encryption Enabled
EMR Clusters1
- EMR Cluster Encryption In Transit Enabled
API Gateway Custom Domains1
- API Gateway domain names should use recommended security policies
DocumentDB Clusters1
- Amazon DocumentDB clusters should be encrypted in transit
RDS DB Proxies1
- RDS DB proxies should require TLS encryption for connections
Redshift Serverless Workgroups1
- Connections to Redshift Serverless workgroups should be required to use SSL
SES Configuration Sets1
- SES configuration sets should have TLS enabled for sending emails
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
