Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

End-User Services Best Practices
16 controls
9 services covered
Checks user-facing managed services — WorkSpaces, AppStream 2.0, Cognito, Connect, SES, and Directory Service — for encryption, authentication, session limits, logging, and public-access controls.
What we check
Cognito User Pools4
- Cognito User Pool Advanced Security Enabled
- Cognito user pool passwords should require min length 8, lower, upper, number, symbol, and temporary passwords <= 7 days
- MFA should be enabled for Cognito user pools
- Cognito user pools should have deletion protection enabled
AppStream Fleets4
- AppStream fleet default internet access should be disabled
- AppStream fleet idle disconnect timeout should be set to less than or equal to 10 mins
- AppStream fleet max user duration should be set to less than 10 hours
- AppStream fleet session disconnect timeout should be set to less than or equal to 5 mins
WorkSpaces2
- WorkSpaces Root Volume Encryption Check
- Amazon WorkSpaces User Volume Encryption Enabled
Cognito Identity Pools1
- Cognito identity pools should not allow unauthenticated identities
Directory Service Logs1
- Directory Service Domain Controller Has Security Event Logging Enabled
Directory Service Certificates1
- Directory Service Certificates Do Not Expire Within 90 Days
Directory Service Snapshots1
- Directory Service Manual Snapshots ≥ 2
SES Identities1
- No Publicly Accessible SES Identities
Amazon Connect Instances1
- Connect Customer instances should have CloudWatch logging enabled
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
