Reports for Every Cloud

Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.

58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results
ASecureCloud report preview
AWS logo

End-User Services Best Practices

16 controls
9 services covered

Checks user-facing managed services — WorkSpaces, AppStream 2.0, Cognito, Connect, SES, and Directory Service — for encryption, authentication, session limits, logging, and public-access controls.

What we check

Cognito User Pools4
  • Cognito User Pool Advanced Security Enabled
  • Cognito user pool passwords should require min length 8, lower, upper, number, symbol, and temporary passwords <= 7 days
  • MFA should be enabled for Cognito user pools
  • Cognito user pools should have deletion protection enabled
AppStream Fleets4
  • AppStream fleet default internet access should be disabled
  • AppStream fleet idle disconnect timeout should be set to less than or equal to 10 mins
  • AppStream fleet max user duration should be set to less than 10 hours
  • AppStream fleet session disconnect timeout should be set to less than or equal to 5 mins
WorkSpaces2
  • WorkSpaces Root Volume Encryption Check
  • Amazon WorkSpaces User Volume Encryption Enabled
Cognito Identity Pools1
  • Cognito identity pools should not allow unauthenticated identities
Directory Service Logs1
  • Directory Service Domain Controller Has Security Event Logging Enabled
Directory Service Certificates1
  • Directory Service Certificates Do Not Expire Within 90 Days
Directory Service Snapshots1
  • Directory Service Manual Snapshots ≥ 2
SES Identities1
  • No Publicly Accessible SES Identities
Amazon Connect Instances1
  • Connect Customer instances should have CloudWatch logging enabled

Run these reports on your own cloud

Connect an account and get your first set of reports in minutes — free to start, no credit card required.