Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Serverless Best Practices
38 controls
25 services covered
Checks managed application services — Lambda, API Gateway, AppSync, Step Functions, EventBridge, SNS, SQS, and Cognito — with Inspector and GuardDuty coverage for serverless workloads.
What we check
Inspector Lambda Scanning4
- Amazon Inspector Lambda Standard Scanning is Enabled
- Inspector Lambda Code Scanning Enabled
- Lambda Functions Covered by Inspector Vulnerability Scanning
- No active Inspector Findings for Lambda Functions
Lambda Function Configuration3
- Lambda Code Signing is Enabled
- Lambda Dead-Letter Queue Configured
- Lambda Functions Concurrent Execution Limit Configured
Cognito User Pools3
- Cognito user pool passwords should require min length 8, lower, upper, number, symbol, and temporary passwords <= 7 days
- MFA should be enabled for Cognito user pools
- Cognito user pools should have deletion protection enabled
Lambda Functions2
- Lambda Resource-Based Policy Configured
- No Public Accessible Lambda Functions
Lambda Networking2
- Lambda functions should be in a VPC
- Lambda Multi-AZ Availability Check
GuardDuty Lambda Protection2
- GuardDuty Lambda Protection Enabled
- GuardDuty Lambda Protection Auto-Enroll Accounts in the Organization
API Gateway REST APIs2
- API Gateway Stage with Client Certificate Configured
- API Gateway stages should have authorizers configured
API Gateway Methods2
- API Gateway methods authorizer should be configured
- API Gateway methods request parameter should be validated
AppSync GraphQL APIs2
- AppSync is WAF protected
- AWS AppSync GraphQL APIs should not be authenticated with API keys
Lambda Function URLs1
- No Public Lambda Function URLs Without Authentication
Lambda Logging1
- Lambda function Logging is enabled
Lambda Runtimes1
- Lambda Functions do not use Obsolete Runtimes
API Gateway HTTP and WebSocket APIs1
- Websocket and HTTP API routes should specify an authorization type
API Gateway Custom Domains1
- API Gateway domain names should use recommended security policies
AppSync API Caches1
- AppSync API Cache Encryption at Rest Check
AppSync Logging1
- AWS AppSync API Logging Configuration Check
Step Functions State Machines1
- AWS Step Functions State Machine Logging Enabled Check
EventBridge Schema Registries1
- Custom Schema Registry Policy Attachment Check
EventBridge Event Buses1
- Custom EventBridge Event Bus Policy Attachment Check
EventBridge Global Endpoints1
- EventBridge Global Endpoint Event Replication Enabled Check
SNS Topics1
- SNS Topic Message Delivery Notification Enabled Check
SQS Queues1
- No Public SQS Queues
Cognito Identity Pools1
- Cognito identity pools should not allow unauthenticated identities
Directory Service Directories1
- Directory Service directories should have SNS notification enabled
EC2 Instance Roles1
- EC2 instance IAM should not allow pass role and lambda invoke function access
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
