Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Data Protection Best Practices
47 controls
5 services covered
Focuses on direct data-protection controls for storage accounts, Key Vault, protected log storage, databases, and Data Lake Store, including public-access blocks, encryption, key lifecycle, soft delete, versioning, TLS, OAuth defaults, and shared-key restrictions.
What we check
Storage Accounts17
- Storage Accounts Public Access Blocked
- Storage Accounts Blob Containers Anonymous Access Disabled
- Storage Accounts Default Network Access Denied
- Secure Transfer Required
- Storage Accounts Enforces TLS 1.2 or higher
- Storage Accounts are Encrypted with CMK
- Storage Accounts Encryption Scopes Encrypted with CMK
- Storage Accounts Infrastructure Encryption Enabled
- Storage Account Encryption at Rest Using MMK
- Cross Tenant Replication Should Be Disabled for Storage Accounts
- Default to Microsoft Entra Authorization Should Be Enabled for Storage Accounts
- Shared Key Access Should Be Disabled for Storage Accounts
- Storage Accounts Soft Delete Enabled
- Blob Versioning Enabled
- File Share Soft Delete Enabled
- File Share SMB Channel Encryption AES-256-GCM
- File Share SMB Protocol Version 3.1.1
Key Vaults15
- KeyVault Firewall Enabled
- KeyVault Vault Public Network Access Disabled
- Key Vault uses Private Link
- KeyVault Vault Recoverable
- KeyVault Soft Delete Enabled
- KeyVault Purge Protection Enabled
- Key Vault uses RBAC Permission Model
- Key Vault Keys Have an Expiration Date
- Key Vault Keys Have Automatic Rotation Enabled
- Key Vault Secrets Have an Expiration Date
- Key Vault Certificates Have Validity Period Less Than or Equal to 12 Months
- Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Expiration Date is set for all Keys in RBAC Key Vaults
- Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Expiration Date is set for all Secrets in RBAC Key Vaults
Database Data Protection10
- SQL Server Database Transparent Data Encryption Enabled
- Servers TDE CMK Encryption Enabled
- SQL Database Vulnerability Assessment Findings are Resolved
- Vulnerability Assessment should be Enabled on your SQL Servers
- CosmosDB Account Should Use CMK To Encrypt Data At Rest
- CosmosDB Account Should Disable Key Based Metadata Write Access
- Infrastructure Encryption is Enabled for PostgreSQL Servers
- PostgreSQL Flexible Servers Should be Encrypted with CMK
- Servers CMK Encryption at Rest
- Flexible Servers CMK Encryption at Rest
Protected Log Storage4
- Activity Log Storage Container Encrypted with BYOK
- Operational Log Storage Container Encrypted with BYOK
- Activity Log Storage Container Not Publicly Accessible
- Operational Log Storage Container Not Publicly Accessible
Data Lake Stores1
- Require Encryption on Data Lake Store Accounts
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
