Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Encryption at Rest
44 controls
33 services covered
Checks that stored data uses customer-managed keys (CMK) and infrastructure encryption across disks, storage accounts, SQL/MySQL databases, container registries, Service Bus and more.
What we check
Storage Accounts4
- Storage Accounts are Encrypted with CMK
- Storage Accounts Encryption Scopes Encrypted with CMK
- Storage Accounts Infrastructure Encryption Enabled
- Storage Account Encryption at Rest Using MMK
Managed Disks3
- Disk Encrypted with CMK
- Unattached Disks Encrypted with CMK
- Ensure Sensitive Disks are Double Encrypted with Customer and Platform Managed Key
Data Explorer Clusters3
- Disk Encryption Should Be Enabled On Azure Data Explorer
- Double Encryption Should Be Enabled On Azure Data Explorer
- Azure Data Explorer Encryption At Rest Should Use A CMK
AKS Nodes2
- AKS Cluster Nodes Disk Encrypted CMK
- AKS Cluster Nodes Cache Encrypted at Host
HDInsight Clusters2
- HDInsight cluster encrypted at rest with CMK
- HDInsight cluster encryption at host enabled
Log Storage Containers2
- Activity Log Storage Container Encrypted with BYOK
- Operational Log Storage Container Encrypted with BYOK
MySQL Servers2
- Servers CMK Encryption at Rest
- Servers Infrastructure Encryption Enabled
App Configuration Stores1
- App Configuration CMK Encryption Should Be Enabled
App Service Environments1
- Environment Internal Encryption Enabled
Automation Accounts1
- Automation Account Variables Should Be Encrypted
Batch Accounts1
- Batch Accounts Should Be Encrypted With CMK
Cognitive Services Accounts1
- Cognitive Service Account Encrypted with CMK
Virtual Machines1
- Ensure Virtual Machines Have Encryption At Host Enabled
Virtual Machine Scale Sets1
- Virtual Machine Scale Sets Have Encryption At Host Enabled
Container Instances1
- Azure Container Instance Container Group Should Use CMK for Encryption
Container Registries1
- Container Registry Encrypted with CMK
Cosmos DB Accounts1
- CosmosDB Account Should Use CMK To Encrypt Data At Rest
Data Box Edge Devices1
- Data Box Edge Devices Should Use SKUs with Double Encryption
Data Factories1
- Azure Data Factories Should Be Encrypted With CMK
Data Lake Store Accounts1
- Require Encryption on Data Lake Store Accounts
Databricks Workspaces1
- Databricks Workspaces have Customer-Managed Key Configured
Event Hub Namespaces1
- Event Hub Namespaces Should By Encrypted with CMK
Healthcare FHIR Services1
- Azure API for FHIR is Encrypted at Rest with CMK
Machine Learning Workspaces1
- Machine Learning Workspaces should be Encrypted with CMK
MySQL Flexible Servers1
- Flexible Servers CMK Encryption at Rest
PostgreSQL Servers1
- Infrastructure Encryption is Enabled for PostgreSQL Servers
PostgreSQL Flexible Servers1
- PostgreSQL Flexible Servers Should be Encrypted with CMK
Service Bus Namespaces1
- ServiceBus Namespace CMK Encrypted
SQL Servers1
- Servers TDE CMK Encryption Enabled
SQL Databases1
- SQL Server Database Transparent Data Encryption Enabled
SQL Managed Instances1
- MSSQL Managed Instance Encryption at Rest Using CMK
HPC Caches1
- Storage Caches Should Be Encrypted Using CMK
Synapse Workspaces1
- Synapse Workspaces Should Use Customer-Managed Keys to Encrypt Data at Rest
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
