Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Key & Secrets Lifecycle
12 controls
5 services covered
Checks Key Vault key, secret, and certificate expiration or rotation controls, RBAC-backed access model, and storage account key lifecycle controls such as rotation reminders and shared-key restrictions.
What we check
Key Vault Keys4
- Key Vault Keys Have an Expiration Date
- Key Vault Keys Have Automatic Rotation Enabled
- Expiration Date is set for all Keys in Non-RBAC Key Vaults
- Expiration Date is set for all Keys in RBAC Key Vaults
Key Vault Secrets3
- Key Vault Secrets Have an Expiration Date
- Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- Expiration Date is set for all Secrets in RBAC Key Vaults
Storage Keys3
- Storage Account Access Keys Should Be Periodically Regenerated
- Key Rotation Reminders Should Be Enabled for Storage Accounts
- Shared Key Access Should Be Disabled for Storage Accounts
Key Vault Certificates1
- Key Vault Certificates Have Validity Period Less Than or Equal to 12 Months
Key Vault Access Model1
- Key Vault uses RBAC Permission Model
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
