Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Serverless & Integration Security
24 controls
4 services covered
Reviews Function Apps, Logic Apps, API Management, and Event Grid integration controls, including authentication, certificates, CORS, logging, TLS, runtime versions, remote debugging, managed identity, and virtual network access.
What we check
Function Apps18
- App Service Authentication is Enabled for Function Apps
- Function App Java Runtime is Not Obsolete
- Function App Python Runtime is Not Obsolete
- Function App Restrict Public Access
- Function App has Incoming Client Certificates Enabled
- Function Apps Should Not Have CORS Configured To Allow Every Resource To Access Your Apps
- Function Apps Should Have Resource Logs Enabled
- Function Apps Should Have Failed Request Tracing Enabled
- Function App Health Check Enabled
- HTTP Logs Should Be Enabled For Function Apps
- Function App Redirect HTTP to HTTPS
- Remote Debugging Should Be Disabled For Function Apps
- Function Apps are Using Virtual Network Service Endpoint
- Function App Uses Latest TLS Version
- Function Apps Should Use Managed Identity
- Function App Worker More Than One
- Function Apps FTP Deployment Disabled
- Function Apps are Using the latest HTTP Version (2)
Event Grid Triggers3
- EventGrid Domains Use Managed Identity
- EventGrid Topics Use Managed Identity
- EventGrid Topics Do Not Use Local Authentication
API Management Services2
- API Management Service Client Certificate Should Be Enabled
- API Management Service API Should Use Virtual Network
Logic Apps1
- Resource Logs are Enabled for Logic App Workflows
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
