Back to Security and compliance

SOC 2

523 complying controls out of 525

Last synchronised :

The counter is the one produced by our continuous monitoring platform Aikido Security, and the detail lists the controls it reports as satisfied. The two figures may differ slightly.

Assessment, type and control names are those of the original frameworks.

Request the security audit report

Configured monitoring for code repositories

ControlStatus
Configured monitoring for all code repositoriescomplying

Configured monitoring for container images

ControlStatus
Configured monitoring for all container imagescomplying

Configured monitoring for domains

ControlStatus
Configured monitoring for domainscomplying

Does not have any severe open source dependency issues

ControlStatus
No active critical open source dependency issuescomplying
No active high severity open source dependency issuescomplying

Does not have any severe surface monitoring issues

ControlStatus
No active critical surface monitoring issuescomplying
No active high severity surface monitoring issuescomplying

Properly manages the identity of cloud users

ControlStatus
Firewall rules restrict public ingress to port 636complying
No user has both the Service Account User and Service Account Admin rolecomplying
Service accounts have strict access permissionscomplying
Users are logging in securelycomplying
Users are only allowed to use corporate emailscomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Applies the least privilege principle for cloud resource

ControlStatus
Access Approval is enabled for the projectcomplying
Compute instances have OS Login enabledcomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
VM instances have strict access permissionscomplying

Applies the least privilege principle to cloud resources

ControlStatus
Access to BigQuery datasets are restrictedcomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
KMS keys have strict access permissionscomplying
Kubernetes master endpoint is not publicly availablecomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying

Enabled security logging for cloud instances

ControlStatus
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Requires MFA for cloud users

ControlStatus
Users are logging in securelycomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Applies the least privilege principle for cloud resource

ControlStatus
Access Approval is enabled for the projectcomplying
Compute instances have OS Login enabledcomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
Kubernetes pods are isolatedcomplying
Load Balancers only accept HTTPS connectionscomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
VM instances have strict access permissionscomplying

Does not have any severe infrastructure as code issues

ControlStatus
No active critical infrastructure as code issuescomplying
No active high severity infrastructure as code issuescomplying

Has deletion protection for cloud resources

ControlStatus
Cloud SQL instances have deletion protection enabledcomplying
VM instances have deletion protection enabledcomplying

Properly manages the identity of cloud users

ControlStatus
Firewall rules restrict public ingress to port 636complying
Users are logging in securelycomplying
Users are only allowed to use corporate emailscomplying

Has separate production and test environments

ControlStatus
No cloud environment used for mixed purposes (eg production and staging)complying

Prevents unauthorized access via ssh

ControlStatus
AWS EKS Node groups have implicit SSH access from any IPcomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow unrestricted SSH accesscomplying

Prevents unauthorized public access to database

ControlStatus
BigQuery table is anonymously or publicly accessiblecomplying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
No firewall rule allows MongoDB access from the internetcomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying

Prevents unauthorized public access to file storage

ControlStatus
Azure Storage Account allow public accesscomplying
Azure Storage blobs do not restrict public access for nested itemscomplying
Firewall rules restrict public ingress to port 3020complying
S3 bucket grants public access to all contentscomplying
S3 Buckets should have block public access globallycomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying

Has secured load balancer access points

ControlStatus
Users are logging in securelycomplying

Has secured load balancer access points

ControlStatus
AWS EKS Node groups have implicit SSH access from any IPcomplying
Compute instances have OS Login enabledcomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow unrestricted SSH accesscomplying
Load Balancers only accept HTTPS connectionscomplying
Project-wide SSH keys are blockedcomplying

Applies the least privilege principle to cloud resources

ControlStatus
Access to BigQuery datasets are restrictedcomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
KMS keys have strict access permissionscomplying
Kubernetes master endpoint is not publicly availablecomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying

Encrypts data at rest

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
KMS keys have key rotation enabledcomplying
SNS topics are not encrypted at restcomplying
SQS queue data is not encryptedcomplying
Virtual Machines have confidential computing enabledcomplying

Enforces encryption of data in transit

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
App does not validate SSL certificates properlycomplying
App uses an outdated TLS protocolcomplying
App uses an outdated TLS protocolcomplying
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHcomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Cloud functions require HTTPS invocationscomplying
Cloud SQL db not enforcing SSLcomplying
Cloud SQL instance requires SSL connectionscomplying
Cookie missing HttpOnly flagcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying
Elasticsearch domain might have outdated TLS versioncomplying
Express is not emitting security headerscomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
HTTP Client misconfigured with SSL validation disabledcomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure HTTP Request detectedcomplying
Insecure TLS configuration detectedcomplying
Insecure usage of `requests` sends data over cleartextcomplying
Insecure websocket connection sends data over cleartextcomplying
Laravel cookies can be sent unencryptedcomplying
Load balancer allows invalid HTTP headerscomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Load Balancers only accept HTTPS connectionscomplying
NodeJS talks to database without encryptioncomplying
NodeJS talks to database without encryptioncomplying
Outbound Ansible connections are not encryptedcomplying
Outbound Ansible connections are not encryptedcomplying
Server certificates are not verified during SSL/TLS connectionscomplying
Server hostnames not verified during SSL/TLS connectionscomplying
Signature validation for dnf packages is offcomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying
Storage account does not enforce HTTPS-only trafficcomplying
TLS Certificate Validation Disabledcomplying
TLS Certificate Validation Disabledcomplying
Turning off TLS verification enables man-in-the-middle attackscomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using potentially unsafe FTP connections to move datacomplying
Using potentially unsafe FTP connections to move datacomplying
Weak SSL/TLS protocols usedcomplying

Has measures against SQL injection attacks

ControlStatus
NoSQL injection attack possiblecomplying
NoSQL injection attack possiblecomplying
NoSQL injection attack possiblecomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential NoSQL injection via string-based query concatenationcomplying
Potential SQL injection in Doctrine's QueryBuildercomplying
Potential SQL injection in sqlite3 via string-based query concatenationcomplying
Potential SQL injection through JDBC via string-based query concatenationcomplying
Potential SQL injection using sqflite execute sinkcomplying
Potential SQL injection via Drupal database functionalitycomplying
Potential SQL injection via dynamic raw query constructioncomplying
Potential SQL injection via dynamic raw query constructioncomplying
Potential SQL injection via dynamic raw query constructioncomplying
Potential SQL injection via Laravel functioncomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenationcomplying
Potential SQL injection via string-based query concatenation using AuraSQL framework functionscomplying
Potential SQL injection via Yii functioncomplying
Potential SQL injection when bypassing Django ORM with extra()complying
Potential SQL injection when bypassing Django ORM with RawSQL()complying
Potential SQL injection when bypassing Doctrine ORM with raw querycomplying

Is protected against command injections attacks

ControlStatus
A potential Swift command injection vulnerability has been identified due to the construction of an operating system command with user-controlled input.complying
Possible command injection via Process.Startcomplying
Possible command injection via Process.Startcomplying
Possible command injection via shell scriptcomplying
Possible command injection via user-controlled input to clojure.java.shell/shcomplying
Potential command injection via Command APIcomplying
Potential command injection via Process.runcomplying
Use of vulnerable ingress-nginx controllercomplying
Xpath injection attack could lead to information extractioncomplying
Xpath injection attack could lead to information extractioncomplying

Is protected against SSRF attacks

ControlStatus
A timing attack might allow hackers to bruteforce passwordscomplying
EC2 IAM roles vulnerable to SSRF attackscomplying
GCP Kubernetes engine clusters vulnerable to SSRF attackscomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
HTTP request might enable SSRF attackcomplying
Potential file inclusion attack via reading filecomplying
Potential file inclusion attack via reading filecomplying
Potential file inclusion attack via reading filecomplying
Potential user input in HTTP request may allow SSRF attackcomplying
Potential user input in HTTP request may allow SSRF attackcomplying
Simple DOS attack possible due to http.server misconfigurationcomplying
User data used in Puppeteer methods can result in SSRFcomplying
User data used in Puppeteer methods can result in SSRFcomplying

Prevents the exposure of sensitive data

ControlStatus
Currently there are no exposed secretscomplying

Prevents XSS attacks

ControlStatus
Apex Visualforce misconfigurations may lead to Cross-Site Scripting (XSS) Vulnerabilitiescomplying
Directly writing unsanitized input to http.ResponseWriter can lead to XSScomplying
Disabling JSON HTML Escaping in ActiveSupport may lead to XSScomplying
DOM Cross-Site Scripting (XSS) via Insecure jQuery Execution Sinkscomplying
HttpServletResponse output can be used for XSS attackscomplying
Improper sanitization in dynamic attribute bindings can lead to XSS attackscomplying
Input validation disabled in controllercomplying
Jinja2 template config can lead to XSS attackscomplying
Potential Cross Site Scripting (XSS) via window.location.hrefcomplying
Potential XSS due to enabling bypassSecurityTrustUrlcomplying
Potential XSS via MarkupStr(...) in Razor template may lead to XSScomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input can lead to XSS attackscomplying
Rendering unescaped input in EJS template can lead to XSS attackscomplying
Rendering unescaped input in handlebar/mustache template can lead to XSS attackscomplying
Rendering unescaped input in HTML template can lead to XSS attackscomplying
Unsanitized user input in jQuery DOM handling methods detectedcomplying
Unsanitized user input leads to cross-site scripting (XSS)complying
Using dangerouslySetInnerHTML in React can lead to XSS attackscomplying
Using document write methods can lead to XSS attackscomplying
Using document write methods can lead to XSS attackscomplying
Using document write methods can lead to XSS attackscomplying
Using raw on potential user input can leads to XSScomplying
Using v-html in Vue templates can lead to XSS attackscomplying

Requires MFA for cloud users

ControlStatus
Users are logging in securelycomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Encrypts data at rest

ControlStatus
Amazon EKS Clusters should have secrets encryption enabledcomplying
API Gateway REST API caching is unencryptedcomplying
AWS ElastiCache Redis cluster should have encryption at rest enabledcomplying
Docker image repository not encrypted at restcomplying
Elasticsearch domain is not encrypted at restcomplying
Ensure all data stored in the RDS is securely encrypted at restcomplying
KMS keys have key rotation enabledcomplying
SNS topics are not encrypted at restcomplying
Virtual Machines have confidential computing enabledcomplying

Enforces encryption of data in transit

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
App does not validate SSL certificates properlycomplying
App uses an outdated TLS protocolcomplying
App uses an outdated TLS protocolcomplying
AWS ElastiCache Replication Group should encrypt data in transit and enable Redis AUTHcomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Network Security Rule allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Account allows plaintext HTTP connectionscomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Cloud functions require HTTPS invocationscomplying
Cloud SQL db not enforcing SSLcomplying
Cloud SQL instance requires SSL connectionscomplying
Cookie missing HttpOnly flagcomplying
Deprecated SSL Protocol Usage Detectedcomplying
Deprecated SSL Protocol Usage Detectedcomplying
DNSSEC is disabledcomplying
DNSSEC is enabled for all managed zonescomplying
Elasticsearch domain might have outdated TLS versioncomplying
Express is not emitting security headerscomplying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 636complying
HTTP Client misconfigured with SSL validation disabledcomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure gRPC connection can lead to remote code executioncomplying
Insecure HTTP Request detectedcomplying
Insecure TLS configuration detectedcomplying
Insecure usage of `requests` sends data over cleartextcomplying
Insecure websocket connection sends data over cleartextcomplying
Laravel cookies can be sent unencryptedcomplying
Load balancer allows invalid HTTP headerscomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Load Balancers only accept HTTPS connectionscomplying
NodeJS talks to database without encryptioncomplying
NodeJS talks to database without encryptioncomplying
Outbound Ansible connections are not encryptedcomplying
Outbound Ansible connections are not encryptedcomplying
Server certificates are not verified during SSL/TLS connectionscomplying
Server hostnames not verified during SSL/TLS connectionscomplying
Signature validation for dnf packages is offcomplying
SQS queue data is not encryptedcomplying
SSL certificate verification turned off during requestscomplying
SSL certificate verification turned off during requestscomplying
Storage account does not enforce HTTPS-only trafficcomplying
TLS Certificate Validation Disabledcomplying
TLS Certificate Validation Disabledcomplying
Turning off TLS verification enables man-in-the-middle attackscomplying
Using potentially unsafe FTP connections to move datacomplying
Using potentially unsafe FTP connections to move datacomplying
Weak SSL/TLS protocols usedcomplying

Uses up to date cryptography libraries

ControlStatus
Hashes should include an unpredictable saltcomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using deprecated cryptographic librarycomplying

Applies the least privilege principle for cloud resource

ControlStatus
Access Approval is enabled for the projectcomplying
Access to BigQuery datasets are restrictedcomplying
API key restricts usage to certain APIscomplying
API key restricts usage to certain clientscomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Compute instances have IP forwarding disabledcomplying
Compute instances have OS Login enabledcomplying
Compute instances have serial port access disabledcomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
GKE clusters have the GKE Metadata Server enabledcomplying
GKE clusters have the Kubernetes Dashboard disabledcomplying
GKE node pools use dedicated service accountscomplying
KMS keys have strict access permissionscomplying
Kubernetes master endpoint is not publicly availablecomplying
Kubernetes pods are isolatedcomplying
No instance uses the default service accountcomplying
No user has both the Service Account User and Service Account Admin rolecomplying
Project-wide SSH keys are blockedcomplying
Service accounts have strict access permissionscomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying
Storage buckets have uniform bucket-level access enabledcomplying
Users are logging in securelycomplying
VM instances have strict access permissionscomplying

MFA is enforced for cloud users

ControlStatus
Users are logging in securelycomplying

Prevents public access to cloud resources

ControlStatus
Access to BigQuery datasets are restrictedcomplying
AKS API server does not limit access by IP rangescomplying
Amazon EKS Clusters public endpoints should not allow traffic from any IPcomplying
API Gateway endpoints do not require an API key or authorizationcomplying
AWS EKS Node groups have implicit SSH access from any IPcomplying
Azure Cognitive Services allows unrestricted public network accesscomplying
Azure Cosmos DB is publicly reachablecomplying
Azure Key Vault allows public network accesscomplying
Azure Storage Account allow public accesscomplying
Azure Storage blobs do not restrict public access for nested itemscomplying
BigQuery table is anonymously or publicly accessiblecomplying
Cloud functions are not publicly accessiblecomplying
Cloud functions have strict access policiescomplying
Cloud Storage bucket does not enforce public access preventioncomplying
Cloud Storage bucket does not enforce uniform bucket-level accesscomplying
Cloud Storage bucket is publicly accessiblecomplying
Compute instances do not have public IP addressescomplying
Dataproc cluster is anonymously or publicly accessiblecomplying
Default network exists in GCP projectcomplying
Firewall rule prevents Docker API access from anywherecomplying
Firewall rule prevents RDP access from anywherecomplying
Firewall rule prevents SSH access from anywherecomplying
Firewall rules allow RDP access from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow SSH from any public IPcomplying
Firewall rules allow unrestricted RDP accesscomplying
Firewall rules allow unrestricted SSH accesscomplying
Firewall rules do not allow unrestricted ingress to all ports and protocolscomplying
Firewall rules restrict public ingress to port 11214complying
Firewall rules restrict public ingress to port 11215complying
Firewall rules restrict public ingress to port 135complying
Firewall rules restrict public ingress to port 137complying
Firewall rules restrict public ingress to port 138complying
Firewall rules restrict public ingress to port 139complying
Firewall rules restrict public ingress to port 1433complying
Firewall rules restrict public ingress to port 1434complying
Firewall rules restrict public ingress to port 23complying
Firewall rules restrict public ingress to port 2379complying
Firewall rules restrict public ingress to port 2383complying
Firewall rules restrict public ingress to port 2484complying
Firewall rules restrict public ingress to port 27017complying
Firewall rules restrict public ingress to port 27018complying
Firewall rules restrict public ingress to port 27019complying
Firewall rules restrict public ingress to port 3000complying
Firewall rules restrict public ingress to port 3020complying
Firewall rules restrict public ingress to port 3306complying
Firewall rules restrict public ingress to port 389complying
Firewall rules restrict public ingress to port 4505complying
Firewall rules restrict public ingress to port 4506complying
Firewall rules restrict public ingress to port 5500complying
Firewall rules restrict public ingress to port 5800complying
Firewall rules restrict public ingress to port 61621complying
Firewall rules restrict public ingress to port 636complying
Firewall rules restrict public ingress to port 7001complying
Firewall rules restrict public ingress to port 8000complying
Firewall rules restrict public ingress to port 9200complying
Firewall rules restrict public ingress to port 9300complying
Key Vault is publicly accessiblecomplying
KMS cryptographic key policy allows public accesscomplying
KMS keys have strict access permissionscomplying
Kubernetes dashboard might be deployedcomplying
Kubernetes master endpoint is not publicly availablecomplying
No firewall rule allows access to Open Telemtry metrics endpoint from the internetcomplying
No firewall rule allows access to port 1720 from the internetcomplying
No firewall rule allows cPanel access from the internetcomplying
No firewall rule allows etcd access from the internetcomplying
No firewall rule allows MongoDB access from the internetcomplying
No firewall rule allows NFS access from the internetcomplying
No firewall rule allows Telnet access from the internetcomplying
No firewall rule allows Tomcat Cluster Receiver access from the internetcomplying
Profiling endpoint automatically exposed on /debug/pprofcomplying
Pub/Sub topic is anonymously or publicly accessiblecomplying
S3 bucket grants public access to all contentscomplying
S3 Buckets should have block public access globallycomplying
SQL instance root user has strict access permissionscomplying
SQL instances do not have a public IP assignedcomplying
SQL instances have strict access permissioncomplying
SQL Server is publicly reachablecomplying
Storage Buckets have proper access rulescomplying
Storage buckets have public access prevention enabledcomplying
Vertex AI notebook instance has a public IP addresscomplying

Enforces latest TLS version

ControlStatus
API Gateway stages are not using TLS 1.2 or highercomplying
Azure Storage Accounts does not enforce latest TLS versioncomplying
Elasticsearch domain might have outdated TLS versioncomplying
Load balancer allows unencrypted or encrypted traffic with outdated TLS policycomplying
Storage account does not enforce HTTPS-only trafficcomplying

Uses up to date cryptography libraries

ControlStatus
Hashes should include an unpredictable saltcomplying
Usage of deprecated or broken encryption detectedcomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Use of broken or outdated encryptioncomplying
Using deprecated cryptographic librarycomplying

Enabled security logging for cloud instances

ControlStatus
Alerting policies have a notification channel configuredcomplying
Amazon EKS Clusters should have control plane logging enabledcomplying
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Prevents container orchestration takeover

ControlStatus
AKS local admin account is still enabledcomplying
Dangerous Impersonate permission given to ServiceAccount or nodecomplying

Protects unauthorized runtime access

ControlStatus
Container processes can gain more privileges than its parentcomplying
Container running as root can allow attacker to escalate attackscomplying
Default Kubernetes settings allow containers to eavesdrop on traffic.complying
Default security context allows pods to access host system.complying
Docker container configured to run as user with root privilegescomplying
Docker container runs as default root usercomplying
Filesystem for docker container should not be writeablecomplying
Privileged container can allow attackers to escalate attackscomplying

Aikido Malware Scanner is enabled

ControlStatus
Aikido Malware Scanner is enabledcomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Connected code repositories

ControlStatus
Connect code repositoriescomplying

Connected public facing domain

ControlStatus
Connect public facing domaincomplying

Does not have any issues outside of their SLA

ControlStatus
No issues outside of slacomplying

Uses Lockfiles to pin code dependencies

ControlStatus
Use lockfiles in reposcomplying

Does not have risky licenses

ControlStatus
No risky licenses in dependenciescomplying

Connected code repositories

ControlStatus
Connect code repositoriescomplying

Threat detection is enabled

ControlStatus
Alerting policies have a notification channel configuredcomplying

Configured SLAs to resolve issues

ControlStatus
Configure SLAscomplying

Connected cloud environment

ControlStatus
Connect a cloud environmentcomplying

Connected code repositories

ControlStatus
Connect code repositoriescomplying

Connected public facing domain

ControlStatus
Connect public facing domaincomplying

Enabled security logging for cloud instances

ControlStatus
Alerting policies have a notification channel configuredcomplying
Amazon EKS Clusters should have control plane logging enabledcomplying
Audit Configuration logging is enabledcomplying
Logging and alerts are enabled for Project Ownership assignmentscomplying
Storage Permissions logging is enabledcomplying
VPC Firewall has Rule logging enabledcomplying

Has no critical open source dependency issues

ControlStatus
There are critical open source dependency issuescomplying

Runtimes are up to date

ControlStatus
AWS MQBroker version is outdatedcomplying
GKE clusters use stable release channels with automatic upgradescomplying
GKE node pools have node auto-upgrade enabledcomplying
No AKS cluster upgrade channel is chosencomplying

Prevents the exposure of sensitive data

ControlStatus
Currently there are no exposed secretscomplying

Tracks progress via an issue tracker

ControlStatus
Integration with issue tracker enabledcomplying

Has backups for stateful cloud resources

ControlStatus
Databases have automated backups enabledcomplying
DynamoDB backups are offcomplying