Skip to main content
Compliance · 121 checks

Compliance.

Configuration drift from best practice: public access, missing MFA, unencrypted storage, deprecated runtimes. ZopNight runs 121 checks for compliance findings across AWS, Azure and Google Cloud.

Free to start. No card. The playground just needs your work email.

121checks
3providers
Manualfixes, spelled out
Compliancewhere it shows up

AWSAzureGoogle CloudKubernetes

Every compliance check.

Most severe first.

ACM Certificate Expiring SoonAWSCriticalAKS Cluster RBAC Not EnabledAzureCriticalAzure NSG Open to InternetAzureCriticalGCP Cloud SQL Instance Has Public IP EnabledGoogle CloudCriticalGCP Firewall Rule Allows All PortsGoogle CloudCriticalGCP Firewall Rule Allows Internet Access to Sensitive PortGoogle CloudCriticalGCS Bucket Does Not Enforce Public Access PreventionGoogle CloudCriticalGKE Control Plane Master Authorized Networks DisabledGoogle CloudCriticalGuardDuty Not EnabledAWSCriticalIAM Role with Wildcard PrincipalAWSCriticalLambda Using Deprecated RuntimeAWSCriticalRDS Instance Publicly AccessibleAWSCriticalRoot Account MFA Not EnabledAWSCriticalS3 Bucket with Public Access EnabledAWSCriticalSecurity Group with Unrestricted Inbound AccessAWSCriticalAKS Cluster API Server Not PrivateAzureHighAKS Cluster Network Policy Not EnabledAzureHighAzure App Service SSL Not EnforcedAzureHighAzure Function App Deprecated Runtime VersionAzureHighAzure SQL Database TDE Not EnabledAzureHighAzure SQL Database Threat Detection Not EnabledAzureHighAzure Storage Account HTTPS Not EnforcedAzureHighAzure Storage Account Public Access EnabledAzureHighAzure VM Antimalware Not EnabledAzureHighAzure VM Backup Not EnabledAzureHighAzure VM Disk Encryption Not EnabledAzureHighCloud SQL Production Instance Without HAGoogle CloudHighCloudTrail Not EnabledAWSHighCluster Network Policy Not EnforcedAWS, Google CloudHighEBS Volume Not EncryptedAWSHighEC2 IMDSv2 Not RequiredAWSHighGCP Audit Logging Not EnabledGoogle CloudHighGCP Cloud SQL Automated Backup DisabledGoogle CloudHighGCP Cloud SQL Instance Does Not Require SSLGoogle CloudHighGCP Firewall Rule on Default VPC NetworkGoogle CloudHighGCP IAM Primitive Role in UseGoogle CloudHighGCP Service Account Has Admin RoleGoogle CloudHighGCP VM Serial Port Access EnabledGoogle CloudHighGKE Cluster Logging DisabledGoogle CloudHighGKE Cluster Monitoring DisabledGoogle CloudHighGKE Cluster Not PrivateGoogle CloudHighIAM Role with AdministratorAccess PolicyAWSHighIAM User Without MFA EnabledAWSHighInspector Not EnabledAWSHighRDS Instance Not Using Multi-AZAWSHighResource Not Encrypted at RestAWSHighS3 Bucket Not Requiring HTTPSAWSHighSageMaker Endpoint Volume Not Encrypted with CMKAWSHighSageMaker HyperPod Cluster Volume Not Encrypted with CMKAWSHighSageMaker Notebook Direct Internet Access EnabledAWSHighSageMaker Notebook Volume Not Encrypted with CMKAWSHighScaling Target Too HighAzureHighAKS Cluster Diagnostic Logging Not EnabledAzureMediumAKS Cluster Monitoring Not EnabledAzureMediumAKS Node Pool Autoscaler Not EnabledAzureMediumASG Has No Scaling PoliciesAWSMediumAWS Config Recorder Not EnabledAWSMediumAzure App Service Authentication Not EnabledAzureMediumAzure Cosmos DB Backup Policy Not ConfiguredAzureMediumAzure Managed Disk Without BackupAzureMediumAzure NSG Flow Logs Past End-of-LifeAzureMediumAzure SQL Database Auditing Not EnabledAzureMediumAzure VM JIT Access Not EnabledAzureMediumAzure VM Missing Deletion ProtectionAzureMediumAzure VM Update Management Not EnabledAzureMediumAzure VM Using Unmanaged DisksAzureMediumAzure VM Without Availability SetAzureMediumBedrock Custom Model Without CMEKAWSMediumCloud SQL No Maintenance Window ConfiguredGoogle CloudMediumDynamoDB Auto Scaling DisabledAWSMediumEC2 EBS Optimization Not EnabledAWSMediumEC2 Instance Has a Public IP: Review If NeededAWSMediumEC2 Instance Not Managed by SSMAWSMediumECS Service Auto Scaling Not EnabledAWSMediumEKS Cluster Autoscaling Not ConfiguredAWSMediumEKS Control Plane Logging DisabledAWSMediumGCP Dataproc Cluster Autoscaling DisabledGoogle CloudMediumGCP Firewall Rule Uses Port RangesGoogle CloudMediumGCP IAM Policy Grants Access to Gmail AccountGoogle CloudMediumGCP IAM Project-Level Role BindingGoogle CloudMediumGCP Persistent Disk Without SnapshotGoogle CloudMediumGCP Service Account Has User-Managed KeysGoogle CloudMediumGCP Service Account Key Not Rotated Within 90 DaysGoogle CloudMediumGCP VM Deletion Protection DisabledGoogle CloudMediumGCP VM Missing Snapshot ScheduleGoogle CloudMediumGCP VM OS Login Not EnabledGoogle CloudMediumGCP VM Shielded VM Not EnabledGoogle CloudMediumGCS Bucket Missing Retention PolicyGoogle CloudMediumGCS Bucket Uniform Access Not EnabledGoogle CloudMediumGKE Cluster Alias IPs Not EnabledGoogle CloudMediumGKE Node Auto-Upgrade Not ConfiguredGoogle CloudMediumGKE Node Pool Auto-Repair DisabledGoogle CloudMediumGKE Node Pool Not Using COS ImageGoogle CloudMediumIAM Password Policy Non-CompliantAWSMediumIAM User Access Key Older Than 90 DaysAWSMediumSageMaker Endpoint Data Capture DisabledAWSMediumSageMaker HyperPod Cluster Not in a VPCAWSMediumSageMaker Notebook Not in a VPCAWSMediumSageMaker Notebook Root Access EnabledAWSMediumScaling Cooldown Too ShortAzureMediumVM Monitoring Not EnabledAzure, Google CloudMediumVMSS Autoscale Setting Not ConfiguredAzureMediumAWS Config Rule with No EvaluationsAWSLowAzure VM Diagnostics Not EnabledAzureLowCloud SQL Slow Query Log DisabledGoogle CloudLowEC2 Detailed Monitoring Not EnabledAWSLowEC2 HPC Instance Without Placement GroupAWSLowECS Cluster Missing Container InsightsAWSLowGCP GCS Bucket Access Logging DisabledGoogle CloudLowGCP GCS Bucket Versioning DisabledGoogle CloudLowGCP Vertex AI Endpoint Without CMEKGoogle CloudLowGCP Vertex AI Feature Online Store Without CMEKGoogle CloudLowGCP Vertex AI Feature Store Without CMEKGoogle CloudLowGCP Vertex AI Metadata Store Without CMEKGoogle CloudLowGCP Vertex AI Model Without CMEKGoogle CloudLowGCP Vertex AI TensorBoard Without CMEKGoogle CloudLowGCP Vertex AI Vector Search Index Endpoint Without CMEKGoogle CloudLowGCP Vertex AI Vector Search Index Without CMEKGoogle CloudLowGCS Bucket CORS Not ConfiguredGoogle CloudLowS3 Bucket Access Logging Not EnabledAWSLowSageMaker Notebook Has No Lifecycle ConfigurationAWSLow

Find the compliance findings in your account.

Connect a read-only role and every one of these runs on the first pass.

Prefer to talk it through first? Book 20 minutes with the team.

  • $30M+annualised cloud spend under management
  • 550K+resources tracked since launch
  • 20-60%off the bill in the first month
  • SOC 2Type II report, plus ISO 27001

Figures published on zop.dev.

Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·