Compliance · 121 checks
Compliance.
Configuration drift from best practice: public access, missing MFA, unencrypted storage, deprecated runtimes. ZopNight runs 121 checks for compliance findings across AWS, Azure and Google Cloud.
Free to start. No card. The playground just needs your work email.
121checks
3providers
Manualfixes, spelled out
Compliancewhere it shows up
AWSAzureGoogle CloudKubernetes
Every compliance check.
Most severe first.
ACM Certificate Expiring SoonAKS Cluster RBAC Not EnabledAzure NSG Open to InternetGCP Cloud SQL Instance Has Public IP EnabledGCP Firewall Rule Allows All PortsGCP Firewall Rule Allows Internet Access to Sensitive PortGCS Bucket Does Not Enforce Public Access PreventionGKE Control Plane Master Authorized Networks DisabledGuardDuty Not EnabledIAM Role with Wildcard PrincipalLambda Using Deprecated RuntimeRDS Instance Publicly AccessibleRoot Account MFA Not EnabledS3 Bucket with Public Access EnabledSecurity Group with Unrestricted Inbound AccessAKS Cluster API Server Not PrivateAKS Cluster Network Policy Not EnabledAzure App Service SSL Not EnforcedAzure Function App Deprecated Runtime VersionAzure SQL Database TDE Not EnabledAzure SQL Database Threat Detection Not EnabledAzure Storage Account HTTPS Not EnforcedAzure Storage Account Public Access EnabledAzure VM Antimalware Not EnabledAzure VM Backup Not EnabledAzure VM Disk Encryption Not EnabledCloud SQL Production Instance Without HACloudTrail Not EnabledCluster Network Policy Not EnforcedEBS Volume Not EncryptedEC2 IMDSv2 Not RequiredGCP Audit Logging Not EnabledGCP Cloud SQL Automated Backup DisabledGCP Cloud SQL Instance Does Not Require SSLGCP Firewall Rule on Default VPC NetworkGCP IAM Primitive Role in UseGCP Service Account Has Admin RoleGCP VM Serial Port Access EnabledGKE Cluster Logging DisabledGKE Cluster Monitoring DisabledGKE Cluster Not PrivateIAM Role with AdministratorAccess PolicyIAM User Without MFA EnabledInspector Not EnabledRDS Instance Not Using Multi-AZResource Not Encrypted at RestS3 Bucket Not Requiring HTTPSSageMaker Endpoint Volume Not Encrypted with CMKSageMaker HyperPod Cluster Volume Not Encrypted with CMKSageMaker Notebook Direct Internet Access EnabledSageMaker Notebook Volume Not Encrypted with CMKScaling Target Too HighAKS Cluster Diagnostic Logging Not EnabledAKS Cluster Monitoring Not EnabledAKS Node Pool Autoscaler Not EnabledASG Has No Scaling PoliciesAWS Config Recorder Not EnabledAzure App Service Authentication Not EnabledAzure Cosmos DB Backup Policy Not ConfiguredAzure Managed Disk Without BackupAzure NSG Flow Logs Past End-of-LifeAzure SQL Database Auditing Not EnabledAzure VM JIT Access Not EnabledAzure VM Missing Deletion ProtectionAzure VM Update Management Not EnabledAzure VM Using Unmanaged DisksAzure VM Without Availability SetBedrock Custom Model Without CMEKCloud SQL No Maintenance Window ConfiguredDynamoDB Auto Scaling DisabledEC2 EBS Optimization Not EnabledEC2 Instance Has a Public IP: Review If NeededEC2 Instance Not Managed by SSMECS Service Auto Scaling Not EnabledEKS Cluster Autoscaling Not ConfiguredEKS Control Plane Logging DisabledGCP Dataproc Cluster Autoscaling DisabledGCP Firewall Rule Uses Port RangesGCP IAM Policy Grants Access to Gmail AccountGCP IAM Project-Level Role BindingGCP Persistent Disk Without SnapshotGCP Service Account Has User-Managed KeysGCP Service Account Key Not Rotated Within 90 DaysGCP VM Deletion Protection DisabledGCP VM Missing Snapshot ScheduleGCP VM OS Login Not EnabledGCP VM Shielded VM Not EnabledGCS Bucket Missing Retention PolicyGCS Bucket Uniform Access Not EnabledGKE Cluster Alias IPs Not EnabledGKE Node Auto-Upgrade Not ConfiguredGKE Node Pool Auto-Repair DisabledGKE Node Pool Not Using COS ImageIAM Password Policy Non-CompliantIAM User Access Key Older Than 90 DaysSageMaker Endpoint Data Capture DisabledSageMaker HyperPod Cluster Not in a VPCSageMaker Notebook Not in a VPCSageMaker Notebook Root Access EnabledScaling Cooldown Too ShortVM Monitoring Not EnabledVMSS Autoscale Setting Not ConfiguredAWS Config Rule with No EvaluationsAzure VM Diagnostics Not EnabledCloud SQL Slow Query Log DisabledEC2 Detailed Monitoring Not EnabledEC2 HPC Instance Without Placement GroupECS Cluster Missing Container InsightsGCP GCS Bucket Access Logging DisabledGCP GCS Bucket Versioning DisabledGCP Vertex AI Endpoint Without CMEKGCP Vertex AI Feature Online Store Without CMEKGCP Vertex AI Feature Store Without CMEKGCP Vertex AI Metadata Store Without CMEKGCP Vertex AI Model Without CMEKGCP Vertex AI TensorBoard Without CMEKGCP Vertex AI Vector Search Index Endpoint Without CMEKGCP Vertex AI Vector Search Index Without CMEKGCS Bucket CORS Not ConfiguredS3 Bucket Access Logging Not EnabledSageMaker Notebook Has No Lifecycle Configuration
Find the compliance findings in your account.
Connect a read-only role and every one of these runs on the first pass.
Prefer to talk it through first? Book 20 minutes with the team.
- $30M+annualised cloud spend under management
- 550K+resources tracked since launch
- 20-60%off the bill in the first month
- SOC 2Type II report, plus ISO 27001
Figures published on zop.dev.