Security
Prioritised findings with evidence and remediation context.
Security posture
Fix the exposure that matters first
Review evidence-backed AWS, Azure and Google Cloud control outcomes. CloudAudit records unavailable evidence as unknown and never treats it as a pass.
Evidence source
Live outcomes come only from the latest persisted authenticated scan for each connection.
Evidence horizon
Representative posture across 15 sample accounts
86
Good posture
1
Critical
3
High
34
Resolved
Control outcomes
Open a row for evidence, framework mappings and remediation guidance.
| Finding | Control | Severity | Age |
|---|---|---|---|
Public database endpoint prod-eu / payments-db · AWS | CIS 2.3.1 | Critical | 7m |
Owner role granted directly core-platform / svc-deploy · GCP | CIS 1.5 | High | 24m |
Storage encryption disabled finance-prod / exports · AZ | ISO A.8.24 | High | 41m |
Access key older than 90 days shared-services / deploy-bot · AWS | SOC CC6.1 | Medium | 2h |
Flow logs not enabled research / vpc-ml-lab · GCP | CIS 3.9 | Medium | 5h |
MFA not enforced for privileged role identity / break-glass-admin · AWS | CIS 1.10 | High | 8h |
Database audit logging disabled finance-prod / ledger-sql · AZ | SOC CC7.2 | Medium | 11h |
Unused service account key analytics / batch-loader · GCP | ISO A.5.18 | Low | 1d |