AWS
Amazon AWS security scanning
Scan 78 AWS services for public exposure, weak IAM, unencrypted storage and missing audit trails.
How you connect
Connect with an IAM access key or, preferably, a cross-account role with an external ID. A1 Cloud Guard needs read-only permissions.
What A1 Cloud Guard looks for
- S3 buckets readable by anyone on the internet
- Security groups allowing 0.0.0.0/0 on SSH or RDS ports
- IAM users with long-lived access keys and no MFA
- RDS instances and EBS volumes without encryption at rest
- CloudTrail disabled, or not writing to a protected bucket
78 services covered
Choose any combination per scan — you are never forced to scan the whole estate.
Scan your AWS estate
Connect a read-only credential and see the full report on the free plan.