GCP

Google Cloud security scanning

Scan 45 Google Cloud services for over-broad IAM, weak org policy, open buckets and unprotected data stores.

How you connect

Connect with a service account key — project ID, client email and private key. Viewer plus Security Reviewer covers most checks; organization policy, Security Command Center and Cloud Asset Inventory also need their own read-only roles.

What A1 Cloud Guard looks for

  • Storage buckets granting allUsers or allAuthenticatedUsers
  • Firewall rules opening ports to the whole internet
  • Service accounts holding primitive Owner or Editor roles
  • BigQuery datasets shared beyond the project
  • Cloud SQL instances with public IPs

45 services covered

Choose any combination per scan — you are never forced to scan the whole estate.

  • Compute Engine
  • Cloud Storage
  • BigQuery
  • IAM & Admin
  • GKE Clusters
  • Cloud SQL
  • VPC Firewall Rules
  • Pub/Sub
  • Cloud Run
  • Cloud Functions
  • Cloud Spanner
  • Firestore
  • Cloud Logging
  • Cloud Monitoring
  • Cloud KMS
  • Secret Manager
  • Artifact Registry
  • Cloud DNS
  • Cloud Load Balancing
  • Resource Manager & Org Policy
  • Security Command Center
  • Cloud Asset Inventory
  • VPC Service Controls
  • Binary Authorization
  • Identity-Aware Proxy
  • Essential Contacts
  • Cloud Armor
  • Bigtable
  • Memorystore
  • AlloyDB
  • Filestore
  • Dataproc
  • Dataflow
  • Cloud Composer
  • App Engine
  • Cloud Build
  • Certificate Manager
  • Vertex AI
  • Eventarc
  • Workflows
  • Cloud Scheduler
  • Cloud Tasks
  • API Gateway
  • Service Directory
  • Datastream

Scan your GCP estate

Connect a read-only credential and see the full report on the free plan.