Skip to content

Assessment Coverage

RedCloud runs thousands of automated security checks across multiple clouds and domains, plus deeper IAM analytics. This page describes the breadth of coverage and how to see exactly what ran for a given scan.

RedCloud assesses six surfaces:

SurfaceCoverage
Google CloudHundreds of checks across IAM, networking, storage, GKE, compute, databases, logging, and more
AWSThe largest check set, spanning identity, network, storage, and containers
AzureBroad coverage across identity, network, and Kubernetes
Microsoft 365Tenant security checks
Google WorkspaceWorkspace security checks
Web applicationsWeb security and Web PT checks

GCP checks are organized into dozens of categories, with the largest being:

DomainFocus
IAMRoles, bindings, service accounts, privilege escalation
ComputeVM configuration and hardening
Web SecurityWeb-facing service exposure
NetworkingFirewalls, VPC, public exposure
GKEKubernetes cluster and node hardening
StorageBucket exposure and data protection
DatabaseManaged database security
WorkspaceGoogle Workspace controls

Specialized check families also cover DSPM (data security), CIEM (entitlements), toxic combinations, secrets scanning, host/OS hardening, container vulnerabilities, Model Armor, and AI prompt-injection.

Beyond pass/fail checks, the Assessment Coverage and IAM Permissions screens show permission distribution and analytics — how entitlements are spread across identities and where over-privilege concentrates. Domain-Wide Delegation (DWD) analysis highlights service accounts with broad, sensitive scopes.

Findings map to recognized frameworks for reporting — including CIS, PCI-DSS, SOC 2, HIPAA, ISO 27001, NIST 800-53 / CSF, GDPR, and many more. See Audit & Compliance.

  • The set of checks that run depends on the chosen profile (e.g. mvp15 vs full) and the connected cloud.
  • For the exact, current inventory, rely on the in-product Capabilities view rather than a static number.