Cloud Security — Business+ Feature

See Which Cloud Config Breaks DPDPA Rule 6

AWS security scanner with CIS v8 → ISO 27001 → DPDPA Rules 2025 triple mapping. Every misconfiguration mapped to the exact Rule 6 clause it violates — with score impact per fix.

Scanners included
S3 Bucket Security
Public access blocking, default encryption, ACL status
CloudTrail Logging
Multi-region logging, log file validation, S3 delivery
RDS Encryption
Encryption at rest on all database instances
IAM Policy Checks
Password policy, root MFA, access key rotation (<90d)
CloudWatch Alarms
Billing alarm and root account activity monitoring

One finding. Three compliance frameworks. Zero manual cross-referencing.

CIS v8

CIS 3.1 — Ensure S3 bucket ACLs are not used

CIS Controls v8 are the gold standard for cloud security configuration baselines.

ISO 27001:2022

A.8.5 — Secure authentication

ISO 27001 is the international standard your enterprise clients and auditors expect.

DPDPA Rules 2025

Rule 6(1)(a) — Encryption of personal data

The exact legal obligation that each finding violates under India's data protection law.

Connect once, scan automatically

1
Connect your AWS account
Create a read-only IAM role with SecurityAudit policy. Provide the Role ARN and External ID in DPDPA Shield. No access keys stored — we use STS AssumeRole.
2
5 scanners run in parallel
S3 public-access checks, CloudTrail logging gaps, RDS encryption status, IAM password policy, and CloudWatch alarm coverage — all executing simultaneously.
3
Triple mapping applied
Each finding is mapped to its CIS v8 control number, ISO 27001:2022 clause, and the specific DPDPA Rules 2025 section it violates (e.g., Rule 6(1)(a): Encryption of personal data).
4
Score impact calculated
Every finding shows exactly how many compliance score points it costs you — and how many you gain by fixing it. Prioritise fixes by maximum score impact.
5
Daily auto-scan
GitHub Actions triggers a daily scan across all connected accounts. Score recalculates after each scan. Drift alerts fire immediately on new CRITICAL findings.

Cloud security mapped to DPDPA obligations

Secure

AWS IAM Role Integration

Read-only STS AssumeRole — no access keys ever stored. IAM SecurityAudit managed policy. Works with any AWS account in any region.

5 Parallel Scanners

S3 (public access + encryption), CloudTrail (multi-region logging), RDS (encryption at rest), IAM (password policy, MFA, key rotation), CloudWatch (alarm coverage). All run in parallel, typically complete in under 60 seconds.

Audit-Ready

CIS + ISO + DPDPA Badges

Every finding shows three badges: CIS v8 control number, ISO 27001:2022 clause, and the DPDPA Rules 2025 section violated. Evidence for auditors, not just noise.

Score Impact Per Finding

Fix S3 public access → +8 pts. Enable CloudTrail → +12 pts. Every finding shows the exact score delta so you always know which fix delivers the highest compliance return.

Severity Classification

Findings rated INFO / LOW / MEDIUM / HIGH / CRITICAL. CRITICAL findings trigger immediate in-app drift alerts. Filter by severity to focus on what matters most.

Daily Automated Scans

GitHub Actions triggers scans daily at 1am IST across all connected accounts. Compliance score recalculates automatically — no manual trigger needed.

5
AWS scanners
3-layer
CIS + ISO + DPDPA
<60s
Scan time
Daily
Auto-scan cadence
Available from Business plan onwards

Cloud Security Mapping is available on Business and Enterprise plans. Business: 1 AWS account. Enterprise: unlimited accounts.

Cloud security for DPDPA — answered

What permissions does the AWS scanner need?+

The scanner requires a read-only IAM role with AWS's SecurityAudit managed policy (arn:aws:iam::aws:policy/SecurityAudit). This gives read access to security configuration metadata — it cannot read S3 object contents, database data, or any personal data. We use STS AssumeRole with an External ID for security — no access keys are stored in DPDPA Shield. You create the role in your AWS console and provide only the Role ARN.

Which DPDPA obligations does cloud security map to?+

The primary obligation is DPDPA Rule 6(1): Security Safeguards. Rule 6(1)(a) requires encryption of personal data in transit and at rest — directly mapped to RDS encryption and S3 encryption findings. Rule 6(1)(b) requires access control — mapped to IAM policy findings. Rule 6(1)(c) covers monitoring and logging — mapped to CloudTrail and CloudWatch findings. Each finding in the dashboard shows the exact rule clause it violates.

Which AWS services does the scanner cover?+

Phase 1 (current): S3 (public access blocking, default encryption), CloudTrail (multi-region logging enabled, log file validation), RDS (encryption at rest on all instances), IAM (password policy strength, MFA on root, access key rotation), CloudWatch (billing alarm, root account activity alarm). GCP and Azure support is on the roadmap for a future phase.

How does the score impact work?+

Each finding has a scoreImpact value (e.g., +12) that represents the compliance score points you gain by resolving it. The impact is calculated from the control weight, severity, and the number of active findings in that category. The total score improvement shown when you filter by severity tells you the maximum compliance score improvement available from fixing those issues.

Can I connect more than one AWS account?+

Business plan: 1 connected AWS account. Enterprise plan: unlimited accounts. Each account has its own connection, scanning schedule, and findings list. The compliance score aggregates findings across all connected accounts.

See your cloud risk against DPDPA Rule 6.

Business plan includes 1 AWS account, daily scans, and full CIS → ISO → DPDPA mapping. No access keys stored.