Limitations
Coverage limits, domain by domain
What each domain can and cannot see, including the case where resilience coverage of a real estate is close to zero.
Security
Covered. The scanner's control catalogue at critical, high and medium severity, across every enabled region.
Not covered.
- Low and informational severities, which are never collected
- Three families of check disabled by the read-only boundary: log event content, function package scanning for embedded secrets, and object content reads
- Anything the scanner does not have a check for
- Anything not expressed as cloud configuration
Resilience
Covered. Databases, auto scaling groups, load balancers and object storage.
Not covered. Point-in-time recovery on managed NoSQL, backup plans, block storage snapshots, network file systems, distributed relational databases, container and serverless compute, cross-region replication, and standalone compute instances.
Cost
Covered. 30-day spend, and three classes of demonstrably idle resource: unattached storage volumes, unassociated static IP addresses, and snapshots stale beyond a year.
Not covered. Right-sizing, reserved capacity and savings plan modelling, architectural efficiency, data transfer costs, licensing, and anything requiring knowledge of what a workload is for.
Delivery
Collected when a repository is supplied. Not scored. See Delivery, and why it is out of scope.
Across all domains
- One account, one point in time
- Configuration only. No runtime behaviour, no traffic, no logs
- No knowledge of what any workload does, who uses it, or what it is worth
