Skip to content

Assessment domain

Data security & storage

Data security is knowing where sensitive data actually sits across accounts, projects, and tenants — and proving it is encrypted, access-controlled, and not quietly exposed. In sprawling multi-cloud estates, data multiplies faster than anyone tracks it: copied into a backup, exported to a bucket, cloned into a snapshot, or replicated to a region nobody signed off on. We map where the data is and measure the controls around it, because a single misconfigured store is the shortest path from a routine oversight to a reportable breach.

Why it matters

Where the risk lives

Public storage and unencrypted data are among the most common and most damaging cloud findings — a single readable bucket or over-shared snapshot can be a breach, a regulatory notification, and a headline all at once. Unlike a compromised host, exposed data cannot be re-secured after the fact: once it has been copied, the disclosure has already happened. Getting data controls right is what protects the assets your customers, regulators, and insurers care about most, and it is where findings map straight to HIPAA, PCI-DSS, GLBA, SOC 2, and ISO 27001.

Clean modern server aisle and organized storage environment representing protected enterprise data and storage posture
Data & storage

What we assess

The checks inside data security

Each area below is a focused review with its own findings, per-cloud detail, and remediation.

Public buckets & blob exposure

Object storage is the most common place cloud data leaks, because "public" can mean an anonymous internet URL, an over-broad account principal, or a policy that quietly grants read to everyone. Buckets drift open through one-off sharing, legacy defaults, or a permission copied from a template nobody reviewed. We check every storage container against who can actually reach it, not just how it was labeled.

What we look for

Encryption at rest & in transit

Encryption is table stakes, but the details decide whether it actually protects you: which keys, who controls them, and whether transport is enforced or merely available. Default provider-managed encryption covers the baseline, yet regulated data often calls for customer-managed keys with tight key policies and rotation. We verify that stores are encrypted, that key access follows least privilege, and that plaintext transport is refused rather than tolerated.

What we look for

Snapshots, backups & retention

Snapshots and backups are full copies of production data — and they routinely inherit weaker controls than the source they came from. A disk snapshot shared to another account, an unencrypted backup, or an RDS snapshot marked public can expose everything the live system holds while drawing none of the attention. We follow the copies, checking that they are encrypted, scoped, and retained on a defined schedule rather than accumulating forever.

What we look for

Data classification & residency

You cannot protect data at the right level if you do not know which stores hold regulated or sensitive information, and where those stores physically live. Residency requirements from contracts, regional privacy law, or regulators depend on data staying in agreed geographies, yet replication and multi-region services move it silently. We look for evidence that sensitive data is identified and that its location matches the commitments your organization has made.

What we look for

Database & datastore exposure

Managed databases and datastores are high-value targets, and they are dangerous when reachable from the internet or from over-broad internal networks. A public database endpoint, a cache with no authentication, or a warehouse open to every workload turns one credential or one misconfigured rule into direct access to structured data at scale. We assess network reachability, authentication, and encryption together, since a gap in any one undermines the others.

What we look for

Across your clouds

AWS, Azure & Google Cloud

AWS

S3 Block Public Access and bucket policies/ACLs; default and customer-managed KMS encryption on S3, EBS, and RDS; EBS and RDS snapshot sharing and encryption; RDS/Redshift/ElastiCache public accessibility and security-group scope; Macie for sensitive-data discovery.

Azure

Storage account "allow blob public access" and network rules; encryption with platform- or customer-managed keys via Key Vault; managed-disk and SQL Transparent Data Encryption; SQL Database/PostgreSQL public network access and firewall rules; Microsoft Purview for classification.

Google Cloud

Cloud Storage IAM and "public access prevention"; default encryption and customer-managed encryption keys (CMEK) via Cloud KMS; persistent-disk snapshot scope; Cloud SQL/Memorystore public IP and authorized networks; Sensitive Data Protection (DLP) for discovery.

Compliance evidence

Frameworks this domain produces evidence for

Example finding

A database snapshot of production exports shared to any authenticated principal

Risk: A full copy of production data becomes readable far beyond its intended audience — and unlike a live system, a copied snapshot cannot be un-disclosed once accessed.

Fix: Remove the broad share, restrict the snapshot to specific accounts that need it, confirm it is encrypted with a controlled key, and set a retention policy so old copies expire.

Questions

Do you read our data?

No. The assessment is read-only and looks at configuration and access around your data stores — encryption settings, public-access controls, network reachability, and sharing — not the contents of the data itself.

Isn't encryption on by default enough?

Default encryption is the baseline, but it does not answer who controls the keys, whether copies and backups are also encrypted, whether transport is enforced, or whether the store is reachable from the internet. We assess the whole picture, because regulated data usually needs more than the default.

How does this map to compliance?

Data findings map directly to HIPAA safeguards for PHI, PCI-DSS storage and transmission requirements, the GLBA Safeguards Rule, SOC 2 confidentiality criteria, and ISO 27001 controls — so the same work produces evidence your auditors can use.

See where you stand on data security

A health check finds and prioritizes real exposure. It is not a certification or a promise you will never be breached — closing the findings is what changes your risk.

Related domains

The rest of the health check

One read-only assessment covers all six domains — here's where else exposure tends to hide.