Skip to content

How Black Cat SSPM maps to GDPR (SaaS Security)

General Data Protection Regulation — SaaS security posture controls for data protection, access control, encryption, and accountability

GDPR-5 — Data Processing Principles

Principles relating to processing of personal data (Article 5)

GDPR-25 — Data Protection by Design & Default

Appropriate technical and organizational measures for implementing data protection principles (Article 25)

GDPR-28 — Processor Obligations

Requirements for controllers using processors (third-party SaaS) to ensure sufficient guarantees (Article 28)

GDPR-32 — Security of Processing

Technical and organizational measures to ensure a level of security appropriate to the risk (Article 32)

GDPR-33 — Breach Notification Readiness

Capability to detect and notify personal data breaches without undue delay (Article 33)

GDPR-44 — International Data Transfers

Controls governing transfer of personal data to third countries or international organizations (Articles 44-49)

GDPR-5.1f — Integrity & Confidentiality

Personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorized processing, accidental loss, destruction or damage

GDPR-5.1f.i — Transport Encryption

Encryption of personal data in transit using TLS, HTTPS, HSTS, and secure transport protocols

  • SSL Encryption Disabled (cloudflare)
  • SSL Mode Flexible (cloudflare)
  • TLS Mode Not Strict (cloudflare)
  • Always Use HTTPS Disabled (cloudflare)
  • Minimum TLS Version Weak (cloudflare)
  • HSTS Disabled (cloudflare)
  • HSTS Not Enabled (akamai)
  • HSTS Max-Age Too Short (akamai)
  • Origin Not Using TLS (akamai)
  • App Service HTTPS Disabled (azure)
  • App Service Minimum TLS (azure)
  • Storage HTTPS Not Required (azure)
  • Storage Minimum TLS (azure)
  • SQL Minimum TLS (azure)
  • SSL Not Enforced (digitalocean)
  • No SSL Termination (digitalocean)
  • HTTP Allowed (digitalocean)
  • Insecure Backend (digitalocean)
  • SSL Not Verified (vercel)
  • Edge Hostname Using Shared Cert (akamai)
  • Geo Firewall Not Configured (akamai)
  • HTTP/2 Not Enabled (akamai)
  • IP Firewall Not Configured (akamai)
  • Rate Control Threshold Too Permissive (akamai)
  • Rate Controls Disabled (akamai)
  • SOA Serial Stale (akamai)
  • Slow POST Protection Disabled (akamai)
  • TSIG Not Enabled (akamai)
  • WAF Policy Alert-Only Mode (akamai)
  • Device Without Disk Encryption (chrome_enterprise)
  • Safe Browsing Disabled (chrome_enterprise)
  • Allows All Inbound (digitalocean)
  • Allows All Outbound (digitalocean)
  • Default VPC Used (digitalocean)
  • No Firewall (digitalocean)
  • No VPC (digitalocean)
  • SSH Open To All (digitalocean)
  • IP Allowlist Disabled (incidentio)
  • S/MIME CRL Timeout Too Long (m365)
  • S/MIME Cert Chain With Root Not Included (m365)
  • S/MIME Cert Chain Without Root Not Included (m365)
  • Extension Disabled (pagerduty)
  • Webhook External URL (pagerduty)
  • Webhook Inactive (pagerduty)
  • Integration No Network Policy (snowflake)
  • Network Policy No Blocklist (snowflake)
  • Network Policy Wildcard (snowflake)
  • No Network Policy (snowflake)
  • Application Has TLS Verification Disabled (teleport)
  • Database Configured Without TLS (teleport)
  • No Network Restrictions Configured (teleport)
  • Overly Broad Network Allow Rule (teleport)
  • Agent Pool Organization Scoped (terraform_cloud)
  • Notification No HMAC Token (terraform_cloud)
  • Run Task Advisory Enforcement (terraform_cloud)
  • SSH Key Present (terraform_cloud)
  • VCS Connection Organization Scoped (terraform_cloud)

GDPR-5.1f.ii — Data-at-Rest Encryption

Encryption of personal data at rest in storage, databases, and key management systems

  • SQL TDE Disabled (azure)
  • S3 Bucket Encryption Disabled (aws)
  • Storage Infrastructure Encryption Disabled (azure)
  • Data Rekeying Disabled (snowflake)
  • Expired Service Token Not Deleted (cloudflare_access)
  • Service Token Without Expiry (cloudflare_access)
  • Stale Service Token (cloudflare_access)
  • Unused API Key (datadog)
  • Dormant Cloud Token (grafana_cloud)
  • Excessive Tokens Per Policy (grafana_cloud)
  • Non-Expiring Cloud Token (grafana_cloud)
  • Recently Created Token Without Use (grafana_cloud)
  • Token With Wildcard Policy (grafana_cloud)
  • Variable Not Marked Sensitive (terraform_cloud)
  • Variable Plaintext Credentials (terraform_cloud)
  • Variable Set Global Scope (terraform_cloud)

GDPR-5.1f.iii — Communication Integrity

Integrity of communications including email signing (DKIM, S/MIME), webhook security, and prevention of plaintext secret exposure

  • Org Web Commit Signoff Not Required (github)
  • Gmail Unverified Send-As Alias (workspace)
  • S/MIME Not Configured (workspace)
  • S/MIME Encryption Not Enforced (m365)
  • S/MIME Signing Not Enforced (m365)
  • DKIM Not Configured (workspace)
  • Webhook Insecure URL (circleci)
  • Webhook Unverified TLS (circleci)
  • Webhook Using HTTP (shopify)
  • Webhook Insecure URL (github)
  • Integration Insecure URL (gitlab)
  • Data Source TLS Skip Verify (grafana)
  • Plain Text Env Var (digitalocean)
  • Plain Text Secret (vercel)
  • Pipeline Hardcoded Secrets (circleci)
  • Vault Exported (1password)
  • Excessive Env Vars (circleci)
  • Public Status Page (incidentio)
  • Debug Files Access (sentry)
  • Enhanced Privacy Disabled (sentry)
  • Event Attachments Access (sentry)
  • Open Membership (sentry)
  • Shared Issues Enabled (sentry)
  • Password Protection Disabled (shopify)
  • Webhook External Destination (shopify)
  • No Storage Integration Required (snowflake)
  • Unload To Inline URL (snowflake)
  • Unload To Internal Stages (snowflake)
  • Auto Expose System Environment Variables (vercel)
  • Directory Listing Enabled (vercel)
  • Exposed to Preview (vercel)
  • IP Visibility Enabled (vercel)
  • Sensitive Env Var Policy Disabled (vercel)

GDPR-5.2 — Accountability & Governance

The controller shall be responsible for, and be able to demonstrate compliance with, the data processing principles

  • Audit Logging Disabled (workday)
  • Audit Logging Not Enabled (gcp)
  • Data Access Logs Incomplete (gcp)
  • Global Mailbox Auditing Disabled (m365)
  • Mailbox Auditing Disabled (m365)
  • Mailbox Audit Bypass Configured (m365)
  • Non-Shared Mailbox Audit Bypass (m365)
  • User Mailbox Auditing Disabled (m365)
  • Shared Mailbox Sent-As Not Audited (m365)
  • Shared Mailbox Sent-On-Behalf Not Audited (m365)
  • Audit Logging Disabled (datadog)
  • Audit Log Retention Period (datadog)
  • CloudTrail Not Logging (aws)
  • CloudTrail Not Multi-Region (aws)
  • CloudTrail Log Validation Disabled (aws)
  • S3 Bucket Logging Disabled (aws)
  • SQL Auditing Disabled (azure)
  • SQL Audit Retention Short (azure)
  • Diagnostic Retention Short (azure)
  • Key Vault Diagnostic Logging Disabled (azure)
  • NSG Flow Logs Disabled (azure)
  • App Service Logging Disabled (azure)
  • Insecure Log Drain (vercel)
  • Log Drain Disabled (vercel)
  • No Log Drain (vercel)
  • Recent Sensitive Change (google_ads)
  • Alert Source Unowned (incidentio)
  • App No Description (slack)
  • Archive Channel Unrestricted (slack)
  • Default Channels Excessive (slack)
  • Display Name Not Validated (slack)
  • Everyone Notify General (slack)
  • Inactive Channel (slack)
  • Message Edit Unrestricted (slack)
  • Notify Channel Unrestricted (slack)
  • Remove Private Channel Unrestricted (slack)
  • Remove Public Channel Unrestricted (slack)
  • Slackbot Responses Unrestricted (slack)
  • User Groups Unrestricted (slack)
  • Workflow Creation Unrestricted (slack)
  • Channel Without Moderation (teams)
  • Large Team Without Moderation (teams)
  • Meeting Recording Disabled (teams)
  • Message Edit Delete Unrestricted (teams)
  • Team Without Description (teams)
  • Policy Set Empty (terraform_cloud)
  • Policy Set Not Global (terraform_cloud)
  • Policy Set Overridable (terraform_cloud)
  • Sentinel Policy Advisory Only (terraform_cloud)
  • Workspace Auto Apply Enabled (terraform_cloud)
  • Workspace Destroy Plan Allowed (terraform_cloud)
  • Collaborator Group No Description (workato)
  • Prompt/Response Logging Enabled (openrouter)
  • Logging At Full Sampling (openrouter)

GDPR-25.1 — Technical Measures

Implementation of appropriate technical measures such as pseudonymisation and secure defaults to protect data processing

  • GitHub Actions Can Approve Pull Requests (github)
  • GitHub Actions Enabled For All Repositories (github)
  • Group Not SCIM-Managed (openai)
  • SSO Not Enabled (workday)
  • DLP Rules Not Configured (workspace)
  • Gmail Confidential Mode Disabled (workspace)
  • Meet Recording Unrestricted (workspace)
  • Spoofing Protection Disabled (workspace)
  • Join Before Host Allowed (zoom)
  • No Password For Instant Meetings (zoom)
  • No Password For PMI Meetings (zoom)
  • Password Embedded In Join Link (zoom)
  • SSO Not Configured (cloudflare)
  • SSO Not Configured (workspace)
  • SSO Not Configured (atlassian)
  • SSO Disabled (datadog)
  • SSO Disabled (pagerduty)
  • SSO Disabled (grafana)
  • SSO Disabled (sentry)
  • SSO Not Enforced (datadog)
  • SSO Not Enforced (zoom)
  • SSO Not Enforced (vercel)
  • No SSO Configured (docusign)
  • SSO Not Mandatory (docusign)
  • No SSO Configured (snowflake)
  • SSO Login Page Disabled (snowflake)
  • SSO Disabled (1password)
  • No SAML or OIDC Provider (cloudflare_access)
  • Access Policy Default Not Deny (okta)
  • App Not Using Federated Auth (okta)
  • Sensitivity Labels Not Configured (m365)
  • Config Policies Disabled (circleci)
  • Config Policies Soft Fail (circleci)
  • No Compliance Framework (gitlab)
  • WAF Disabled (cloudflare)
  • Account Protection Disabled (akamai)
  • WAF In Alert-Only Mode (akamai)
  • Bot Management Disabled (akamai)
  • Browser Integrity Check Disabled (cloudflare)
  • Firewall Rule Changed (1password)
  • SSO Policy Modified (1password)
  • Signing Key Changed (1password)
  • Default Security Group Has Rules (aws)
  • Default VPC In Use (aws)
  • EC2 IMDSv2 Not Enforced (aws)
  • EC2 Instance Has Public IP (aws)
  • GuardDuty Not Enabled (aws)
  • KMS Key Disabled (aws)
  • RDS Backup Retention Too Short (aws)
  • RDS Publicly Accessible (aws)
  • RDS Storage Not Encrypted (aws)
  • Unrestricted Egress (aws)
  • Unrestricted RDP Access (aws)
  • Unrestricted SSH Access (aws)
  • CP Code Unused (akamai)
  • Edge Hostname IPv4 Only (akamai)
  • Group With No Contracts (akamai)
  • Property Caching Disabled (akamai)
  • SureRoute Not Enabled (akamai)
  • Archived Workspace Not Deleted (anthropic)
  • Stale Workspace (anthropic)
  • App Service FTP Enabled (azure)
  • App Service HTTP/2 Disabled (azure)
  • App Service Remote Debugging Enabled (azure)
  • Key Vault Network ACLs Allow (azure)
  • Key Vault No Private Endpoint (azure)
  • NSG All Ports Open (azure)
  • NSG Permissive Outbound (azure)
  • NSG UDP Open (azure)
  • NSG Unrestricted RDP (azure)
  • NSG Unrestricted SSH (azure)
  • SQL Firewall Allow Azure Services (azure)
  • SQL Firewall Unrestricted (azure)
  • Bidirectional Collaboration Whitelist (box)
  • Broad Inbound Collaboration Whitelist (box)
  • No Collaboration Whitelist Entries (box)
  • Extension With Risky Permissions (chrome_enterprise)
  • Outdated Browser Version (chrome_enterprise)
  • Sideloaded Extension Detected (chrome_enterprise)
  • Forked PR Builds Enabled (circleci)
  • Pipeline Deprecated Image (circleci)
  • Schedule Non-Default Branch (circleci)
  • Stale Runner (circleci)
  • CORS Allows All Origins (cloudflare_access)
  • Auto Upgrade Disabled (digitalocean)
  • Basic Tier (digitalocean)
  • Database No Maintenance Window (digitalocean)
  • Droplet Powered Off (digitalocean)
  • Email Not Verified (digitalocean)
  • IPv6 Disabled (digitalocean)
  • Kubernetes No Registry Integration (digitalocean)
  • No Droplets Attached (digitalocean)
  • No Garbage Collection (digitalocean)
  • Outdated Kubernetes Version (digitalocean)
  • Outdated Version (digitalocean)
  • Surge Upgrade Disabled (digitalocean)
  • Content Filter Not Full (discord)
  • NSFW Channel (discord)
  • No AutoMod Rules (discord)
  • No Keyword Filtering (discord)
  • No Mention Spam Protection (discord)
  • No Spam Protection (discord)
  • Widget Enabled (discord)
  • Bulk Recipients Enabled (docusign)
  • No IP Restrictions (docusign)
  • No Signer Certificate Required (docusign)
  • PowerForms Enabled (docusign)
  • Recipient Domain Validation Disabled (docusign)
  • Sign On Paper Enabled (docusign)
  • Signer Reassignment Enabled (docusign)
  • External Folder Join Unrestricted (dropbox)
  • Folder Link Restriction Not Enforced (dropbox)
  • Public Shared Links Allowed by Default (dropbox)
  • Shared Folders Open to Anyone (dropbox)
  • Cloud SQL Backup Not Enabled (gcp)
  • Cloud SQL Instance Has Public IP (gcp)
  • Cloud SQL SSL Not Required (gcp)
  • Default VPC In Use (gcp)
  • Essential Contacts Coverage Incomplete (gcp)
  • Firewall Rule Egress Open to World (gcp)
  • Firewall Rule Exposes Dangerous Port (gcp)
  • Instance Serial Port Enabled (gcp)
  • Public Firewall Rule (gcp)
  • Shielded VM Disabled (gcp)
  • Actions Allow All External (github)
  • Active Runner Offline (gitlab)
  • Group No IP Restriction (gitlab)
  • Project Discussions Not Required (gitlab)
  • Shared Runner Not Locked (gitlab)
  • Broad Mute Timing (grafana)
  • Community Plugin (grafana)
  • Data Source Basic Auth (grafana)
  • Data Source With Credentials (grafana)
  • Direct Access Data Source (grafana)
  • Outdated Plugin (grafana)
  • Unsigned Plugin (grafana)
  • Admin Stale Master Password (lastpass)
  • Critically Low Shared Folder Score (lastpass)
  • Empty Vault User (lastpass)
  • Low Shared Folder Security Score (lastpass)
  • Master Password Never Changed (lastpass)
  • Stale Master Password (lastpass)
  • ActiveSync Integration Enabled for OWA (m365)
  • Anti-Phishing First Contact Tip Disabled (m365)
  • Anti-Phishing Spoof Detection Weak (m365)
  • Blocked File Type Action Not Quarantine (m365)
  • Common Attachment Types Filter Disabled (m365)
  • Common Attachment Types Missing (m365)
  • Comprehensive Spam Marking Disabled (m365)
  • Connection Filter Not Configured (m365)
  • Customer Lockbox Not Enabled (m365)
  • DKIM Record Missing (m365)
  • DMARC Record Missing (m365)
  • Distribution List Hidden From GAL (m365)
  • External Recipient Mail Tips Disabled (m365)
  • Group Naming Convention Not Configured (m365)
  • High Confidence Spam Not Quarantined (m365)
  • Inbound Spam Bulk Threshold Too High (m365)
  • Mail Tips Not Fully Enabled (m365)
  • Mailbox Move Enabled for Org Relationships (m365)
  • Mailbox SMTP Auth Not Disabled (m365)
  • No File Types Blocked in OWA (m365)
  • No MIME Types Blocked in OWA (m365)
  • OWA Clickjacking Protection Not Set (m365)
  • On-Send Add-ins Enabled in OWA (m365)
  • Outbound Spam Thresholds Not Configured (m365)
  • Remote Domain Auto-Reply Enabled (m365)
  • Remote Domain Delivery Reports Enabled (m365)
  • Remote Domain NDR Enabled (m365)
  • Remote Domain TNEF Enabled (m365)
  • Remote Domain Trusted Inbound Enabled (m365)
  • Remote Domain Trusted Outbound Enabled (m365)
  • SMTP Auth Not Disabled Globally (m365)
  • SPF Hard Fail Not Enabled (m365)
  • SPF Record Missing (m365)
  • Self-Service Subscriptions Enabled (m365)
  • Transport Rule Deletes Messages (m365)
  • Transport Rule Disabled (m365)
  • Transport Rule Includes BCC (m365)
  • Transport Rule Processes External Sender (m365)
  • Unknown File Types Not Blocked (m365)
  • Unverified Domain (m365)
  • Unverified Federated Domain (m365)
  • Zero-Hour Auto Purge Disabled (m365)
  • Cloud Project Suspended (ovhcloud)
  • Developer Mode Enabled (ovhcloud)
  • IAM Policy No Identities (ovhcloud)
  • Instance In Shelved State (ovhcloud)
  • Instance Rescue Mode (ovhcloud)
  • Instance Using Default Image (ovhcloud)
  • OAuth2 Client No Description (ovhcloud)
  • Active Project Without Users (openai)
  • Disproportionate Output Tokens (openai)
  • Excessive API Request Volume (openai)
  • Project Without Rate Limits (openai)
  • Data Scrubber Defaults Disabled (sentry)
  • Data Scrubber Disabled (sentry)
  • Low Data Retention (snowflake)
  • No Account Resource Monitor (snowflake)
  • No SCIM Configured (snowflake)
  • Resource Monitor Notify Only (snowflake)
  • Warehouse No Auto Resume (snowflake)
  • Warehouse No Auto Suspend (snowflake)
  • Warehouse No Resource Monitor (snowflake)
  • Warehouse Oversized (snowflake)
  • No Client Idle Timeout Configured (teleport)
  • Node Running Outdated Teleport Version (teleport)
  • Trusted Cluster Is Disabled (teleport)
  • Organization Default Execution Mode Local (terraform_cloud)
  • Organization Force Delete Allowed (terraform_cloud)
  • Variable Set Priority Override (terraform_cloud)
  • Workspace Drift Detection Disabled (terraform_cloud)
  • Workspace Global Remote State (terraform_cloud)
  • Workspace No VCS Connection (terraform_cloud)
  • Workspace Outdated Terraform Version (terraform_cloud)
  • Deployment Protection Disabled (vercel)
  • Domain Expiring Soon (vercel)
  • Fork Protection Disabled (vercel)
  • No Target Restriction (vercel)
  • Project No Deployment Protection (vercel)
  • Strict Deployment Protection Disabled (vercel)
  • Broken Connection (workato)
  • Stale Connection (workato)
  • Workspace Recipe Limit (workato)
  • Domain Not Verified (workspace)
  • Drive Shared Drive Creation Unrestricted (workspace)
  • Gemini Not Licensed (workspace)
  • Group Spam Moderation Disabled (workspace)
  • IMAP Access Enabled (workspace)
  • POP Access Enabled (workspace)
  • Shared Drive Folder Sharing Unrestricted (workspace)
  • Shared Drive No Admin Restrictions (workspace)
  • Chat File Transfer Enabled (zoom)
  • Cloud Recording No Auto-Delete (zoom)
  • Local Recording Enabled (zoom)
  • No Meeting Password Required (zoom)
  • Unauthenticated Join Allowed (zoom)
  • Waiting Room Disabled (zoom)

GDPR-25.2 — Data Minimisation & Least Privilege

Only personal data necessary for each specific purpose of processing is accessible — limiting the amount, extent, and storage period

  • GitHub Actions Default Workflow Permissions Read-Write (github)
  • Org Repository Creation Unrestricted (github)
  • Repo Branch Deletion Allowed (github)
  • Repo Force Pushes Allowed (github)
  • Repo Insufficient Required Reviews (github)
  • Certificate Expiring Soon (openai)
  • Certificate Without Project Scope (openai)
  • Inactive Certificate (openai)
  • Invite Grants Owner Role (openai)
  • Overpermissive Custom Role (openai)
  • Stale Expired Invite (openai)
  • Stale Pending Invite (openai)
  • Delegated Auth Certificate Expiring Soon (workday)
  • Empty Security Group (workday)
  • No Account Lockout Policy (workday)
  • No IP Restrictions Configured (workday)
  • Security Group With Broad Domain Access (workday)
  • Security Group With Excessive Members (workday)
  • Terminated User With Active Account (workday)
  • Workday Dormant User Account (workday)
  • Gmail App Passwords Active (workspace)
  • Gmail Stale Delegates (workspace)
  • Super Admin Count Excessive (okta)
  • Super Admin Count Excessive (workspace)
  • Super Admin Count Excessive (cloudflare)
  • Excessive Admins (datadog)
  • Excessive Admins (zoom)
  • Excessive Admins (slack)
  • Excessive Admins (pagerduty)
  • Excessive Admins (sentry)
  • Excessive Admins (discord)
  • Excessive Admins (docusign)
  • Excessive Admins (shopify)
  • Excessive Admins (workato)
  • Excessive Org Admins (anthropic)
  • Excessive Workspace Admins (anthropic)
  • Excessive Organization Owners (openai)
  • Excessive Cloud Admins (grafana_cloud)
  • Excessive Project Owners (gcp)
  • Owner Count Exceeded (azure)
  • Excessive Team Owners (teams)
  • Excessive Owners (slack)
  • Excessive Owners (vercel)
  • Excessive Members (vercel)
  • Overly Permissive IAM Binding (gcp)
  • Overly Permissive IAM Policy (aws)
  • Overly Permissive Access Policy (grafana_cloud)
  • Overly Broad Permission Profile (docusign)
  • Staff Unrestricted Permissions (shopify)
  • Overprivileged Member (workato)
  • Excessive Modify All Data (salesforce)
  • Permission Set Modify All Data (salesforce)
  • Dormant Accounts (okta)
  • Dormant Super Admins (okta)
  • Dormant User (1password)
  • Dormant Account (lastpass)
  • Dormant User (sentry)
  • Dormant Member (anthropic)
  • Dormant User (grafana)
  • Dormant User (snowflake)
  • Inactive User (atlassian)
  • Inactive User (zoom)
  • Inactive User With Access (docusign)
  • Inactive Member (workato)
  • Inactive IAM Users (aws)
  • Stale Organization Member (github)
  • Never Logged In Users (workspace)
  • Admin Dormant (lastpass)
  • Admin Never Logged In (lastpass)
  • Suspended User Not Removed (1password)
  • Suspended User With Access (atlassian)
  • Disabled Account Not Removed (lastpass)
  • Disabled User Not Removed (openai)
  • Identity User Disabled Not Removed (ovhcloud)
  • Deactivated Member Not Removed (gitlab)
  • Frozen Active User (salesforce)
  • Service Account Token Created (1password)
  • Sign-in From Untrusted Location (1password)
  • Suspended User Activity (1password)
  • Password Never Used (aws)
  • Password Policy Expiration Too Long (aws)
  • Root Access Key Exists (aws)
  • Unused Access Keys (aws)
  • API Client Credentials Near Expiry (akamai)
  • API Client Inactive (akamai)
  • Custom Role With Admin Permissions (akamai)
  • User Account Locked (akamai)
  • User All Groups Access (akamai)
  • User Inactive (akamai)
  • API Key Created By Non-User (anthropic)
  • Admin Invite Pending Review (anthropic)
  • Expired Invite Not Cleaned (anthropic)
  • Inactive API Key Not Removed (anthropic)
  • Managed User Review (anthropic)
  • Stale API Key (anthropic)
  • Stale Invite (anthropic)
  • Unscoped API Key (anthropic)
  • Unscoped Admin (anthropic)
  • API Token Without Expiry (cloudflare)
  • API Token Stale (cloudflare)
  • API Token Older Than 90 Days (atlassian)
  • Jira Project Permissive Default Roles (atlassian)
  • Session Duration Excessive (atlassian)
  • User Dual Admin Role (atlassian)
  • User With Multiple API Tokens (atlassian)
  • App Service Auth Disabled (azure)
  • App Service Managed Identity Disabled (azure)
  • Classic Administrators (azure)
  • Custom Admin Roles (azure)
  • Key Vault RBAC Not Enabled (azure)
  • SQL AD Admin Not Configured (azure)
  • Excessive Admin Users (box)
  • External Collaboration Not Restricted (box)
  • Inactive User Account (box)
  • No Device Pins Configured (box)
  • Platform Access Only Admin (box)
  • User Exempt from Device Limits (box)
  • User Exempt from Login Verification (box)
  • Download Restrictions Not Set (chrome_enterprise)
  • Incognito Mode Allowed (chrome_enterprise)
  • Stale Browser (90+ Days Inactive) (chrome_enterprise)
  • Unmanaged Browser (30+ Days Inactive) (chrome_enterprise)
  • No Groups Defined (circleci)
  • OIDC Not Configured (circleci)
  • Unrestricted Context (circleci)
  • User Checkout Key (circleci)
  • Application Allows All IdPs (cloudflare_access)
  • Application Without Policies (cloudflare_access)
  • Bypass Decision Policy (cloudflare_access)
  • Group Includes Everyone (cloudflare_access)
  • Group With Empty Include Rules (cloudflare_access)
  • No Purpose Justification (cloudflare_access)
  • Policy Allows Everyone (cloudflare_access)
  • Single Identity Provider (cloudflare_access)
  • Application Key Write Scopes (datadog)
  • Dashboard Permissions Open (datadog)
  • Service Account Custom Role (datadog)
  • Kubernetes SSO Not Enabled (digitalocean)
  • Weak SSH Key (digitalocean)
  • Channel Everyone Overwrite (discord)
  • Everyone Role Has Dangerous Permissions (discord)
  • Excessive Admin Roles (discord)
  • Low Verification Level (discord)
  • Member Verification Gate Disabled (discord)
  • Overly Permissive Channel (discord)
  • Permanent Invite (discord)
  • Role Can Mention Everyone (discord)
  • Role Has Administrator Permission (discord)
  • Role Has Dangerous Permissions (discord)
  • Unlimited Use Invite (discord)
  • Long Mobile Session Timeout (docusign)
  • Long Signing Session Timeout (docusign)
  • Long Web Session Timeout (docusign)
  • No Account Lockout (docusign)
  • No Password Expiration (docusign)
  • Unclaimed Domain (docusign)
  • User Without Group (docusign)
  • EMM Not Required (dropbox)
  • Email Not Verified (dropbox)
  • Excessive Admin Users (dropbox)
  • Excessive Device Sessions (dropbox)
  • Group Creation Unrestricted (dropbox)
  • Inactive Member Account (dropbox)
  • Stale Desktop Session (dropbox)
  • Stale Pending Invite (dropbox)
  • Stale Web Session (dropbox)
  • Bucket Uniform Access Disabled (gcp)
  • Default SA Grant Not Disabled (gcp)
  • Instance Uses Default Service Account (gcp)
  • KMS Separation of Duties Violation (gcp)
  • Org-Level Editor Binding (gcp)
  • Org-Level Owner Binding (gcp)
  • Owner Role Group Assignment (gcp)
  • Privileged Service Account Binding (gcp)
  • SA Impersonation Role Binding (gcp)
  • SA Key Creation Not Disabled (gcp)
  • SA Key Upload Not Disabled (gcp)
  • Service Account Key Expiry Not Enforced (gcp)
  • SA Separation of Duties Violation (gcp)
  • Stale API Key (gcp)
  • Unrestricted API Key (gcp)
  • Fine-Grained PAT Stale (github)
  • Fine-Grained PAT Broad Access (github)
  • Org Default Permission Too Permissive (github)
  • Repo Branch Protection Disabled (github)
  • Group Membership Unlocked (gitlab)
  • Pending Invitation Not Accepted (gitlab)
  • Project Branch Protection Disabled (gitlab)
  • Project Force Push Allowed (gitlab)
  • Project Merge Approvals Disabled (gitlab)
  • Project No Code Owner Approval (gitlab)
  • Email-Only User Access (google_ads)
  • Excessive Admin Users (google_ads)
  • Stale Pending Invitation (google_ads)
  • Stale User Access (google_ads)
  • Admin Without Recent Activity (grafana)
  • Basic Auth Enabled With SSO (grafana)
  • Disabled Service Account With Tokens (grafana)
  • Excessive Admins (grafana)
  • Non-Expiring Service Account Token (grafana)
  • Service Account Admin Role (grafana)
  • Single SSO Provider (grafana)
  • Access Policy Without IP Restriction (grafana_cloud)
  • Cloud Wildcard Access Policy (grafana_cloud)
  • Excessive Admins (incidentio)
  • User No Slack Linked (incidentio)
  • User Without Base Role (incidentio)
  • Workflow Accesses Private Data (incidentio)
  • Excessive Shared Folder Admins (lastpass)
  • Never Logged In Account (lastpass)
  • Shared Folder All Admin (lastpass)
  • Shared Folder Excessive Users (lastpass)
  • Shared Folder No Read-Only Users (lastpass)
  • Shared Folder Single Admin (lastpass)
  • ActiveSync Does Not Block Unmanaged Devices (m365)
  • App Certificate Credentials Expiring Soon (m365)
  • App Expired Certificate Credentials (m365)
  • App Expired Password Credentials (m365)
  • App Long-Lived Certificate Credentials (m365)
  • App Long-Lived Password Credentials (m365)
  • App Password Credentials Expiring Soon (m365)
  • App Using Password Credentials (m365)
  • Auth Methods Migration Incomplete (m365)
  • CA Block High Risk Users Missing (m365)
  • CA Compliant Devices Not Required (m365)
  • CA Device Code Flow Not Blocked (m365)
  • CA Session Duration Not Set (m365)
  • Direct File Access on Public Computers (m365)
  • Excessive Global Administrators (m365)
  • External Users With Admin Role (m365)
  • Global Admin Not Cloud-Only (m365)
  • Global Admin Redundancy Missing (m365)
  • Guest Invitation Not Restricted (m365)
  • Guest User Permissions Not Restricted (m365)
  • Lockout Duration Too Short (m365)
  • M365 Group Creation Not Restricted (m365)
  • MSOL PowerShell Not Blocked (m365)
  • Mobile Device Allows Non-Provisionable (m365)
  • OWA Session Timeout Disabled (m365)
  • Password Expiration Policy Enabled (m365)
  • Password Lockout Threshold Too High (m365)
  • Password Protection Mode Audit Only (m365)
  • Password Protection On-Prem Disabled (m365)
  • SP Certificate Credentials Expiring Soon (m365)
  • SP Expired Certificate Credentials (m365)
  • SP Expired Password Credentials (m365)
  • SP Long-Lived Certificate Credentials (m365)
  • SP Long-Lived Password Credentials (m365)
  • SP Password Credentials Expiring Soon (m365)
  • SP Using Password Credentials (m365)
  • Self-Service Sign Up Enabled (m365)
  • Shared Mailbox Sign-In Enabled (m365)
  • TAP Character Length Too Short (m365)
  • TAP Enabled for All Users (m365)
  • TAP Global Policy Enabled (m365)
  • TAP Maximum Lifetime Too Long (m365)
  • TAP Not One-Time Use (m365)
  • User Consent to Apps Not Restricted (m365)
  • Users Can Create Security Groups (m365)
  • Users Can Create Tenants (m365)
  • WAC Viewing on Public Computers (m365)
  • Bot Without Description (notion)
  • Guest User Sprawl (notion)
  • Member Without Email (notion)
  • API Credential Never Used (ovhcloud)
  • API Credential No Expiry (ovhcloud)
  • API Credential No IP Restriction (ovhcloud)
  • API Credential OVH Support Access (ovhcloud)
  • API Credential Overly Permissive (ovhcloud)
  • Excessive OAuth2 Clients (ovhcloud)
  • IAM Policy Excessive Identities (ovhcloud)
  • IAM Policy Wildcard Actions (ovhcloud)
  • IAM Policy Wildcard Resources (ovhcloud)
  • Identity User No Group (ovhcloud)
  • No IP Restrictions (ovhcloud)
  • Only SMS MFA Enabled (ovhcloud)
  • SSH Key Size Too Small (ovhcloud)
  • Weak SSH Key Algorithm (ovhcloud)
  • App With Individual User Assignments (okta)
  • Session Idle Timeout Too Long (okta)
  • Session Lifetime Too Long (okta)
  • Super Admin API Tokens (okta)
  • Stale API Token (okta)
  • Old API Token (okta)
  • Weak Account Lockout (okta)
  • API Key Non-User Owner (openai)
  • Admin Key Non-User Owner (openai)
  • Admin Key Sprawl (openai)
  • Excessive Project API Keys (openai)
  • Excessive Service Accounts (openai)
  • Orphaned Service Account (openai)
  • Project With Only Service Accounts (openai)
  • Stale API Key (openai)
  • Stale Admin Key (openai)
  • Stale Service Account (openai)
  • Unassigned User (pagerduty)
  • API Access Review (salesforce)
  • Inactive Admin (salesforce)
  • Default Role Not Member (sentry)
  • Old Pending Invite (sentry)
  • External Admin (slack)
  • Guest Multi Channel (slack)
  • Guest Slash Commands (slack)
  • Public Channel Creation Unrestricted (slack)
  • ACCOUNTADMIN Default Role (snowflake)
  • ACCOUNTADMIN Excessive Grants (snowflake)
  • Disabled User With Active Grants (snowflake)
  • Excessive Admin Roles (snowflake)
  • No Separation Of Duties (snowflake)
  • Service Account Password Auth (snowflake)
  • User Not Disabled (snowflake)
  • Anonymous Meeting Join Enabled (teams)
  • Lobby Bypass for Everyone (teams)
  • Auth Connector Has Broad Claim Mapping (teleport)
  • Auth Connector Has No Role Mappings (teleport)
  • Auth Connector Maps Claims to Admin Role (teleport)
  • GitHub Connector Maps All Teams (teleport)
  • Local User Has No SSO Identity (teleport)
  • Role Allows Impersonation (teleport)
  • Role Enables SSH Agent Forwarding (teleport)
  • Role Has Broad Admin RBAC Rules (teleport)
  • Role Has Unlimited Session TTL (teleport)
  • Role Has Wildcard App Labels (teleport)
  • Role Has Wildcard Database Labels (teleport)
  • Role Has Wildcard Kubernetes Labels (teleport)
  • Role Has Wildcard Node Labels (teleport)
  • Token Grants Admin Role (teleport)
  • Token Grants Auth System Role (teleport)
  • Token Has No Expiry (teleport)
  • Token Uses Static Join Method (teleport)
  • Trusted Cluster Has Broad Role Map (teleport)
  • User Account Is Locked (teleport)
  • User Has Admin Role (teleport)
  • User Has Excessive Roles (teleport)
  • Organization 2FA Not Enforced (terraform_cloud)
  • Organization SAML Not Enabled (terraform_cloud)
  • Organization Session Timeout Too Long (terraform_cloud)
  • Team Excessive Permissions (terraform_cloud)
  • Team Secret Visibility (terraform_cloud)
  • Team Workspace Admin Access (terraform_cloud)
  • User 2FA Not Enabled (terraform_cloud)
  • User Pending Invitation (terraform_cloud)
  • Access Group Empty (vercel)
  • Auto Join Enabled (vercel)
  • Member Unconfirmed (vercel)
  • Non-SSO Member (vercel)
  • Overly Broad Access (vercel)
  • Token No Expiration (vercel)
  • Token Overprivileged (vercel)
  • Token Stale (vercel)
  • API Client No IP Restriction (workato)
  • API Endpoint Inactive (workato)
  • API Platform Client Excessive Keys (workato)
  • Excessive API Clients (workato)
  • No Custom Roles (workato)
  • Admin With App Password (workspace)
  • Dormant Users (workspace)
  • User With App Password (workspace)
  • Data-Discount Logging Enabled (openrouter)
  • Permissive Privacy Posture (openrouter)

GDPR-28.1 — Third-Party Security Guarantees

Processors shall implement appropriate technical and organizational measures to meet GDPR requirements and protect data subject rights

  • Integration With Excessive Scope (workday)
  • Stale Integration System (workday)
  • Chat Webhooks Enabled (workspace)
  • OAuth App Critical Scopes (workspace)
  • OAuth App Broad Scopes (okta)
  • OAuth App With Restricted Scopes Widely Authorized (workspace)
  • OAuth App With Restricted Scopes (workspace)
  • OAuth App Inactive With Grants (okta)
  • OAuth App AI With Data Scopes (workspace)
  • OAuth App AI With Data Scopes (m365)
  • OAuth App AI With Broad Access (okta)
  • Multi-Tenant App Without Verified Publisher (m365)
  • Risk-Based Consent Not Configured (m365)
  • Admin Consent Requests Disabled (m365)
  • Users Can Register Applications (m365)
  • Excessive API Scopes (shopify)
  • Excessive Integrations (discord)
  • Stale Integration (vercel)
  • Overprivileged Integration (vercel)
  • App Approval Not Required (slack)
  • App Management Unrestricted (slack)
  • Custom App Sideloading (teams)
  • Unapproved Third-Party App (teams)
  • OAuth Integration Permissive (snowflake)
  • Users Can Install Outlook Add-ins (m365)
  • Copilot License Assigned (m365)
  • Copilot License on Guest User (m365)
  • Excessive Applications Installed (box)
  • Connected App with Full Dropbox Access (dropbox)
  • Orb Allowlist Empty (circleci)
  • Bot With Admin (discord)
  • Orphaned Webhook (discord)
  • Webhook Inventory (discord)
  • Connection to Sensitive Provider (workato)
  • Recipe Excessive Application Integrations (workato)

GDPR-28.3 — Processing Boundaries

Processing by a processor shall be governed by a contract stipulating subject matter, duration, nature and purpose of processing

  • Org Members Can Fork Private Repos (github)
  • Chat External Access Enabled (workspace)
  • Gmail Delegate Privileged (workspace)
  • Gmail Filter Forwards Externally (workspace)
  • Gmail Multiple Forwarding Destinations (workspace)
  • Gmail Send-As External Alias (workspace)
  • Gmail Suspicious Forwarding (workspace)
  • Drive External Sharing Enabled (workspace)
  • Drive Sharing Outside Organization (workspace)
  • Drive External Shared Drives Allowed (workspace)
  • Drive Publish to Web Allowed (workspace)
  • Drive Link Sharing Anyone (workspace)
  • Organization Sharing Enabled (m365)
  • Default Sharing Policy Allows External (m365)
  • Sharing Policy Allows External Domains (m365)
  • Remote Domain Auto-Forwarding Allowed (m365)
  • Outbound Spam External Forwarding Allowed (m365)
  • External Forwarding on Mailbox (m365)
  • Forwarding SMTP to External (m365)
  • Automatic Email Forwarding Enabled (workspace)
  • Public Sharing Model (salesforce)
  • External Messaging Enabled (teams)
  • External Shared Channel (teams)
  • Unrestricted External Federation (teams)
  • Guest Access to Groups Not Restricted (m365)
  • Guest Access to Group Content Not Restricted (m365)
  • Outbound Share Review (snowflake)
  • Share To Many Accounts (snowflake)
  • S3 Bucket Policy Public (aws)
  • Group Forking Allowed Outside (gitlab)
  • Group Public Visibility (gitlab)
  • Group Sharing Outside Organization (gitlab)
  • Group Sharing Unlocked (gitlab)
  • Active External Data Link (google_ads)
  • Overly Permissive Dashboard (grafana)
  • Overly Permissive Folder (grafana)
  • Default Calendar Sharing Too Permissive (m365)
  • Default Group Access Public (m365)
  • Distribution Group Open Join Policy (m365)
  • Distribution List Allows External Senders (m365)
  • Forwarding Address Configured (m365)
  • LinkedIn Integration Enabled in OWA (m365)
  • Mailbox Delivers to Both Mailbox and Forward (m365)
  • Mobile Contact Sync Enabled in OWA (m365)
  • Transport Rule Forwards Outside Org (m365)
  • Transport Rule Redirects Externally (m365)
  • Stale Public Page (notion)
  • Drive File Broad Internal Sharing (workspace)
  • Drive File Excessive Permissions (workspace)
  • Drive File External Commenter Access (workspace)
  • Drive File Link Sharing Enabled (workspace)
  • Drive File Org-Wide Link Sharing (workspace)
  • Drive File Stale External Sharing (workspace)
  • Group Allows External Posting (workspace)
  • Group Allows Open Join (workspace)
  • Group Contact Owner Anyone (workspace)
  • Group Discoverable by Anyone (workspace)
  • Group Domain-Wide Membership Visibility (workspace)
  • Group Public Conversations (workspace)
  • Mail Delegation Enabled (workspace)
  • Shared Drive Allows External Users (workspace)
  • Shared Drive Allows Non-Members (workspace)
  • Shared Drive Has External Members (workspace)
  • Shared Drive No Download Restriction (workspace)
  • LLM Data Exported To External Sink (openrouter)

GDPR-32.1a — Encryption

Encryption of personal data at rest and in transit

  • Encryption Not Required For Third-Party Endpoints (zoom)
  • TLS 1.3 Disabled (cloudflare)
  • Opportunistic Encryption Disabled (cloudflare)
  • Automatic HTTPS Rewrites Disabled (cloudflare)
  • S3 Bucket Encryption Disabled (aws)
  • KMS Key Rotation Disabled (aws)
  • KMS Key Pending Deletion (aws)
  • SQL TDE Disabled (azure)
  • Storage Infrastructure Encryption Disabled (azure)
  • Storage Shared Key Enabled (azure)
  • Storage Key Not Rotated (azure)
  • Key Vault Key No Expiry (azure)
  • Key Vault Secret No Expiry (azure)
  • Key Vault Purge Protection Disabled (azure)
  • Key Vault Soft Delete Disabled (azure)
  • S/MIME Buffer Encryption Not Enabled (m365)
  • S/MIME Encryption Algorithms Not Configured (m365)
  • S/MIME Clear Signing Not Enabled (m365)
  • S/MIME Triple-Wrap Not Enabled (m365)
  • Data Rekeying Disabled (snowflake)
  • Old Service Account Keys (gcp)
  • User Managed Service Account Keys (gcp)
  • Old Access Keys Not Rotated (aws)
  • DNSSEC Not Enabled (akamai)

GDPR-32.1b — Confidentiality & Access Control

Ability to ensure ongoing confidentiality of processing systems and services through access control, authentication, and authorization

GDPR-32.1b.i — Authentication Controls

Multi-factor authentication, single sign-on enforcement, password policy strength, session management, and phishing-resistant authentication

  • Delegated Auth Allows Local Fallback (workday)
  • Excessive Session Timeout (workday)
  • MFA Not Enforced (workday)
  • Weak Password Policy (workday)
  • Workday User Without MFA Required (workday)
  • Super Admin Account Recovery Enabled (workspace)
  • Weak Password Policy (workspace)
  • Weak Session Control (workspace)
  • Admin Without MFA (okta)
  • MFA Not Enrolled (okta)
  • Admin Without 2-Step Verification (workspace)
  • User 2-Step Verification Not Enforced (workspace)
  • MFA Not Enabled (cloudflare)
  • Two-Factor Enforcement Disabled (cloudflare)
  • Root Account MFA Not Enabled (aws)
  • User MFA Not Enabled (aws)
  • MFA Disabled (1password)
  • Sign-in Without MFA (1password)
  • MFA Not Enabled (lastpass)
  • Admin Without MFA (lastpass)
  • User Without MFA (atlassian)
  • Two-Step Verification Not Enforced (atlassian)
  • Org 2FA Not Required (github)
  • Member Without 2FA (github)
  • Group 2FA Not Enforced (gitlab)
  • Member Without 2FA (gitlab)
  • MFA Not Required (slack)
  • User No MFA (slack)
  • Admin Without MFA (zoom)
  • User Without MFA (zoom)
  • Admin Without MFA (salesforce)
  • User Without MFA (salesforce)
  • MFA Not Required for Admins (discord)
  • User MFA Not Enabled (akamai)
  • Identity User MFA Not Enabled (ovhcloud)
  • Identity User Password Never Changed (ovhcloud)
  • MFA Not Enabled (ovhcloud)
  • MFA Not Enabled (snowflake)
  • Authentication Policy No MFA (snowflake)
  • Staff MFA Disabled (shopify)
  • No MFA Requirement (cloudflare_access)
  • Weak Password Policy (okta)
  • Weak Password Policy (aws)
  • Weak Password Policy (salesforce)
  • Weak Password Policy (snowflake)
  • Weak Password Policy (zoom)
  • Weak Password Length (docusign)
  • Weak Password Strength (docusign)
  • Very Weak Master Password (lastpass)
  • Weak Master Password (lastpass)
  • Weak Authentication Factors Enabled (m365)
  • Custom Banned Passwords Not Enforced (m365)
  • Password Only Auth (snowflake)
  • CA Legacy Auth Not Blocked (m365)
  • Phishing Resistant Auth Policies (okta)
  • Phishing Resistant MFA Factors (okta)
  • MFA Status Unknown (1password)
  • Password Manager Disabled (chrome_enterprise)
  • Long Session Duration (cloudflare_access)
  • One-Time PIN Only Authentication (cloudflare_access)
  • Group 2FA Grace Period Too Long (gitlab)
  • CA MFA Not Enforced (m365)
  • Security Defaults Disabled (m365)
  • Guest Email OTP Not Enabled (m365)
  • Session MFA Not Required (okta)
  • Advanced Permissions Disabled (pagerduty)
  • No Clickjack Protection (salesforce)
  • Session Timeout Too Long (salesforce)
  • Admin Action MFA Not Enforced (teleport)
  • Cluster MFA Disabled (teleport)
  • Device Trust Disabled (teleport)
  • Expired Certificate Disconnect Disabled (teleport)
  • Local Auth Enabled With SSO (teleport)
  • Local User Has No MFA Device (teleport)
  • Passwordless Without Hardware Key Policy (teleport)
  • Role Does Not Require Session MFA (teleport)
  • Session MFA Not Enforced (teleport)
  • TOTP Without WebAuthn (teleport)
  • User Uses Only TOTP for MFA (teleport)
  • Admin 2-Step Verification Not Enforced (workspace)
  • Delegated Admin Without 2-Step Verification (workspace)
  • User Without 2-Step Verification (workspace)

GDPR-32.1b.ii — Authorization Controls

Role-based access control, least privilege enforcement, admin privilege restrictions, and access review

GDPR-32.1c — Availability & Resilience

Ability to ensure ongoing availability and resilience of processing systems and services

  • S3 Bucket Versioning Disabled (aws)
  • Bucket Versioning Disabled (gcp)
  • Storage Blob Soft Delete Disabled (azure)
  • Storage Container Soft Delete Disabled (azure)
  • Backups Disabled (digitalocean)
  • Database Single Node (digitalocean)
  • Kubernetes HA Disabled (digitalocean)
  • No Backups (digitalocean)
  • Single Node Cluster (digitalocean)
  • Property No Origin Failover (akamai)
  • Super Admin Redundancy Missing (okta)
  • Super Admin Redundancy Missing (workspace)
  • Super Admin Redundancy Missing (cloudflare)
  • Owner Redundancy Missing (openai)
  • Admin Redundancy Missing (anthropic)
  • Admin Redundancy (datadog)
  • Single Account Owner (pagerduty)
  • Single Account Owner (incidentio)
  • Owner Redundancy (slack)
  • Workspace Single Admin (anthropic)
  • Workspace Single Admin (workato)

GDPR-32.1d — Testing & Evaluation

Process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures

  • Repo Secret Scanning Push Protection Disabled (github)
  • Security Alert Notifications Disabled (azure)
  • Security Contact Email Missing (azure)
  • Security Contact Phone Missing (azure)
  • Security Contact Missing (gcp)
  • Defender App Service Disabled (azure)
  • Defender Containers Disabled (azure)
  • Defender Key Vault Disabled (azure)
  • Defender Resource Manager Disabled (azure)
  • Defender Servers Disabled (azure)
  • Defender SQL Disabled (azure)
  • Defender Storage Disabled (azure)
  • SQL Threat Detection Disabled (azure)
  • SQL Vulnerability Assessment Disabled (azure)
  • Network Watcher Disabled (azure)
  • Repo Dependabot Disabled (github)
  • Repo Secret Scanning Disabled (github)
  • Project Container Scanning Disabled (gitlab)
  • Monitoring Disabled (digitalocean)
  • MFA Suspicious Activity Reporting Disabled (m365)
  • Sensitive Audit Event (openai)
  • Usage Anomaly (openai)
  • No Alert Rules Configured (grafana)
  • Master Password Changed (1password)
  • AWS Config Not Recording (aws)
  • CloudTrail Data Events Disabled (aws)
  • VPC Flow Logs Disabled (aws)
  • Modifiable Retention Policy (box)
  • No Indefinite Retention Policies (box)
  • No Retention Policies Defined (box)
  • Permanent Delete Disposition Action (box)
  • Retired Retention Policy (box)
  • Short Retention Period (box)
  • Office Add-in Disabled (dropbox)
  • Suspended Member Not Removed (dropbox)
  • Subnet Flow Logs Disabled (gcp)
  • Unified Audit Log Not Enabled (m365)
  • Audit Log Using Local Filesystem Storage (teleport)
  • Proxy Host Key Checks Disabled (teleport)
  • Role Disables Session Recording (teleport)
  • Session Recording Disabled (teleport)
  • Session Recording in Async Mode (teleport)
  • Session Recording in Proxy Mode (teleport)

GDPR-33.1 — Detection Capability

Technical measures to detect unauthorized access, data breaches, and security incidents

  • Audit Logging Not Enabled (gcp)
  • CloudTrail Not Logging (aws)
  • Global Mailbox Auditing Disabled (m365)
  • SQL Auditing Disabled (azure)
  • Alert Disabled (azure)
  • Alert NSG Create Missing (azure)
  • Alert NSG Delete Missing (azure)
  • Alert Policy Assignment Missing (azure)
  • Alert Security Solution Create Missing (azure)
  • Alert Security Solution Delete Missing (azure)
  • Alert SQL Firewall Missing (azure)
  • CA Block Risky Sign-ins Missing (m365)
  • Suspicious Outbound Copy Not Enabled (m365)
  • Failed Sign-in Attempt (1password)
  • Failed Sign-in From Untrusted Location (1password)
  • High Failed Logins (salesforce)
  • Alert Source No Auto-Resolve (incidentio)
  • Escalation Path Shallow (incidentio)
  • Schedule No Holiday Configuration (incidentio)
  • Schedule Without Active Shift (incidentio)
  • Single Responder Escalation (incidentio)
  • Single Rotation Schedule (incidentio)
  • Workflow Disabled or Error (incidentio)
  • Workflow Ignores Step Errors (incidentio)
  • Escalation Policy Without Loops (pagerduty)
  • Escalation Policy Without Schedule (pagerduty)
  • Possibly Abandoned Service (pagerduty)
  • Service Without Auto-Resolve (pagerduty)
  • Service Without Escalation Policy (pagerduty)
  • Single User Escalation Rule (pagerduty)
  • Single User Schedule (pagerduty)

GDPR-33.2 — Notification Infrastructure

Established notification channels and alerting mechanisms to communicate breaches within 72 hours

  • Admin Malware Notifications Disabled (m365)
  • Outbound Spam Notification Disabled (m365)
  • Security Alert Notifications Disabled (azure)
  • External Contact Point (grafana)

GDPR-44.1 — Transfer Controls

Restrictions and controls preventing unauthorized cross-border transfer of personal data

  • Org Members Can Create Public Repos (github)
  • Public Storage Bucket (gcp)
  • S3 Bucket Public Access Not Blocked (aws)
  • Storage Public Blob Access (azure)
  • Storage Network Default Allow (azure)
  • Drive File Public Sharing (workspace)
  • Drive File Publicly Indexed (workspace)
  • Drive File Shared With Personal Email (workspace)
  • Drive File Shared With External Domain (workspace)
  • Drive File External Edit Access (workspace)
  • Drive File Owner Is External (workspace)
  • Drive User Excessive External Sharing (workspace)
  • Drive Shared Drive Has External Members (workspace)
  • Group Allows External Members (workspace)
  • External Account Member (cloudflare)
  • External Members at Org Level (gcp)
  • External User With Product Access (atlassian)
  • External Admin (datadog)
  • External Admin Service Account (datadog)
  • Guest Users Present (m365)
  • Guest Privileged Role (azure)
  • Guest Group Privileges Not Restricted (m365)
  • Guest Access Overly Permissive (teams)
  • Guest Members in Team (teams)
  • Public Team (teams)
  • Public Microsoft 365 Group (m365)
  • Public Dashboard (grafana)
  • Public Project (gitlab)
  • Public Repo Without Security Policy (github)
  • Publicly Shared Page (notion)
  • Publicly Shared Database (notion)
  • Guild Publicly Discoverable (discord)
  • Dashboard Public Sharing (datadog)
  • Dashboard Public URL (datadog)
  • Confluence Space Anonymous Access (atlassian)
  • Confluence Space Public Links (atlassian)
  • Jira Project Public Access (atlassian)
  • Publicly Accessible (digitalocean)
  • Storage Container Public (ovhcloud)
  • Instance Has Public IP (ovhcloud)
  • Public Source (vercel)

GDPR-44.2 — Appropriate Safeguards

Technical safeguards ensuring data protection during international transfers

  • TLS Mode Not Strict (cloudflare)
  • Always Use HTTPS Disabled (cloudflare)
  • HSTS Disabled (cloudflare)
  • App Service HTTPS Disabled (azure)
  • App Service Minimum TLS (azure)
  • Storage HTTPS Not Required (azure)
  • SQL Minimum TLS (azure)
  • HTTP Allowed (digitalocean)
  • No SSL Termination (digitalocean)
  • Origin Not Using TLS (akamai)
  • HSTS Not Enabled (akamai)
  • Webhook Using HTTP (shopify)

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial