Encryption, keys & secrets security checks across 10 apps
Encryption at rest and in transit, key rotation, and the API keys, tokens and credentials that outlive the people who created them.
Why it matters
API keys and tokens outlive the people who created them; an unrotated key is how an integration nobody remembers keeps reading data years later. Encryption settings and key rotation are checkbox items on every framework and among the least often verified in practice.
Browse by app
- Microsoft 365 9 checks
- Cloudflare 9 checks
- Grafana Cloud 8 checks
- Workato 7 checks
- Akamai 5 checks
- DigitalOcean 4 checks
- Azure 3 checks
- Terraform Cloud 3 checks
- Jamf Pro 3 checks
- Cloudflare Access 3 checks
Highest-severity checks
The 8 most severe Encryption, keys & secrets checks across all 10 apps — each links to the connector page where the setting, its remediation and its framework mapping are documented.
- SSL Encryption Disabled — Cloudflare severity: critical
- Token With Wildcard Policy — Grafana Cloud severity: critical
- Variable Not Marked Sensitive — Terraform Cloud severity: critical
- Variable Plaintext Credentials — Terraform Cloud severity: critical
- Always Use HTTPS Disabled — Cloudflare severity: high
- API Client No IP Restriction — Workato severity: high
- API Platform Client Static Auth Token — Workato severity: high
- Computer FileVault Disabled — Jamf Pro severity: high
Where to start
Connect Microsoft 365 first — it carries the most Encryption, keys & secrets checks in the catalog(setup guide, read-only access). A first scan takes about 15 minutes and reports every failing check on this page with its remediation steps.