Network security checks across 5 apps
IP allow-lists, TLS, DNS and edge settings that keep the application reachable only from where it should be.
Why it matters
IP allow-lists, TLS versions and DNS settings decide from where an application can be reached at all. They drift when a vendor changes a default or an admin opens access for a contractor and never closes it, and nobody notices until a scan compares the tenant with the baseline.
Browse by app
Highest-severity checks
The 8 most severe Network security checks across all 5 apps — each links to the connector page where the setting, its remediation and its framework mapping are documented.
- Cloud SQL Authorized Networks Open to World — Google Cloud severity: critical
- No Firewall — DigitalOcean severity: critical
- Publicly Accessible — DigitalOcean severity: critical
- SSH Open To All — DigitalOcean severity: critical
- Allows All Inbound — DigitalOcean severity: high
- Cloud Function Public Ingress — Google Cloud severity: high
- Cloud Run Service Public Ingress — Google Cloud severity: high
- DNSSEC Not Enabled — Akamai severity: high
Where to start
Connect DigitalOcean first — it carries the most Network security checks in the catalog(setup guide, read-only access). A first scan takes about 15 minutes and reports every failing check on this page with its remediation steps.