Cloud Integrations

Evidence collected straight from the AWS environment

For vendors running in the cloud, Aranis collects technical evidence directly — IAM configuration, encryption, logs, and network controls — with no reliance on self-declaration. Automated collection covers AWS today; GCP, Azure, and OCI are on the roadmap.

Get started

Technical evidence, not self-declared

The vendor grants read-only access and the platform collects the actual cloud configuration state.

30 controls answerable from cloud evidence

These are the 30 questionnaire controls that cloud configuration can answer — IAM without MFA, public buckets, encryption at rest, audit logs. Automated collection of them runs on AWS today.

Mapped to NIST CSF 2.0

Each collected piece of evidence is mapped to the corresponding control in the questionnaire.

AWS IAM & S3

MFA, password policy, public buckets, IAM roles and access policies.

Encryption at rest

Checks whether EBS, RDS, and S3 have encryption enabled.

Audit logs

CloudTrail and CloudWatch Logs — confirms logs are active and retained.

Network controls

Security groups, NACLs, VPCs, and publicly exposed critical port openings.

Collect cloud evidence automatically

Connect the vendor's environment and see the real state in minutes.

Get started