8 findings
| HIGH | OPEN | Azure OpenAI RAI policy should have prompt injection protection | AI | Cloud only | azure://Microsoft.CognitiveServices/accounts/prod-openai |
| HIGH | OPEN | Azure AI Search public network access should be disabled | AI | Cloud only | azure://Microsoft.Search/searchServices/prod-search |
| MEDIUM | OPEN | Bedrock Agent should be associated with Bedrock Guardrails | AI | Cloud only | arn:aws:bedrock:eu-west-1:123456789012:agent/support-agent |
| MEDIUM | OPEN | Bedrock Guardrail should protect PII data | AI | Cloud only | arn:aws:bedrock:eu-west-1:123456789012:guardrail/prod-guardrail |
| MEDIUM | OPEN | Direct Internet access should be disabled for SageMaker Notebook Instance | AI | DRIFT | arn:aws:sagemaker:eu-west-1:123456789012:notebook-instance/ds-notebook |
| MEDIUM | OPEN | SageMaker Notebook Instance should be encrypted using a customer-managed key | AI | Cloud only | arn:aws:sagemaker:eu-west-1:123456789012:notebook-instance/ds-notebook |
| INFO | OPEN | Active Bedrock long-term API key | AI | Cloud only | ACCA0123456789EXAMPLE |
| INFO | OPEN | Bedrock Agent should reference an active service role | AI | Cloud only | arn:aws:bedrock:eu-west-1:123456789012:agent/support-agent |