DSPM coverage by cloud
Which data store types DSPM analyses on each cloud and for self-hosted databases, with per-service notes on what is checked and what is not.
The stores below receive the full set of DSPM checks. Other data services — on AWS, for example DocumentDB, Neptune, Timestream, Keyspaces, ElastiCache, SQS, SNS and MSK — are evaluated by the storage and database posture rules and their findings are grouped into DSPM modules, but they do not get the per-store classification and governance score.
AWS
| Store | Notes |
|---|---|
| S3 buckets | Full checks; multi-signal public determination; bucket-policy cross-account analysis; object ownership; event-notification lineage |
| RDS instances and Aurora clusters | Encryption (storage encryption or KMS key), public accessibility, log exports or enhanced monitoring, backup retention and deletion protection |
| DynamoDB tables | Server-side encryption, point-in-time recovery, streams; not publicly reachable by design |
| Redshift clusters | Encrypted flag, public accessibility, audit logging, snapshot retention |
| Glue databases | Encryption and classification |
| OpenSearch domains | Encryption at rest, log publishing |
| Kinesis streams | Treated as encrypted; consumers recorded as lineage |
| Lake Formation | Broad default and wildcard admin grants |
Azure
Storage accounts, Data Lake Storage, Azure SQL servers, Cosmos DB, Synapse workspaces and Key Vault.
Google Cloud
Cloud Storage buckets, Cloud SQL instances, BigQuery datasets, Spanner instances, Firestore databases and Secret Manager secrets. Residency treats europe-* locations as EU and us-* as US.
Oracle Cloud (OCI)
Object Storage buckets, Autonomous Databases, NoSQL tables and Streaming streams.
Alibaba Cloud
OSS buckets, ApsaraDB RDS instances, PolarDB clusters, Tablestore instances and MaxCompute projects.
IBM Cloud
Cloud Object Storage buckets, IBM Cloud Databases instances (for example Databases for PostgreSQL), Cloudant and Event Streams.
Kubernetes
Secrets (always labelled confidential), ConfigMaps (confidential when a key name looks like a credential), persistent volume claims and StatefulSets.
Self-hosted databases
PostgreSQL, MySQL, MariaDB, SQL Server, MongoDB, Oracle, Cassandra, IBM Db2 and Snowflake, once onboarded as technology accounts. DSPM classifies them from their resource, database and schema names; it only adds labels and never overwrites a label from the cloud path. Engine-level hardening for the same databases is covered by Database Security through CIS benchmarks.
Not covered
- Data inside SaaS applications other than Snowflake.
- On-premises file shares and storage arrays.
- Databricks.