What ARCO scans
Understand the signals ARCO reads from AWS and how those signals become findings, framework gaps, and readiness states.
AWS posture checks
Scans inspect configuration signals across supported AWS services and surface findings related to logging, encryption, identity, network exposure, and monitoring.
Framework mapping
Checks are mapped into SOC 2, HIPAA, and PCI DSS readiness views so teams can explain why a finding matters.
Readiness states
No AWS account or no scan means awaiting first scan. ARCO Governance avoids fake readiness claims when there is no source signal.
Related guides
AWS onboarding
Connect AWS securely to ARCO Governance using CloudFormation, Terraform, or manual IAM role setup with read-only access and an External ID.
Read guideReports and readiness
Understand ARCO Governance readiness views, AWS report types, evidence exports, auditor packets, certification boundaries, and plan limits.
Read guidePricing and plans
Compare ARCO Governance Starter, Growth, and Scale plans, including AWS account limits, scan frequency, report exports, evidence ZIPs, and support.
Read guide