What it checks
On AWS: public S3 storage exposure, open security-group ingress, stale IAM access keys, overly-permissive IAM policies, disabled CloudTrail logging, and default-encryption gaps.
On Azure: public blob storage exposure and open NSG ingress rules. On GCP: public cloud storage exposure and open VPC firewall ingress.
Credentials used once, never stored
Provide read-only credentials for whichever provider(s) you want scanned — leave any provider's fields blank to skip it. Credentials are used only for the duration of the scan and are never written to disk or the database.