# SecurityProductStates Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/securityproductstates/

Schema for the `SecurityProductStates` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier — a full ARN, resource id, or self-link — passed through verbatim, never truncated or normalized.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider returns no location, the queried region is substituted and flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified — e.g. 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them, with no case folding or normalization. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto actually read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`created_at`** _(string)_
  When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Explanation of the reason, where one adds anything.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`product_name`** _(string)_
  Which product — for example 'securityhub', 'guardduty', 'inspector2', 'macie', 'config', 'accessanalyzer', 'defender-for-cloud', 'security-command-center'.
- **`enabled`** _(boolean)_
  Whether the product is enabled in this account and region. 'Not enabled' (e.g. a 404) maps to false, never unknown; a permission failure is left null and flagged in unreadable_fields.
- **`status`** _(string)_
  The provider's own status string, verbatim. Distinct from `enabled` — e.g. AWS Macie's PAUSED is enabled-but-suspended, not disabled.
- **`tier`** _(string)_
  Paid tier or edition, where the provider has one. AWS services are usage-priced with no tier concept, so this is always null there (not_supported_by_provider in unreadable_fields).
- **`plan_name`** _(string)_
  The specific plan, for providers with per-plan states (e.g. Azure Defender for Servers vs Storage). No AWS equivalent. Free-trial status is not represented here.
- **`enabled_standards`** _(array<string>)_
  Which compliance benchmarks are subscribed, as provider identifiers. Security Hub only — other products' feature toggles go in enabled_features instead.
- **`enabled_features`** _(array<string>)_
  Capability toggles the product exposes that are not compliance standards.
- **`last_evaluated_at`** _(string)_
  When the product last evaluated the estate. On AWS, only Config and Access Analyzer expose this; otherwise it's null (not_supported_by_provider) — never substituted with a config-change timestamp.
- **`config_updated_at`** _(string)_
  When the product's configuration last changed. Distinct from last_evaluated_at and never used as a stand-in for it.

## Methods

- [GET /unified/cloud-infrastructure/security_product_states](/docs/api-reference/unified-cloud-infrastructure-api/securityproductstates/list) — List Security product states
