IaC Compliance
Compare 52 iac compliance tools to find the right one for your needs
🔧 Tools
Compare and find the best iac compliance for your needs
Wiz
An agentless cloud security platform that provides a comprehensive view of your cloud risks across your entire cloud environment.
Spacelift
A CI/CD platform for IaC with built-in policy and compliance features.
CrowdStrike Falcon Cloud Security
A comprehensive cloud security platform that provides breach protection for the entire cloud estate, from workloads to infrastructure.
Orca Security
An agentless cloud security platform that provides workload and data protection, cloud security posture management (CSPM), and vulnerability management.
Fugue by Snyk
A cloud security posture management (CSPM) tool with IaC capabilities.
Open Policy Agent
An open-source, general-purpose policy engine.
SpectralOps
A developer-first platform for finding and fixing security issues in code.
Datadog Cloud Security Management
A cloud security solution from Datadog that includes CSPM, CWP, and IaC scanning.
Snyk IaC
A tool that helps developers find and fix security issues in IaC files like Terraform, CloudFormation, and Kubernetes.
Sysdig Secure
A cloud-native security platform that provides threat detection, compliance, and vulnerability management.
Deepfactor
A runtime application security platform that includes IaC scanning.
CloudQuery
An open-source tool that extracts, transforms, and loads your cloud infrastructure data into a PostgreSQL database, allowing you to query it with SQL.
Steampipe
An open-source tool that instantly translates APIs into a PostgreSQL database, allowing you to query your cloud infrastructure with SQL.
Lightspin
A CNAPP that provides a contextual view of cloud security risks.
oak9
An Infrastructure as Code security platform that is designed for developers.
Prowler
An open-source security tool for AWS, Azure, and GCP that performs security assessments, audits, and incident response.
SentinelOne Singularity Cloud
A cloud security platform that provides autonomous threat protection for cloud workloads and environments.
Trivy
A comprehensive open-source security scanner for vulnerabilities in container images, filesystems, and Git repositories, as well as for IaC misconfigurations.
Fugue
A cloud security posture management (CSPM) platform that helps you secure your cloud environment from development to runtime.
GitHub Advanced Security
A suite of security features for GitHub that helps you find and fix vulnerabilities in your code.
JupiterOne
A platform that creates a graph-based model of your cyber assets and their relationships, allowing you to understand and manage your attack surface.
Kyverno
A policy engine designed for Kubernetes that can validate, mutate, and generate configurations using policies.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform templates.
Lacework
A cloud security platform that uses data and automation to provide visibility, threat detection, and compliance across multi-cloud environments.
Pulumi CrossGuard
A policy as code solution for the Pulumi platform.
Bridgecrew by Prisma Cloud
A developer-first cloud security platform with a focus on IaC.
SonarCloud
A cloud-based code quality and security service.
Datadog Cloud Security Posture Management
A CSPM solution that scans your cloud environments for misconfigurations and compliance risks, and provides remediation guidance.
Checkov
An open-source static analysis tool for scanning Infrastructure as Code (IaC) files for misconfigurations and security vulnerabilities.
Prisma Cloud by Palo Alto Networks
A comprehensive cloud security platform that includes IaC scanning and compliance.
Aqua Security
A comprehensive cloud-native security platform that provides security from code to cloud and back.
Rapid7 InsightCloudSec
A cloud-native security platform for unified visibility and control.
Sysdig
A cloud-native security and monitoring platform that provides a unified view of risk, health, and performance for cloud and container environments.
Zscaler Posture Control
A cloud-native application protection platform (CNAPP) for unified cloud security.
HashiCorp Sentinel
A policy as code framework for HashiCorp products.
TFLint
An open-source linter for Terraform that checks for errors, best practice improvements, and potential bugs.
GitLab Ultimate
A complete DevOps platform that includes integrated security capabilities, including IaC scanning.
Veracode
A comprehensive application security platform that helps organizations secure their software.
KICS
An open-source static analysis tool that finds security vulnerabilities, compliance issues, and infrastructure misconfigurations in IaC.
Tenable Cloud Security
A cloud security platform that provides visibility and control over cloud environments, including IaC security.
Qualys Cloud Platform
A comprehensive security and compliance platform with IaC scanning.
Tenable.cs
A cloud-native application protection platform (CNAPP) that helps you secure your cloud from code to cloud.
Terrascan
An open-source static code analyzer for IaC that helps detect security vulnerabilities and compliance violations.
Checkmarx One
A comprehensive application security platform that includes IaC scanning with KICS.
Checkmarx IaC Security
A solution that scans your IaC for security vulnerabilities, compliance issues, and misconfigurations.
Bridgecrew
A cloud security platform that helps developers secure their infrastructure from code to cloud.
KICS by Checkmarx
An open-source solution for static analysis of IaC.
Turbot Pipes
An open-source tool for querying and managing your cloud environment.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack.
Cloud Custodian
An open-source rules engine for managing public cloud accounts.
Accurics
A cloud security platform that enables cyber resilience through policy as code.
Regula
An open-source policy engine for checking IaC against security and compliance rules.