IaC Compliance
Compare 55 iac compliance tools to find the right one for your needs
🔧 Tools
Compare and find the best iac compliance for your needs
Wiz
A leading CNAPP that provides full stack visibility and security for your cloud.
Spacelift
A CI/CD platform for IaC with built-in policy and compliance features.
CrowdStrike Falcon Cloud Security
A comprehensive cloud security platform that provides breach protection for the entire cloud estate, from workloads to infrastructure.
Orca Security
An agentless cloud security platform with IaC scanning.
Fugue by Snyk
A cloud security posture management (CSPM) tool with IaC capabilities.
Open Policy Agent
An open-source, general-purpose policy engine.
SpectralOps
A developer-first platform for finding and fixing security issues in code.
Datadog Cloud Security Management
A cloud security solution from Datadog that includes CSPM, CWP, and IaC scanning.
Snyk IaC
A tool that helps developers find and fix security issues in IaC files like Terraform, CloudFormation, and Kubernetes.
Sysdig Secure
A cloud security platform with deep runtime insights.
Deepfactor
A runtime application security platform that includes IaC scanning.
CloudQuery
An open-source tool that extracts, transforms, and loads your cloud infrastructure data into a PostgreSQL database, allowing you to query it with SQL.
Steampipe
An open-source tool that instantly translates APIs into a PostgreSQL database, allowing you to query your cloud infrastructure with SQL.
Lightspin
A CNAPP that provides a contextual view of cloud security risks.
oak9
An Infrastructure as Code security platform that is designed for developers.
Prowler
An open-source security tool for AWS, Azure, and GCP that performs security assessments, audits, and incident response.
GitHub Advanced Security
A suite of security tools for GitHub repositories.
SentinelOne Singularity Cloud
A cloud security platform that provides autonomous threat protection for cloud workloads and environments.
Fugue
A cloud security platform focused on IaC and CSPM.
Trivy
A scanner for vulnerabilities in container images, filesystems, and Git repositories, as well as for configuration issues.
JupiterOne
A platform that creates a graph-based model of your cyber assets and their relationships, allowing you to understand and manage your attack surface.
Kyverno
A policy engine designed for Kubernetes that can validate, mutate, and generate configurations using policies.
tfsec
A static analysis tool for Terraform code.
Lacework
A CNAPP that uses data and machine learning to secure cloud environments.
Pulumi CrossGuard
A policy as code solution for the Pulumi platform.
Bridgecrew by Prisma Cloud
A developer-first cloud security platform with a focus on IaC.
SonarCloud
A cloud-based code quality and security service.
Datadog Cloud Security Posture Management
A CSPM solution that scans your cloud environments for misconfigurations and compliance risks, and provides remediation guidance.
Snyk Infrastructure as Code
A developer-first IaC security tool to find and fix misconfigurations.
Sentinel
A policy as code framework from HashiCorp.
Checkov
An open-source static analysis tool for infrastructure as code.
TFLint
An open-source linter for Terraform that checks for errors, best practice improvements, and potential bugs.
Prisma Cloud by Palo Alto Networks
A comprehensive cloud security platform with IaC scanning capabilities.
Sysdig
A cloud-native security and monitoring platform that provides a unified view of risk, health, and performance for cloud and container environments.
Aqua Security
A comprehensive security platform for cloud native applications.
Rapid7 InsightCloudSec
A CNAPP from Rapid7 for cloud security and compliance.
Zscaler Posture Control
A cloud-native application protection platform (CNAPP) for unified cloud security.
HashiCorp Sentinel
A policy as code framework for HashiCorp products.
SonarQube
A platform for continuous inspection of code quality and security.
Veracode
A comprehensive application security platform.
GitLab Ultimate
A complete DevOps platform with built-in IaC security.
Tenable Cloud Security
A cloud security platform that provides visibility and control over cloud environments, including IaC security.
Qualys Cloud Platform
A cloud-based platform for IT, security, and compliance.
Tenable.cs
A cloud native security platform from Tenable.
KICS
An open-source static analysis tool for IaC security.
Checkmarx One
A comprehensive application security platform that includes IaC scanning with KICS.
Checkmarx IaC Security
An enterprise-grade IaC security solution from Checkmarx.
Terrascan
An open-source static code analyzer for IaC.
KICS by Checkmarx
An open-source solution for static analysis of IaC.
Bridgecrew
A cloud security platform that helps developers secure their infrastructure from code to cloud.
Regula
An open-source policy engine for checking IaC against security and compliance rules.
Accurics
A cloud security platform that enables cyber resilience through policy as code.
Cloud Custodian
An open-source tool for cloud security and governance.
Turbot Pipes
An open-source tool for querying and managing your cloud environment.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine.