IaC Compliance
Compare 43 iac compliance tools to find the right one for your needs
🔧 Tools
Compare and find the best iac compliance for your needs
Wiz
A CNAPP that provides full-stack visibility and risk assessment for your cloud environment.
Spacelift
A CI/CD platform for IaC with built-in policy and compliance features.
CrowdStrike Falcon Cloud Security
A cloud security platform that provides breach protection for the entire cloud estate.
Orca Security
An agentless cloud security platform that provides 100% visibility into your cloud environment.
Fugue by Snyk
A cloud security posture management (CSPM) tool with IaC capabilities.
Open Policy Agent
An open-source, general-purpose policy engine.
SpectralOps
A developer-first platform for finding and fixing security issues in code.
Datadog Cloud Security Management
A cloud security solution from Datadog that includes CSPM, CWP, and IaC scanning.
Snyk IaC
Find and fix security issues in your Terraform, CloudFormation, Kubernetes, and ARM configurations.
Sysdig Secure
A cloud-native security platform that provides threat detection, compliance, and vulnerability management.
Deepfactor
A runtime application security platform that includes IaC scanning.
oak9
An Infrastructure as Code security platform that is designed for developers.
Lightspin
A CNAPP that provides a contextual view of cloud security risks.
Fugue
A cloud security posture management (CSPM) tool with a focus on IaC security and compliance.
Trivy
A simple and comprehensive vulnerability scanner for containers and other artifacts, including IaC.
SentinelOne Singularity Cloud
A cloud security platform that provides autonomous threat protection for cloud workloads and environments.
GitHub Advanced Security
A suite of security features for GitHub that helps you find and fix vulnerabilities in your code.
tfsec
A static analysis security scanner for Terraform code.
Lacework
A CNAPP that provides automated threat detection, compliance, and workload protection.
Bridgecrew by Prisma Cloud
A developer-first cloud security platform with a focus on IaC.
Pulumi CrossGuard
A policy as code solution for the Pulumi platform.
SonarCloud
A cloud-based code quality and security service.
Checkov
An open-source static analysis tool for scanning infrastructure as code (IaC) files for misconfigurations.
Prisma Cloud by Palo Alto Networks
A comprehensive cloud security platform that includes IaC scanning and compliance.
Aqua Security
A comprehensive security platform for cloud-native applications, from development to production.
Rapid7 InsightCloudSec
A cloud-native security platform for unified visibility and control.
Zscaler Posture Control
A cloud-native application protection platform (CNAPP) for unified cloud security.
HashiCorp Sentinel
A policy as code framework for HashiCorp products.
Veracode
A comprehensive application security platform that helps organizations secure their software.
GitLab Ultimate
A complete DevOps platform that includes integrated security capabilities, including IaC scanning.
Terrascan
An open-source static code analyzer for Infrastructure as Code.
Tenable.cs
A cloud-native security platform with IaC scanning.
Qualys Cloud Platform
A comprehensive security and compliance platform with IaC scanning.
KICS
An open-source static analysis tool for Infrastructure as Code.
Tenable Cloud Security
A cloud security platform that provides visibility and control over cloud environments, including IaC security.
Checkmarx One
A comprehensive application security platform that includes IaC scanning with KICS.
KICS by Checkmarx
An open-source solution for static analysis of IaC.
Bridgecrew
A developer-first platform for cloud security, focusing on infrastructure as code.
Turbot Pipes
An open-source tool for querying and managing your cloud environment.
Cloud Custodian
An open-source rules engine for managing public cloud accounts.
Regula
An open-source policy engine for checking IaC against security and compliance rules.
Accurics
A cloud security platform that enables cyber resilience through policy as code.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine.