IaC Security

Compare 132 iac security tools to find the right one for your needs

📂 Subcategories

🔧 Tools

Compare and find the best iac security for your needs

Spacelift

The most flexible and sophisticated CI/CD for Infrastructure as Code.

A specialized CI/CD platform for IaC that provides automation, collaboration, and governance, with built-in security scanning.

View tool details →

Kubescape

An open-source Kubernetes security platform.

A tool for risk analysis, security, compliance, and misconfiguration scanning in Kubernetes.

View tool details →

Wiz

The Cloud Security Platform.

A CNAPP that provides full-stack visibility and risk assessment for your cloud environment.

View tool details →

CrowdStrike Falcon Cloud Security

One platform to stop the breach, for any cloud.

Extends CrowdStrike's EDR leadership to cloud security.

View tool details →

Snyk IaC

Developer-first infrastructure as code security.

Finds and fixes misconfigurations in Terraform, CloudFormation, Kubernetes, and ARM templates within developer workflows.

View tool details →

Spacelift

The most flexible and collaborative CI/CD for Infrastructure as Code.

A CI/CD platform for IaC with built-in policy and compliance features.

View tool details →

Open Policy Agent (OPA)

Policy-based control for cloud native environments.

An open-source, general-purpose policy engine.

View tool details →

Wiz

The Cloud Security Platform.

An agentless CNAPP that provides full-stack visibility of cloud risks, connecting IaC issues to runtime context.

View tool details →

Wiz

The #1 cloud security platform

A CNAPP that provides full stack visibility and security.

View tool details →

Terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning.

An open-source static code analysis tool for IaC that helps detect security and compliance violations.

View tool details →

GitGuardian

The code security platform for the DevOps generation.

A platform for automated secrets detection and remediation.

View tool details →

GitGuardian IaC Security

Automated IaC security and compliance.

Scans infrastructure-as-code files for misconfigurations and security issues within the software development lifecycle.

View tool details →

Orca Security

The pioneer of agentless cloud security

Provides comprehensive, agentless security and compliance for the cloud.

View tool details →

CrowdStrike Falcon Cloud Security

One platform to stop cloud breaches.

A cloud security platform that provides breach protection for the entire cloud estate.

View tool details →

Checkov

Policy-as-code for everyone. Scan infrastructure as code for misconfigurations and vulnerabilities.

An open-source static analysis tool for scanning IaC to find misconfigurations before they're deployed.

View tool details →

Orca Security

The Agentless-First Cloud Security Platform.

An agentless cloud security platform that provides 100% visibility into your cloud environment.

View tool details →

tfsec

Security scanner for your Terraform code.

A static analysis security scanner for Terraform code.

View tool details →

Orca Security

Agentless Cloud Security. Instant-On. 100% Coverage.

A comprehensive, agentless CNAPP that provides full-stack visibility into cloud environments, including IaC security.

View tool details →

Lacework

The data-driven cloud security platform

Automates cloud security and compliance for multicloud environments.

View tool details →

tfsec

A static analysis security scanner for your Terraform code.

An open-source tool that performs static analysis of Terraform code to spot misconfigurations and security issues.

View tool details →

Fugue by Snyk

Cloud security for developers.

A cloud security posture management (CSPM) tool with IaC capabilities.

View tool details →

Trivy

A comprehensive and versatile security scanner.

An open-source scanner for vulnerabilities, misconfigurations, secrets, and SBOM.

View tool details →

Snyk IaC

Developer-first security for your infrastructure as code.

Finds and fixes security issues in Terraform, CloudFormation, Kubernetes, and ARM templates.

View tool details →

Snyk

AI-powered Developer Security Platform

Finds and fixes vulnerabilities in code, open source, containers, and IaC.

View tool details →

KICS

Keeping Infrastructure as Code Secure. An open-source solution for static code analysis of IaC.

An open-source static analysis tool from Checkmarx that finds security vulnerabilities and misconfigurations in IaC.

View tool details →

Open Policy Agent

Policy-based control for cloud native environments.

An open-source, general-purpose policy engine.

View tool details →

Checkov

Policy-as-code for everyone. Scan cloud infrastructure configurations to find misconfigurations before they're deployed.

Scans cloud infrastructure configurations to find misconfigurations before they're deployed.

View tool details →

Prisma Cloud (Checkov)

The most comprehensive Cloud Native Application Protection Platform (CNAPP).

Secures applications from code to cloud, including IaC scanning with the open-source engine Checkov.

View tool details →

Prisma Cloud by Palo Alto Networks

The most complete Cloud-Native Application Protection Platform (CNAPP)

Secures applications from code to cloud across multicloud environments.

View tool details →

SpectralOps

Automated code security.

A developer-first platform for finding and fixing security issues in code.

View tool details →

Prisma Cloud

The Code-to-Cloud™ platform that secures apps from design to runtime.

A comprehensive Cloud Native Application Protection Platform (CNAPP).

View tool details →

Datadog Cloud Security Management

Full-stack security, from development to production.

Integrates security into the Datadog observability platform, providing IaC scanning, CSPM, and threat detection.

View tool details →

Datadog Cloud Security Management

Full-stack security, from development to production.

A cloud security solution from Datadog that includes CSPM, CWP, and IaC scanning.

View tool details →

Terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

A static code analyzer for Infrastructure as Code.

View tool details →

Lacework

The AI-powered Cloud Security Platform.

A data-driven CNAPP that uses machine learning to automate cloud security, from IaC scanning to threat detection.

View tool details →

Snyk IaC

Developer-first security for Infrastructure as Code.

Find and fix security issues in your Terraform, CloudFormation, Kubernetes, and ARM configurations.

View tool details →

KICS

Keeping Infrastructure as Code Secure.

An open-source IaC static analysis tool by Checkmarx.

View tool details →

Tenable Cloud Security (Terrascan)

Identify and address cloud security risks with confidence.

A CNAPP solution that includes IaC scanning, CSPM, and workload protection, utilizing the open-source Terrascan engine.

View tool details →

Sysdig Secure

Cloud security, powered by runtime insights.

A cloud-native security platform that provides threat detection, compliance, and vulnerability management.

View tool details →

Aqua Security (tfsec, Trivy)

Stop cloud native attacks. From code to cloud and back.

A full-lifecycle CNAPP that secures applications from development to production, featuring IaC scanning via tfsec and Trivy.

View tool details →

TFLint

A Pluggable Terraform Linter.

A static analysis tool focused on linting Terraform code.

View tool details →

Cloudanix

Code to Cloud Security Platform.

A unified platform for code, cloud, identity, and workload security.

View tool details →

Deepfactor

Next-gen application security for cloud native.

A runtime application security platform that includes IaC scanning.

View tool details →

Jit

The M-V-P of DevSecOps.

A DevSecOps platform that simplifies and automates security.

View tool details →

Styra Declarative Authorization Service (DAS)

The unified authorization platform, powered by OPA.

An enterprise management plane for Open Policy Agent (OPA) to operationalize authorization and policy.

View tool details →

Lightspin by Cisco

Contextual Cloud Security.

A CNAPP that prioritizes risks using attack path analysis.

View tool details →

Runecast

Automated Proactive Audits.

Proactive security and compliance analysis for hybrid clouds.

View tool details →

Open Policy Agent (OPA)

Policy-based control for cloud native environments.

Open-source, general-purpose policy engine.

View tool details →

Trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more.

A versatile security scanner that finds vulnerabilities, misconfigurations, secrets, and SBOMs in a variety of targets.

View tool details →

oak9

Security as Code for Cloud-Native Applications.

An IaC security platform that helps developers build secure and compliant cloud native applications.

View tool details →

Prowler

Cloud security assessments, audits, incident response, continuous monitoring, hardening and forensics readiness.

An open-source security tool for AWS, Azure, and GCP that performs security assessments, audits, and hardening.

View tool details →

Trivy

The All-in-One Security Scanner.

Versatile open-source scanner for vulnerabilities, misconfigurations, and more.

View tool details →

oak9

Security as Code. Built by developers, for developers.

An Infrastructure as Code security platform that is designed for developers.

View tool details →

tfsec

Security scanner for your Terraform code.

Open-source static analysis for Terraform.

View tool details →

Checkov

Prevent cloud misconfigurations during build time.

An open-source static analysis tool for infrastructure as code.

View tool details →

env0

The complete platform for managing Infrastructure as Code.

An IaC automation platform that helps you manage and govern your cloud environments.

View tool details →

Spacelift

The most flexible and compliant CI/CD for Infrastructure as Code.

A CI/CD platform that helps you manage and automate your IaC deployments with policy as code.

View tool details →

GitGuardian

The code security platform for the DevOps generation.

A platform that helps you detect and remediate secrets in your code and monitor your software supply chain.

View tool details →

oak9

Security as Code for Cloud Native.

Dynamically secure Infrastructure as Code (IaC) and deployed cloud-native workloads.

View tool details →

Lightspin

The Contextual Cloud Security Platform.

A CNAPP that provides a contextual view of cloud security risks.

View tool details →

SentinelOne Singularity Cloud

Autonomous security for the cloud.

A cloud security platform that provides autonomous threat protection for cloud workloads and environments.

View tool details →

GitHub Advanced Security

Find and fix vulnerabilities with ease.

A suite of security features for GitHub that helps you find and fix vulnerabilities in your code.

View tool details →

Trivy

The most popular open source security scanner.

A simple and comprehensive vulnerability scanner for containers and other artifacts, including IaC.

View tool details →

Wiz

Secure everything you build and run in the cloud.

A CNAPP platform that provides full-stack visibility and context to find, fix, and prevent risks in the cloud.

View tool details →

Checkov

Policy-as-code for everyone.

Open-source static analysis for IaC.

View tool details →

Orca Security

Agentless Cloud Security and Compliance for AWS, Azure, and GCP.

A CNAPP that provides comprehensive visibility and security for your cloud estate without agents.

View tool details →

CrowdStrike Falcon Cloud Security

Unified, code to cloud security.

A CNAPP that extends CrowdStrike's leading endpoint security to protect the entire cloud estate.

View tool details →

SpectralOps

Automated code security for developers.

A developer-first security platform that scans code, configuration, and other assets for security issues.

View tool details →

Fugue

Cloud Security and Compliance.

A cloud security posture management (CSPM) tool with a focus on IaC security and compliance.

View tool details →

Lacework

The data-driven cloud security platform.

A CNAPP that provides automated threat detection, configuration compliance, and workload protection.

View tool details →

Pulumi

Create, deploy, and manage infrastructure on any cloud using your favorite languages.

An IaC platform that allows you to use general-purpose programming languages to provision and manage cloud infrastructure.

View tool details →

Datadog Cloud Security Management

Unified security and observability.

Integrates security into the Datadog observability platform, providing posture management and threat detection.

View tool details →

KICS by Checkmarx

Keeping Infrastructure as Code Secure.

Open-source IaC security scanning tool.

View tool details →

Datadog Cloud Security Management

Unified security and observability.

Detects threats and misconfigurations across the full cloud stack.

View tool details →

HashiCorp Sentinel

Policy as Code for Security, Compliance, and Operational Governance.

An embedded policy-as-code framework integrated with the HashiCorp Enterprise products.

View tool details →

Pulumi CrossGuard

Policy as Code for the Cloud.

A policy as code solution for the Pulumi platform.

View tool details →

Snyk IaC

Developer-first IaC security. Find and fix misconfigurations in Terraform, CloudFormation, Kubernetes, and more.

Scans IaC files for misconfigurations and security vulnerabilities, integrating into developer workflows.

View tool details →

Bridgecrew by Prisma Cloud

Developer-first cloud security.

A developer-first cloud security platform with a focus on IaC.

View tool details →

Accurics by Tenable

Policy as Code for the Full Cloud Native Stack.

Provides security and governance from code to cloud.

View tool details →

Snyk Infrastructure as Code

Developer-first security for your infrastructure as code.

Find and fix security issues in your Terraform, CloudFormation, Kubernetes, and ARM configurations.

View tool details →

tfsec

Security scanner for your Terraform code.

A static analysis security scanner for Terraform code.

View tool details →

Lacework

The data-driven cloud security platform.

A CNAPP that provides automated threat detection, compliance, and workload protection.

View tool details →

Fugue

Cloud security posture management for the entire cloud development lifecycle.

A CNAPP that provides end-to-end security for cloud environments, from IaC to runtime.

View tool details →

SonarCloud

Clean code. Delivered.

A cloud-based code quality and security service.

View tool details →

Snyk IaC

Developer-first infrastructure as code security.

Find and fix security issues in your IaC files.

View tool details →

Veracode

The application security platform.

A comprehensive application security platform that helps organizations secure their software.

View tool details →

GitLab Ultimate

The DevSecOps Platform.

A complete DevOps platform that includes integrated security capabilities, including IaC scanning.

View tool details →

Rapid7 InsightCloudSec

Unified Cloud Native Security.

Comprehensive cloud security posture management (CSPM) and workload protection (CWPP).

View tool details →

Aqua Security

The Cloud Native Security Platform.

Secures applications from code to cloud and back.

View tool details →

Rapid7 InsightCloudSec

Unified cloud security and compliance.

A cloud-native security platform for unified visibility and control.

View tool details →

Terrascan

Detect compliance and security violations across Infrastructure as Code.

Open-source static code analyzer for IaC.

View tool details →

Sysdig Secure

Secure your cloud from source to run.

A CNAPP built on runtime insights from Falco.

View tool details →

Zscaler Posture Control

The Zero Trust Exchange.

Provides unified CNAPP to secure cloud applications.

View tool details →

Pulumi Policy as Code

Define and enforce policies on your cloud infrastructure.

An integrated policy as code solution for the Pulumi IaC platform.

View tool details →

CloudSploit by Aqua

Cloud Security Auditing and Monitoring.

Open-source and commercial tool for cloud security posture monitoring.

View tool details →

Zscaler Posture Control

Unified CNAPP to secure your cloud.

A cloud-native application protection platform (CNAPP) for unified cloud security.

View tool details →

Aqua Security

The Cloud Native Security Platform.

A comprehensive security platform for cloud-native applications, from development to production.

View tool details →

Sysdig Secure

Secure your cloud from source to run.

A CNAPP built on a foundation of deep runtime visibility, powered by Falco.

View tool details →

Checkov

Policy-as-code for everyone.

An open-source static analysis tool for scanning infrastructure as code (IaC) files for misconfigurations.

View tool details →

Prisma Cloud by Palo Alto Networks

The most complete Cloud-Native Application Protection Platform (CNAPP).

A comprehensive cloud security platform that includes IaC scanning and compliance.

View tool details →

HashiCorp Sentinel

Policy as Code for Infrastructure.

A policy as code framework for HashiCorp products.

View tool details →

Prisma Cloud (by Palo Alto Networks)

The most complete Cloud-Native Application Protection Platform (CNAPP).

A comprehensive cloud security platform that includes IaC scanning.

View tool details →

Tenable Cloud Security (incorporating Terrascan)

See everything. Predict what matters. Act to address risk.

Provides unified visibility and security for the entire cloud attack surface.

View tool details →

Tenable.cs

Secure your cloud infrastructure from build to runtime.

A cloud-native application protection platform (CNAPP) from Tenable.

View tool details →

KICS

Keeping Infrastructure as Code Secure.

An open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in IaC.

View tool details →

Aqua Security

Stop cloud native attacks.

A CNAPP focused on securing the entire lifecycle of container-based and cloud-native applications.

View tool details →

Tenable.cs

Secure the entire cloud-native stack.

A cloud-native security platform with IaC scanning.

View tool details →

Terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

An open-source static code analyzer for Infrastructure as Code.

View tool details →

KICS

Keeping Infrastructure as Code Secure

An open-source static analysis tool for Infrastructure as Code.

View tool details →

Qualys Cloud Platform

The all-in-one platform for IT, security and compliance.

A comprehensive security and compliance platform with IaC scanning.

View tool details →

Tenable Cloud Security

Secure your cloud from code to cloud.

A cloud security platform that provides visibility and control over cloud environments, including IaC security.

View tool details →

Checkmarx One

The enterprise application security platform.

A comprehensive application security platform that includes IaC scanning with KICS.

View tool details →

Bridgecrew

The #1 developer-first cloud security platform.

Automate cloud security from code to cloud.

View tool details →

Checkmarx KICS

Keeping Infrastructure as Code Secure.

Open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.

View tool details →

KICS by Checkmarx

Keeping Infrastructure as Code Secure

An open-source solution for static analysis of IaC.

View tool details →

Bridgecrew

Automated cloud security for DevOps.

A developer-first platform for cloud security, focusing on infrastructure as code.

View tool details →

Regula

Checks infrastructure as code for security and compliance.

An open-source tool that evaluates Terraform and CloudFormation for misconfigurations using Rego.

View tool details →

CloudQuery

The open source cloud asset inventory powered by SQL.

An open-source tool that extracts, transforms, and loads cloud configuration into a database for analysis.

View tool details →

Open Policy Agent (OPA)

Policy-based control for cloud native environments.

A versatile policy engine that can be used to enforce policies in various systems, including IaC.

View tool details →

Mondoo

Security and Compliance as Code.

Policy-as-code platform for security and compliance.

View tool details →

Regula

A tool that evaluates infrastructure as code for security and compliance.

An open-source policy engine for checking IaC against security and compliance rules.

View tool details →

Cloud Custodian

Rules engine for cloud security, cost optimization, and governance.

An open-source rules engine for managing public cloud accounts.

View tool details →

Horusec

An open source tool that orchestrates other security tools.

Orchestration tool for SAST, SCA, and IaC scanning.

View tool details →

Checkmarx KICS

Keeping Infrastructure as Code Secure.

An open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.

View tool details →

Turbot Pipes

Query everything. Code your controls. Automate your operations.

An open-source tool for querying and managing your cloud environment.

View tool details →

Driftctl

Detect, track and alert on infrastructure drift.

Open-source tool to manage IaC drift.

View tool details →

Terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning.

An open-source static code analyzer for IaC that helps you detect security and compliance issues.

View tool details →

tfsec

Security scanner for your Terraform code.

An open-source static analysis tool for Terraform that checks for security misconfigurations.

View tool details →

Accurics

Policy as Code for the Modern Infrastructure.

A cloud security platform that enables cyber resilience through policy as code.

View tool details →

Regula

Checks infrastructure as code for security and compliance.

An open-source tool that evaluates IaC against policies.

View tool details →

Open Policy Agent (OPA)

Policy-based control for cloud native environments.

An open-source, general-purpose policy engine.

View tool details →

Prowler

The most comprehensive, free tool for AWS security.

An open-source tool for AWS security assessment, auditing, hardening, and incident response.

View tool details →