Infrastructure Policy
Compare 40 infrastructure policy tools to find the right one for your needs
🔧 Tools
Compare and find the best infrastructure policy for your needs
Steampipe
An open-source tool that instantly queries cloud APIs using SQL, without needing to ETL data into a database.
oak9
An IaC security platform that helps developers build secure and compliant cloud native applications.
Checkov
An open-source static analysis tool for scanning Infrastructure as Code for misconfigurations and security vulnerabilities.
Trivy
Finds vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more.
Styra DAS
A management plane for Open Policy Agent (OPA) that provides centralized policy authoring, distribution, and monitoring.
Styra Declarative Authorization Service (DAS)
An enterprise management plane for Open Policy Agent (OPA) to operationalize authorization and policy.
Prowler
An open-source security tool for AWS, Azure, and GCP that performs security assessments, audits, and hardening.
GitGuardian
A platform that helps you detect and remediate secrets in your code and monitor your software supply chain.
Spacelift
A specialized CI/CD platform for Infrastructure as Code that provides automation, collaboration, and policy enforcement.
env0
An automation platform for managing Terraform, Terragrunt, and other IaC workflows with governance and cost control.
Wiz
A CNAPP that provides full stack visibility, risk prioritization, and security for cloud environments.
Firefly
A platform for managing cloud assets, discovering resources, and codifying infrastructure to manage drift and ensure governance.
Orca Security
An agentless CNAPP that provides comprehensive visibility and security for cloud environments without the need for per-asset agents.
SpectralOps
A developer-first security platform that scans code, configuration, and other assets for security issues.
CrowdStrike Falcon Cloud Security
A CNAPP that extends CrowdStrike's leading endpoint security to protect the entire cloud estate.
Pulumi
An IaC platform that allows you to use general-purpose programming languages to provision and manage cloud infrastructure.
Pulumi CrossGuard
Define and enforce policies on your cloud infrastructure using familiar programming languages.
HashiCorp Sentinel
An embedded policy-as-code framework that integrates with the HashiCorp Enterprise platform.
Lacework
A CNAPP that uses data and machine learning to provide automated threat detection, configuration compliance, and vulnerability management.
Datadog Cloud Security Management
A security and compliance solution that provides threat detection, posture management, and IaC scanning within the Datadog platform.
Snyk IaC
Developer-first IaC security tool that finds and fixes misconfigurations in Terraform, CloudFormation, Kubernetes, and more.
Snyk Infrastructure as Code
Find and fix security issues in your Terraform, CloudFormation, Kubernetes, and ARM configurations.
Fugue
A CNAPP that provides end-to-end security for cloud environments, from IaC to runtime.
Prisma Cloud (by Palo Alto Networks)
Secures applications from code to cloud across multicloud environments.
Sysdig Secure
A CNAPP built on a foundation of deep runtime visibility, powered by Falco.
Aqua Security Platform
The industry's most integrated Cloud Native Application Protection Platform (CNAPP).
Prisma Cloud
A unified security platform that protects applications from code to cloud, including IaC scanning, CSPM, and CWPP.
Sysdig
A cloud security platform that provides deep visibility for securing and monitoring containers, Kubernetes, and cloud services.
Pulumi Policy as Code
An integrated policy as code solution for the Pulumi IaC platform.
KICS
An open-source static analysis tool that scans IaC for security vulnerabilities, compliance issues, and misconfigurations.
Aqua Security
A comprehensive CNAPP that secures the entire lifecycle of cloud native applications, including IaC scanning and runtime protection.
Tenable.cs
A cloud-native application protection platform (CNAPP) from Tenable.
Terrascan
An open-source static code analyzer for IaC that helps developers build secure infrastructure from the start.
CloudQuery
An open-source tool that extracts, transforms, and loads cloud asset configuration into SQL databases for analysis.
Regula
An open-source tool that checks Terraform, CloudFormation, and Kubernetes configurations for security and compliance issues using Rego.
Checkmarx KICS
An open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.
Cloud Custodian
A YAML-based DSL to define policies for managing cloud resources.
Kyverno
A policy engine designed for Kubernetes.
Open Policy Agent (OPA)
An open source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform code.