📋 Infrastructure Policy
23 tools compared
🔧 Tools in Infrastructure Policy
Checkov
An open-source static analysis tool for scanning infrastructure as code (IaC) for misconfigurations.
Styra Declarative Authorization Service (DAS)
An enterprise management plane for Open Policy Agent (OPA) to operationalize authorization and policy.
Trivy
A comprehensive, easy-to-use open-source security scanner.
GitGuardian
A platform focused on detecting and remediating secrets in code, with IaC misconfiguration scanning.
Spacelift
A specialized CI/CD platform for IaC that includes integrated policy as code enforcement.
env0
An automation platform for IaC that provides governance, cost management, and policy enforcement.
Wiz
A CNAPP platform that provides full-stack visibility and security risk context, from code to cloud.
Orca Security
An agentless CNAPP that provides comprehensive visibility into cloud risks without per-asset integration.
CrowdStrike Falcon Cloud Security
A CNAPP that extends CrowdStrike's leading endpoint security to protect the entire cloud estate.
Snyk IaC
Scans IaC files for misconfigurations and security vulnerabilities, integrating into developer workflows.
HashiCorp Sentinel
An embedded policy-as-code framework integrated with the HashiCorp Enterprise products.
Lacework
A CNAPP that uses anomaly detection to provide visibility and threat detection across cloud environments.
Datadog Cloud Security Management
Integrates security into the Datadog observability platform, providing posture management and threat detection.
Prisma Cloud (by Palo Alto Networks)
A comprehensive CNAPP that secures applications from code to cloud, including robust IaC security.
Sysdig Secure
A CNAPP built on a foundation of deep runtime visibility, powered by Falco.
Pulumi Policy as Code
An integrated policy as code solution for the Pulumi IaC platform.
Aqua Security
A CNAPP focused on securing the entire lifecycle of container-based and cloud-native applications.
Terrascan
An open-source static code analyzer for IaC that helps detect security issues and enforce policies.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform code.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that enables unified, context-aware policy enforcement.
Checkmarx KICS
An open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.
Regula
An open-source tool that evaluates Terraform and CloudFormation for misconfigurations using Rego.
CloudQuery
An open-source tool that extracts, transforms, and loads cloud configuration into a database for analysis.