Every feature, in one place
Regulatory compliance
13 frameworks evaluated live: GDPR, HIPAA, SOC 2, ISO 27001, DORA, NIS2, and more.
13 frameworks are evaluated live against your actual Terraform plans — violations come from parsing real plan and state resources against each framework's controls, not from a static checklist.
- General frameworks: SOC 2, HIPAA, PCI-DSS, GDPR, ISO 27001, DORA, NIS2, SecNumCloud
- CIS Benchmarks: AWS, Azure, GCP
- Regional privacy laws: PDPA Singapore/Malaysia/Thailand, PDP Indonesia, Decree 53 (Vietnam)
How it works
Each framework is a set of machine-readable controls evaluated against your actual Terraform plan and state resources — not a static questionnaire. A violation means a specific resource attribute failed a specific control, traceable back to the plan that produced it.
A framework with zero violations doesn't mean an untested pass — it means every control in that framework's ruleset was evaluated against your current plan and state, and none matched a violation pattern.