IaC Security Tools
Compare the best IaC tools and vendors. Expert reviews, pricing, and feature comparisons on Latio.
Act maps attack paths across identities (AI, NHI, and human), applications, network and cloud resources and enables teams to properly scope access and isolate resources.
Turbot's Guardrails allow enforcement of cloud security controls, while Pipes enables querying across your cloud data.
Acquired by Cloudflare. Kivera is not strictly speaking a CSPM, but provides granular controls over what cloud API calls are permissible within your environment. This allows instant enforcement of custom rules and policies, giving the same outcomes as CSPMs without the alert explosion. The downside of using them as a sole CSPM would be missing out on more holistic CNAPP features and visibility, but they run well alongside other providers.
Abbey allows you to define grant kits in code, which are custom pre-defined terraform for different access scenarios. Developers can then request access via Abbey, and open a PR subject to defined approval workflows.
Preventive cloud security enforcement platform that blocks risky cloud configuration changes at deployment time (across IaC, CLI, and ClickOps) before they reach production.
Nirmata is a platform built for enforcing policies in your cloud environnment (but mostly Kubernetes). It functions as an admission controller and policy engine, allowing you to enforce checks for all your Kubernetes changes.
Zest provides contextual IaC fixes for your deployed cloud infrastructure.
Blast provides preventative security controls to protect cloud environments based helping organizations deploy and manage different guardrails like SCP and IaC.
Acquired by Anysphere (Cursor). Resourcely provided Terraform guardrails.