Sign in with GitHub.
OAuth in two clicks. We request read scope for the repositories you choose — never your full account.
Estimated time — 30 seconds.
Connect a repository, run a scan, see your compliance score. Four short takes — no demo call required.
OAuth in two clicks. We request read scope for the repositories you choose — never your full account.
Estimated time — 30 seconds.
Choose any repo with Terraform, OpenTofu, Kubernetes, or Helm sources. We auto-detect the language and frameworks.
Free tier — one repository, forever.
The engine parses your IaC, maps cloud resources, and evaluates over two thousand built-in rules. Findings stream into the console as soon as they land.
Median scan time — under 8 seconds.
Every finding ships with a remediation snippet — copy-pasteable, validated against the same rules engine that flagged the issue.
Re-scan to confirm — same engine, same line.
No fluff, no marketing wash — direct answers about scanning, storage, and access.
Complimetric is an Infrastructure-as-Code compliance platform that scans your Terraform configurations for security vulnerabilities, generates compliance reports (SOC2, ISO27001, GDPR, PCI-DSS), and detects drift between your code and actual cloud infrastructure.
We use GitHub OAuth to authenticate you and access your repositories. We only request read access to your code for scanning purposes. Your code is never stored permanently — we only analyze it during scans and discard it immediately after.
We currently support AWS, Azure, and GCP for Terraform scanning. For drift detection, AWS and Azure are fully supported, with GCP coming soon.
Cloud credentials for drift detection are encrypted using AES-256 encryption at rest. They are only decrypted in memory during scan execution and are never logged or exposed. You can revoke credentials at any time from your settings.
We currently map findings to SOC 2, ISO 27001, GDPR, and PCI-DSS frameworks. Each scan result shows which compliance controls are affected, making audit preparation much easier.
Yes. We offer GitHub webhooks that automatically trigger scans on push or pull request. You can also use our API directly for custom integrations. CLI tool is coming soon for local scanning.
The Community plan includes 1 repository, 5 scans per month, and 1 compliance report. It's perfect for individual developers or small projects. Upgrade to Starter or Professional for more capacity.
Complimetric supports the Model Context Protocol (MCP), letting AI assistants scan your infrastructure, check compliance, and generate reports directly from your IDE. Go to Settings > MCP / API Keys, create an API key, then add it to your AI tool's MCP configuration. For Claude Desktop, add the server URL and your API key to claude_desktop_config.json. Full setup instructions are provided when you create a key.
You can cancel anytime from Settings > Billing > Manage Subscription. Your access continues until the end of your current billing period. We don't offer prorated refunds, but you keep full access until your plan expires.
Create a free account and scan your first repository in under two minutes. No credit card, no demo call.