Complimetric
PlatformSolutionsPricingBlog
ComplimetricComplimetric

Infrastructure-as-Code governance for teams that treat compliance as a scene to direct, not a checkbox to ship.

All systems operational

Product

  • Platform
  • Compliance
  • Solutions
  • Pricing
  • Changelog

Company

  • About
  • Blog
  • Getting Started
  • Security

Legal

  • Legal Notice
  • Privacy
  • Cookies
  • Terms
  • Terms of Sale
  • Open Source
  • DPA
Complimetric

© 2026 0x0800 SRL. Directed in production.

01 / Onboarding

Scene 01,
your first scan.

Connect a repository, run a scan, see your compliance score. Four short takes — no demo call required.

Start free
02 / 03Four steps
01
Step 01 — Connect

Sign in with GitHub.

OAuth in two clicks. We request read scope for the repositories you choose — never your full account.


Estimated time — 30 seconds.

02
Step 02 — Select

Pick a repository.

Choose any repo with Terraform, OpenTofu, Kubernetes, or Helm sources. We auto-detect the language and frameworks.


Free tier — one repository, forever.

03
Step 03 — Scan

Run your first scan.

The engine parses your IaC, maps cloud resources, and evaluates over two thousand built-in rules. Findings stream into the console as soon as they land.


Median scan time — under 8 seconds.

04
Step 04 — Remediate

Fix with guided playbooks.

Every finding ships with a remediation snippet — copy-pasteable, validated against the same rules engine that flagged the issue.


Re-scan to confirm — same engine, same line.

03 / 03Open questions
FAQ

Everything you need
to take the stage.

No fluff, no marketing wash — direct answers about scanning, storage, and access.

  • Complimetric is an Infrastructure-as-Code compliance platform that scans your Terraform configurations for security vulnerabilities, generates compliance reports (SOC2, ISO27001, GDPR, PCI-DSS), and detects drift between your code and actual cloud infrastructure.

  • We use GitHub OAuth to authenticate you and access your repositories. We only request read access to your code for scanning purposes. Your code is never stored permanently — we only analyze it during scans and discard it immediately after.

  • We currently support AWS, Azure, and GCP for Terraform scanning. For drift detection, AWS and Azure are fully supported, with GCP coming soon.

  • Cloud credentials for drift detection are encrypted using AES-256 encryption at rest. They are only decrypted in memory during scan execution and are never logged or exposed. You can revoke credentials at any time from your settings.

  • We currently map findings to SOC 2, ISO 27001, GDPR, and PCI-DSS frameworks. Each scan result shows which compliance controls are affected, making audit preparation much easier.

  • Yes. We offer GitHub webhooks that automatically trigger scans on push or pull request. You can also use our API directly for custom integrations. CLI tool is coming soon for local scanning.

  • The Community plan includes 1 repository, 5 scans per month, and 1 compliance report. It's perfect for individual developers or small projects. Upgrade to Starter or Professional for more capacity.

  • Complimetric supports the Model Context Protocol (MCP), letting AI assistants scan your infrastructure, check compliance, and generate reports directly from your IDE. Go to Settings > MCP / API Keys, create an API key, then add it to your AI tool's MCP configuration. For Claude Desktop, add the server URL and your API key to claude_desktop_config.json. Full setup instructions are provided when you create a key.

  • You can cancel anytime from Settings > Billing > Manage Subscription. Your access continues until the end of your current billing period. We don't offer prorated refunds, but you keep full access until your plan expires.

Cue the audit

Roll camera
on your IaC.

Create a free account and scan your first repository in under two minutes. No credit card, no demo call.

Get started free Back to home