Complimetric combines high-performance HCL parsing with a flexible YAML-based rules engine to secure your multi-cloud environment.
Our custom parser engine identifies resources, modules, and variables across your entire Terraform fleet. It supports deep module resolution and variable interpolation to catch risks that simple regex scanners miss.
Rules are defined in human-readable YAML, allowing your security team to contribute without deep coding knowledge. Each rule maps to CIS Benchmarks and SOC2 criteria automatically.
id: Complimetric_SOC2_CC6.1 severity: CRITICAL framework: SOC2 control: CC6.1 resource: aws_iam_policy check: mfa_required: true impact: "Access controls without MFA"
Connect Complimetric to your existing developer workflow.