Complimetric
PlatformSolutionsPricingBlog
ComplimetricComplimetric

Infrastructure-as-Code governance for teams that treat compliance as a scene to direct, not a checkbox to ship.

All systems operational

Product

  • Platform
  • Compliance
  • Solutions
  • Pricing
  • Changelog

Company

  • About
  • Blog
  • Getting Started
  • Security

Legal

  • Legal Notice
  • Privacy
  • Cookies
  • Terms
  • Terms of Sale
  • Open Source
  • DPA
Complimetric

© 2026 0x0800 SRL. Directed in production.

01 / Technical architecture

The machine
behind the scene.

Complimetric pairs a high-performance HCL parser with a YAML-native rules engine. One engine reads your Terraform, Kubernetes, and CloudFormation; another renders verdicts mapped to SOC 2, ISO 27001, and NIST 800-53.

Connect GitHubView pricing
Macro still of the Complimetric parser engine, lit clinically with directional amber light.
Reel 01 — Engine● Rolling
02 / 04HCL Parser

Reads your Terraform
the way it was written.

Built on hashicorp/hcl/v2, the parser walks every module, resolves every variable, and follows every remote source. No regex shortcuts. No proxy formats. The same AST your provider sees, examined for policy.

  • Terraform 1.0+ — module graph, count, for_each, dynamic blocks.
  • Cross-provider awareness: AWS, Azure, GCP, OVHCloud, Kubernetes.
  • Variable interpolation, locals, outputs all resolved before evaluation.
  • Workspace and state file ingestion for actual-vs-declared deltas.
2 000+Resource types parsed
< 8 sMedian scan time
main.tfHCL
1
2
3
4
5
6
7
8
9
10

CRITICALSOC 2 / CC6.1

Wildcard Action: "*" on Resource: "*" — least privilege violated. Line 6.

03 / 04Rules Engine
rules/soc2_cc6.1.yamlYAML
1
2
3
4
5
6
7
8
9
10
11
12

Rule fileYAML — auditable

Two thousand rules,
readable by any auditor.

Every rule is a YAML file. Security engineers contribute without touching Go. Auditors trace a finding to a rule to a control without leaving the platform. Custom rules land per-org, evaluated synchronously inside the same engine.

  • Built-in coverage: SOC 2, ISO 27001, NIST 800-53, HIPAA, PCI-DSS, GDPR, CIS.
  • Per-org custom rules — runtime loaded, no redeploy.
  • Findings include exact file, exact line, exact remediation diff.
  • Rules versioned in git, with change history and rollback.
70 %Audit overhead cut
317 %Average ROI
04 / 04Integrations

Five doorways
into the same scene.

Plug Complimetric where your engineers already work. Webhooks for GitHub, a CLI for local terminals, an Actions runner for PR gates, SSO for the enterprise, and an MCP server for autonomous AI agents.

01 — Primary doorway

GitHub

Connect & scan in one click. Webhook-backed, single-click install, every PR gated before merge.

Connect
02

CLI

Run scans from any shell

03

GitHub Actions

Block non-compliant PRs

04

Okta / SSO

SAML, OIDC, SCIM

05

MCP Server

Compliance for AI agents

Cue the audit

Ready when the
camera rolls.

Connect GitHubTalk to sales