Live demo 
Weekly live demo and office hours, every Wednesday →

Find, prioritize and fix cloud security risks across every
cloud provider.

One control plane where humans and agents collaborate. Connect Claude, Codex, Cursor, Copilot and more, and defend any cloud now.

Trusted by the world's leading teams

How Prowler works

One workflow: connect, scan, prioritize, fix, verify.

The same open-source engine runs in the Prowler CLI and in Prowler Cloud, so what you test locally is what you run in production.

01

Connect

Add a cloud account with a read-only role. No agents to deploy and nothing written back to your environment.

02

Scan

Run more than 2,500 checks, and growing every day, across your accounts and map every result to 70+ compliance frameworks.

03

Prioritize

Findings are ranked by severity, so the risks that matter most surface first.

04

Fix

Follow step-by-step remediation for the console, CLI or IaC, with Lighthouse AI to explain each fix.

05

Verify

Re-scan to confirm the fix held, and track your posture over time and across teams.

Supported providers

Alibaba Cloud
AWS
Azure
Cloudflare
E2E NetworksCLI
Google Cloud
Huawei CloudCLI
LinodeCLI
NHNCLI
OpenStack
Oracle Cloud
ScalewayCLI
StackITCLI
GitHub
Google Workspace
LLMCLI
Microsoft 365
MongoDB Atlas
OktaCLI
Vercel
Infrastructure as Code
Kubernetes
Container images
VMware VCFCLI

Cloud, SaaS, Kubernetes, containers and Infrastructure as Code. Providers marked CLI are available in the Prowler CLI.

Four ways to run Prowler

Pick the edition that fits how you operate.

Every edition runs the same open-source engine. The difference is who operates it and how much it does for you.

Managed SaaS

Prowler Cloud

Hosted and maintained by Prowler
  • Continuous monitoring with auto-scaling scans
  • Continuous compliance
  • Lighthouse AI, Slack and Jira integrations
  • MCP Server for your AI agents
  • 15-day free trial, no cloud account limit
Run your free scan →
Managed, in your environment

Prowler Private Cloud

Deployed in your own environment: cloud, data center or air-gapped
  • Your data residency and control
  • Unlimited resources
  • Private Registry for internal checks and frameworks
Talk to us →
Open source

Prowler CLI

Self-run, locally or in CI/CD. Apache-2.0
  • Scan every supported provider from your terminal
  • Runs in pipelines and air-gapped setups
  • Scan from inside Kubernetes
  • Ship findings to Prowler Cloud for dashboards, Lighthouse AI and integrations
Get it on GitHub →
Open source

Prowler Local Server

Formerly Prowler App. Self-hosted web app and API
  • Run scans and review findings in a web UI
  • REST API, self-hosted, you own the data
  • No SaaS account required
Read the docs →
Built for your security review

Read-only access, control data residency and independent attestation. Private Cloud allows you to choose your data residency.

Read-only

Connectors and Lighthouse AI analyze your cloud. They never modify it.

SOC 2 Type II

Plus the AWS Foundational Technical Review, passed.

We manage the infrastructure

Prowler manages the infrastructure. Private Cloud keeps it in your environment.

AES-256 and TLS 1.2+

Encrypted at rest and in transit, with SAST, DAST and SCA on every build.

Complete code-to-cloud coverage, driven by Agentic AI

Customer Outcomes

Why Thousands of Users Trust Prowler

Unified Cloud Visibility

Get Complete Cloud Visibility

Prowler provides out-of-the-box visibility into multiple clouds – AWS, Microsoft Azure, Google Cloud, Kubernetes, GitHub, Microsoft 365, Infrastructure as Code, Oracle Cloud, Alibaba Cloud, Cloudflare, OpenStack and more from a single, unified interface so you can act before attackers do.

Risk Prioritization

Fix What Matters Most

Prowler automatically prioritizes risks based on severity, context, and impact  helping you address the most critical findings first. With clear, actionable insights, your team can remediate faster and strengthen your security posture efficiently.

Prowler Wins Black Hat Asia Startup Spotlight
Advancing to the Global Startup Spotlight at Black Hat USA
August 4–6, 2026 · Las Vegas · Booth 5913
Open, Customizable Platform

Customize to Your Requirements

Prowler adapts to your environment, not the other way around.  Create and manage custom checks, mute alerts that don’t matter to you, or add users with granular role-based access control (RBAC). With Prowler, you get full flexibility and control over your cloud security posture.

Regulatory Excellence

Automate Compliance, Simplify Audits

Prowler continuously monitors your cloud environment to maintain compliance with industry standards such as CIS, GDPR, NIST, and more including your own custom frameworks. Automated evidence collection ensures you’re always prepared for audits, without the manual effort.

Prowler Love

Don’t take our word for it

Can't thank you enough for this tool. Default go to tool for cloud security, just as nmap was for every netsec folk. All the very best #prowler 

Prowler is a command-line tool for AWS Security Best Practices Assessment, Auditing, Hardening, and Forensics Readiness

Prowler stands out as a top-tier tool in terms of functionality and community engagement. It supports security assessments and compliance across major cloud environments such as AWS, Azure, GCP, and Kubernetes, offering robust features comparable to those of commercial solutions.

 One of the best open-source and cost-effective cloud posture management tools out there. Call it “CSPM” or whatever four-letter acronym you prefer—they do it all.

Prowler contains hundreds of controls covering CIS, PCI-DSS, ISO27001, GDPR, HIPAA, FFIEC, SOC2, AWS FTR, ENS and custom security frameworks.

I was pretty amazed by the tool. I'd definitely recommend this open source tool to audit your AWS account to fix security issues.

Learn how to… set up Prowler to push findings to Security Hub… [a] cool project that automated the entire process.

Prowler is an Open Source Security tool for AWS, Azure and GCP to perform Cloud Security best practices assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness

Prowler makes it super easy to identify vulnerabilities, improve security posture, and stay compliant with cloud best practices. Highly recommend it for anyone working on cloud security!

Security Hub native integration with Prowler is now the recommended solution for sending findings from Prowler.

World's Most Widely Adopted Open Cloud Security Platform

46M+
Downloads
15K+
GitHub Stars
300+
Contributors Worldwide