Infrastructure as Code (IaC)
Secure your Infrastructure as Code with Prowler. Detect misconfigurations, vulnerabilities or secrets in code, and shift security left across Terraform and CloudFormation.
Protect Your Infrastructure from Code to Cloud
Prevent misconfigurations and security issues before they reach runtime. Prowler’s IaC scanning helps you catch risks early, so your infrastructure is secure from the first commit.
Multiple IaC Frameworks
Prowler supports a wide range of IaC types:Terraform, CloudFormation, ARM, Kubernetes manifests (YAML), Dockerfiles, Helm charts, Bicep, Ansible, and more.
Ideal for Shift-Left Workflows
Run IaC scans in CI/CD early in the development lifecycle. Catch violations before merge or deploy, reduce feedback loops, and prevent security debts from piling up.
Zero Runtime Impact, Complete Visibility
Because IaC scanning analyzes code statically, there’s no agent, runtime overhead, or performance hit. You get full insight without touching your running systems.



