Terraform & IaC Security Scanning
Terraform is how modern cloud infrastructure gets built — which makes it exactly where cloud misconfigurations get born. An open security group, a public storage bucket, or an over-permissive IAM policy in HCL becomes a live exposure on the next apply. ArcScan treats infrastructure-as-code as a first-class security surface across its whole lifecycle: author, apply, and drift.
Catch IaC misconfigurations before apply
ArcScan connects to GitHub, GitLab, and Bitbucket to scan pull requests, so Terraform and IaC changes are reviewed for security issues inside your normal DevOps workflow — before they merge, and long before they reach the cloud. Findings are AI-analyzed and mapped against the same CIS- and NIST-aligned policy checks ArcScan runs against live AWS, Azure, and GCP inventory, which keeps "what the code says" and "what the cloud does" measured by one yardstick. When a fix is warranted, ArcScan can open a remediation PR rather than just filing a finding.
Terraform state becomes a living CMDB
Shift-left is half the story; knowing what your IaC actually created is the other half. CI pipelines can post terraform show -json output to ArcScan's API after every apply. ArcScan ingests the state, upserts the discovered resources as tracked assets correlated by cloud ID, backfills ownership from tags, and can push the result to your ServiceNow CMDB automatically. Your asset inventory stops being a quarterly spreadsheet and starts being a side effect of your deploy pipeline.
Drift detection against known-good baselines
Infrastructure that started life in Terraform rarely stays that way — console edits, break-glass changes, and forgotten experiments accumulate. ArcScan snapshots baselines of your cloud inventory and alerts on deviation, so unmanaged drift between your IaC and your actual environment surfaces instead of silently widening your attack surface.
Generate Terraform from what already exists
Working the other direction, ArcScan can generate Terraform from a live cloud snapshot — including tagging configurations that map resources to the business applications they serve. That gives teams a practical on-ramp to bringing click-ops infrastructure under IaC management with security review built in from the first commit.
Built for regulated DevOps
- Compliance mapping across NIST 800-53, CIS, HIPAA, PCI-DSS, SOC 2, DISA STIG, and more.
- ServiceNow integration for change requests, incidents, and CMDB sync; Jira and FreshService also supported.
- Artificial-intelligence analysis with verified, auditable remediation — every action logged.
- Air-gap and FIPS 140-2 modes for federal and defense cloud environments.