Infrastructure Compliance,
fully visualized.
WAFPass is the open-source compliance platform for modern infrastructure. Parse Terraform and AWS CDK, evaluate 83+ WAF++ controls across 8 pillars, explore results in the browser and generate auditor-ready reports — all in one integrated stack. No cloud credentials required.
Three layers. One compliance workflow.
WAFPass is more than a CLI — it is a three-layer stack for engineering teams that need continuous compliance without sacrificing speed.
Core evaluation engine. Parses Terraform and AWS CDK. Runs in CI/CD pipelines. No cloud credentials needed.
FastAPI persistence layer. Stores runs, waivers, risk acceptances, secret findings and audit events. PostgreSQL with automatic migrations.
React web dashboard. 22+ pages of compliance exploration, auditor-ready evidence export and RBAC role management.
Take the controls with you.
Download the full WAF++ controls catalog as YAML, or grab a Checkov-compatible policy bundle generated directly from the same source files.
The Checkov bundle is generated on demand from the same 83+ control definitions and includes one policy per automated check assertion.
Every view points to the next step.
WAFPass renders compliance data so the next action is obvious — whether you're a CISO looking for overview or an engineer fixing a FAIL.
Color-coded region tiles show instantly where the infrastructure stands. Red means active findings — one click leads to the failing controls, the owning project and the responsible engineer.
Track deployment distribution, sovereignty boundaries and cross-region compliance deltas without switching between cloud consoles or spreadsheets.
Each WAFPass evaluation creates a fully documented run — timestamps, changed controls, pillar pass rates and the team member who triggered it.
Compare runs side-by-side to spot regressions instantly. Every run links to the full passport of the evaluated project so nothing goes unnoticed.
WAFPass scans every IaC file for hardcoded API keys, tokens, passwords and certificates — before they reach the repository or the cloud.
Every finding includes the exact file path, line number, matched pattern and remediation hint. Suppressions are tracked with a full audit trail.
Every run produces evidence packages mapped directly to certification frameworks. The Evidence Locker organizes them by framework, control and date — always current, always shareable.
Share read-only evidence links with auditors without manual exports. Packages include pass/fail summaries, waiver documentation and time-stamped screenshots.
Every FAIL opens a structured sprint plan. Findings are grouped by pillar and severity, auto-fix suggestions are generated for common patterns and ownership is assigned in seconds.
Track progress as findings are closed. Every fix links back to the originating run, responsible team member and related Jira or RFC ticket.
Built for every role in the team.
From the CISO who needs the executive view to the engineer who needs line-level details — WAFPass has a view for every stakeholder.
Controls overview
Browse and filter every WAF++ control by pillar, severity and framework mapping. See at a glance which controls cover which compliance requirements.
Module breakdown
Pass rate per Terraform module. See which modules cause the most failures and prioritize remediation by real impact.
API key management
Issue, rotate and revoke API keys per project. Restrict keys to read or read-write access. Every key action is logged with issuing user and timestamp.
SSO & identity
SAML 2.0 and OIDC integration out of the box. Map identity-provider groups to WAFPass roles automatically — no manual user provisioning required.
Project & user mapping
Assign engineers to projects with fine-grained permissions. Visibility is scoped to what each role actually needs — no unnecessary exposure of sensitive compliance data.
Run check overview
Break down individual control results for every run. Filter by PASS, FAIL, SKIP or WAIVED. Sort by pillar, severity or blast radius and export for reporting.
Four lenses. One compliance standard.
WAFPass evaluates your infrastructure through four complementary lenses — making compliance decisions traceable, repeatable and auditable.
Tagging strategies, resource configuration and account guardrails — evaluated automatically on every run.
Policy enforcement as code — strategic decisions stay consistent across time and teams.
Network topology, data residency and sovereignty — provider-neutral WAF++ controls for any cloud.
IAM least-privilege, encryption-at-rest and hardening controls — results are PASS, FAIL, SKIP or WAIVED.
More than pass and fail.
WAFPass augments control checks with deep compliance intelligence — making risk prioritization concrete and actionable.
Parse plan output and evaluate security, compliance and blast-radius impact of pending changes — before terraform apply.
Visualize attack chains that lead to failing controls. Severity badges and direct remediation links make risk prioritization concrete.
Each control carries a blast-radius score that quantifies potential outage impact. Prioritize remediation by actual risk exposure.
Controls that change status between runs without an explicit code change become immediately visible — caught before production drift happens.
The ESG module estimates the CO₂ impact of every cloud workload decision. Captured per control and integrated automatically into PDF compliance reports.
Skip controls deliberately with written justification. Risk acceptances include approver, RFC/Jira link, expiry date — fully traceable.
How the components connect.
Each component is independently deployable. Use the CLI alone for CI/CD pipelines, then add server and dashboard when you need persistent history and visual exploration.
Ready to validate your infrastructure?
Download the WAF++ controls, run WAFPass against your Terraform or CDK code, and get a full compliance report in minutes.