v1.1.0 · Stable · Open Source

Infrastructure Compliance,
fully visualized.

WAFPass is the open-source compliance platform for modern infrastructure. Parse Terraform and AWS CDK, evaluate 83+ WAF++ controls across 8 pillars, explore results in the browser and generate auditor-ready reports — all in one integrated stack. No cloud credentials required.

GDPR SOC 2 HIPAA BSI C5 ISO 27001 NIS2 PCI DSS ISO 27017 CSA STAR CIS Controls DORA EUCS NIST 800-53 COBIT + more
WAFPass Global Operations Center — multi-region compliance overview
v1.1.0
CLI release
8
Pillars covered
83+
Controls mapped
22+
Dashboard views
The platform

Three layers. One compliance workflow.

WAFPass is more than a CLI — it is a three-layer stack for engineering teams that need continuous compliance without sacrificing speed.

wafpass CLI

Core evaluation engine. Parses Terraform and AWS CDK. Runs in CI/CD pipelines. No cloud credentials needed.

Python PyPI: wafpass-core Apache 2.0
wafpass-server

FastAPI persistence layer. Stores runs, waivers, risk acceptances, secret findings and audit events. PostgreSQL with automatic migrations.

FastAPI PostgreSQL Alembic
wafpass-dashboard

React web dashboard. 22+ pages of compliance exploration, auditor-ready evidence export and RBAC role management.

React Vite Docker
Controls library

Take the controls with you.

Download the full WAF++ controls catalog as YAML, or grab a Checkov-compatible policy bundle generated directly from the same source files.

The Checkov bundle is generated on demand from the same 83+ control definitions and includes one policy per automated check assertion.

More engine bundles: TFLint soon to be in Terrascan soon to be in Open Policy Agent soon to be in
Features in action

Every view points to the next step.

WAFPass renders compliance data so the next action is obvious — whether you're a CISO looking for overview or an engineer fixing a FAIL.

Global Operations Center
One view across all regions.

Color-coded region tiles show instantly where the infrastructure stands. Red means active findings — one click leads to the failing controls, the owning project and the responsible engineer.

Track deployment distribution, sovereignty boundaries and cross-region compliance deltas without switching between cloud consoles or spreadsheets.

Multi-region Real-time status Sovereignty boundaries
Global Operations Center — light mode Global Operations Center — dark mode
Run Dashboard
Every compliance run, tracked in real time.

Each WAFPass evaluation creates a fully documented run — timestamps, changed controls, pillar pass rates and the team member who triggered it.

Compare runs side-by-side to spot regressions instantly. Every run links to the full passport of the evaluated project so nothing goes unnoticed.

Run history Run comparison Full audit trail
Run Dashboard with compliance run history and pass rates
Secret Scanner
No hardcoded credentials.

WAFPass scans every IaC file for hardcoded API keys, tokens, passwords and certificates — before they reach the repository or the cloud.

Every finding includes the exact file path, line number, matched pattern and remediation hint. Suppressions are tracked with a full audit trail.

Regex patterns File + line Suppressions audited
Secret Scanner interface with credential findings
Evidence Locker
Audit evidence, generated automatically.

Every run produces evidence packages mapped directly to certification frameworks. The Evidence Locker organizes them by framework, control and date — always current, always shareable.

Share read-only evidence links with auditors without manual exports. Packages include pass/fail summaries, waiver documentation and time-stamped screenshots.

Framework-mapped Audit-ready Auto-generated
Evidence Locker with framework-mapped compliance packages
Error Sprint Planning
From finding to fix — faster.

Every FAIL opens a structured sprint plan. Findings are grouped by pillar and severity, auto-fix suggestions are generated for common patterns and ownership is assigned in seconds.

Track progress as findings are closed. Every fix links back to the originating run, responsible team member and related Jira or RFC ticket.

Auto-fix suggestions Sprint tracking Full traceability
Error Sprint Planning with prioritized fix suggestions
More features

Built for every role in the team.

From the CISO who needs the executive view to the engineer who needs line-level details — WAFPass has a view for every stakeholder.

Controls overview with filterable WAF++ controls

Controls overview

Browse and filter every WAF++ control by pillar, severity and framework mapping. See at a glance which controls cover which compliance requirements.

Run module breakdown per Terraform module

Module breakdown

Pass rate per Terraform module. See which modules cause the most failures and prioritize remediation by real impact.

API key management interface

API key management

Issue, rotate and revoke API keys per project. Restrict keys to read or read-write access. Every key action is logged with issuing user and timestamp.

SSO settings with identity provider configuration

SSO & identity

SAML 2.0 and OIDC integration out of the box. Map identity-provider groups to WAFPass roles automatically — no manual user provisioning required.

Project user mapping with role assignments

Project & user mapping

Assign engineers to projects with fine-grained permissions. Visibility is scoped to what each role actually needs — no unnecessary exposure of sensitive compliance data.

Run check overview with individual control results

Run check overview

Break down individual control results for every run. Filter by PASS, FAIL, SKIP or WAIVED. Sort by pillar, severity or blast radius and export for reporting.

The PASS model

Four lenses. One compliance standard.

WAFPass evaluates your infrastructure through four complementary lenses — making compliance decisions traceable, repeatable and auditable.

P — Platform
Base controls

Tagging strategies, resource configuration and account guardrails — evaluated automatically on every run.

S — Strategy
Governance as code

Policy enforcement as code — strategic decisions stay consistent across time and teams.

A — Architecture
Network & residency

Network topology, data residency and sovereignty — provider-neutral WAF++ controls for any cloud.

S — Standards
Zero-trust security

IAM least-privilege, encryption-at-rest and hardening controls — results are PASS, FAIL, SKIP or WAIVED.

Intelligence layer

More than pass and fail.

WAFPass augments control checks with deep compliance intelligence — making risk prioritization concrete and actionable.

Terraform plan analysis

Parse plan output and evaluate security, compliance and blast-radius impact of pending changes — before terraform apply.

Exploit path analysis

Visualize attack chains that lead to failing controls. Severity badges and direct remediation links make risk prioritization concrete.

Blast-radius scoring

Each control carries a blast-radius score that quantifies potential outage impact. Prioritize remediation by actual risk exposure.

Drift detection

Controls that change status between runs without an explicit code change become immediately visible — caught before production drift happens.

Carbon footprint & ESG

The ESG module estimates the CO₂ impact of every cloud workload decision. Captured per control and integrated automatically into PDF compliance reports.

Waivers & risk acceptance

Skip controls deliberately with written justification. Risk acceptances include approver, RFC/Jira link, expiry date — fully traceable.

Architecture

How the components connect.

Each component is independently deployable. Use the CLI alone for CI/CD pipelines, then add server and dashboard when you need persistent history and visual exploration.

Your IaC
Terraform / CDK
CLI
wafpass
API
wafpass-server
UI
wafpass-dashboard
2 IaC
Terraform, AWS CDK
8 Pillars
SEC, COST, PERF, REL, OPS, SUS, SOV, AGENTIC
20+ Ops
equals, not, exists, cidr, range and more
Get started

Ready to validate your infrastructure?

Download the WAF++ controls, run WAFPass against your Terraform or CDK code, and get a full compliance report in minutes.

GDPR SOC 2 HIPAA BSI C5 ISO 27001 NIS2