Product · IaC

Misconfigs caughtbefore they ship.

Our rule packs run on every push. AI triage drops the noise, the autofix lands in your PR.

Capabilities05

Five checks that run on every push.

Terraform, CloudFormation, Kubernetes, Pulumi, Ansible, CDKTF. With AI triage on top.

AI-Generated Autofix

Open S3, public RDS, missing encryption, IAM over-privilege. Each finding ships with a Cybe AutoFix patch tailored to the framework, ready to merge in your PR. No copy-paste from a ticket to a Terraform file.

Comprehensive Framework Support

Terraform (HCL and JSON), CloudFormation, AWS CDK, Pulumi (TypeScript, Python, Go, .NET), CDKTF, Kubernetes manifests, Helm charts, Kustomize, Ansible playbooks. One engine, every shape, no separate tool to install per stack.

Built-in compliance frames

CIS Benchmarks (AWS, Azure, GCP, Kubernetes), NIST 800-53 and 800-171, AWS Well-Architected. All wired in, no rule writing required.

AI triage on every finding

Cybe Analysis re-scores raw scanner output, drops obvious noise, contextualises by blast radius (public exposure, IAM scope) and groups recurring patterns. The verified queue stays short.

Where the verdict lands

Findings appear in the unified dashboard, alongside SAST, SCA, Secrets, CI/CD and Container. Routed to Jira, GitHub Issues, GitLab Issues and Slack. CI gates on GitHub Actions and GitLab CI, REST API and CLI for any other system.

Why choose CybeDefend

Cloud security without the alert pile.

Three reasons platform teams pick it over a Checkov plus Tfsec stack.

Multi-framework, one engine

Terraform, Kubernetes, Helm, CloudFormation, Pulumi, Ansible and CDKTF read by the same scanners. No separate tool, no per-stack rule pack to maintain.

AI triage out of the box

Cybe Analysis sits between the raw scanner output and your dashboard. It contextualises every finding (blast radius, IAM scope, public exposure) and drops obvious noise so the queue you read is the queue that matters.

Findings live where you work

Routed to Jira, GitHub Issues, GitLab Issues and Slack. The unified dashboard stays the source of truth across SAST, SCA, secrets, IaC, CI/CD and containers.

Where IaC scanning runs

Connect the repo, the rest is automatic.

Connect GitHub or GitLab, scans launch on our pods on every push (or on demand). Verdicts flow back through the dashboard, the MCP server and CI gates on GitHub Actions and GitLab CI.

Browse all integrations
FAQ

Frequently asked about CybeDefend IaC.

Which IaC frameworks and clouds do you cover?

Terraform (HCL and JSON), CloudFormation, AWS CDK, Pulumi (TypeScript, Python, Go, .NET), CDKTF, Kubernetes manifests, Helm charts, Kustomize, Ansible playbooks. Cloud-aware rule packs for AWS, GCP, Azure, DigitalOcean, Hetzner, Scaleway and OVH.

How is the scan triggered?

Connect GitHub or GitLab once. From there, every push triggers a scan in our pods, and you can also run on-demand scans from the dashboard or the CLI. Findings flow into the unified dashboard alongside SAST, SCA, Secrets, CI/CD and Container findings.

What does the autofix look like?

Cybe AutoFix proposes a patch tailored to the framework: a Terraform diff for an S3 misconfig, a Kubernetes manifest patch for a missing securityContext, an Ansible variable change for an open port. Each patch lands as a Cybe AutoFix PR ready to review and merge.

Live · just shipped

Install VibeDefend in 5 seconds.

One command wires every coding agent on your machine to CybeDefend: your business rules, your compliance frameworks, and guards that block destructive calls before they fire.

Install in 5 secondsNode 18.17+
npx -y @cybedefend/vibedefend@latest install
Auto-detects
  • Claude CodeClaude Code
  • CursorCursor
  • OpenAI CodexOpenAI Codex
  • WindsurfWindsurf
  • GitHub CopilotVS Code Copilot
Read the README on npm