Overview
Turn IaC Scans Into Audit Evidence - Automatically
Every regulated company using Terraform, CloudFormation, or CDK faces the same problem: free scanners flag misconfigurations, but auditors need control-level evidence - not raw check output. Mapping findings like CKV_AWS_17 to SOC 2 CC6.1, HIPAA 164.312(a)(2)(iv), FedRAMP SC-28, and CMMC SC.L2-3.13.16 by hand takes 20-40 hours per audit cycle. **ComplyRim IaC Compliance Validator does it in 90 seconds.
Four Frameworks. One Scan. Launch Day.
- SOC 2 (AICPA TSC 2017): 12 Trust Service Criteria mapped to infrastructure controls. Your auditor receives a PDF citing CC6.1, CC7.2, and A1.2 directly from your Terraform.
- HIPAA Security Rule (45 CFR Part 164): 8 sections including encryption, audit controls, and transmission security. Every finding cites the exact HIPAA section plus remediation steps.
- FedRAMP Moderate (NIST SP 800-53 Rev 5): 18 controls including AC-3, AU-2, SC-28, SC-12, IA-5, and CM-6. Supports ATO preparation and continuous monitoring evidence requirements.
- CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2): 27 practices across AC, AU, CM, IA, RA, SC, and SI domains. Built for C3PAO assessments. CUI never leaves your account.
What Your Auditor Actually Receives
- Per-framework compliance scores** with percentage of controls passing and trend over time
- Control-level findings showing which control failed, which resource, and the exact IaC file and line number
- Remediation code blocks for Terraform and CloudFormation - copy-paste fixes for every finding
- Executive summary page designed for non-technical stakeholders such as CISOs and board reporting
- JSON export for import into Drata, Vanta, ServiceNow GRC, or any evidence management platform
Your Data Stays in Your Account
The AMI runs entirely within your VPC. No IaC files, no scan results, and no CUI leave your AWS account. This is a hard requirement for FedRAMP continuous monitoring and CMMC assessment environments.
Who Uses ComplyRim IaC Compliance Validator
- FinTech and HealthTech teams generating pre-audit SOC 2 Type II and HIPAA infrastructure evidence without 40 hours of manual control mapping
- DoD contractors and federal agencies producing CMMC Level 2 C3PAO assessment IaC evidence packages and FedRAMP ATO infrastructure evidence
- B2B SaaS companies where SOC 2 Type II is a contract condition required by enterprise customers
- Government contractors preparing for the CMMC Final Rule requiring 80,000 contractors to achieve Level 2 with IaC evidence as a C3PAO requirement
- MSPs delivering per-customer compliance evidence without per-customer licensing overhead
Quick Start
- Launch the AMI (m5.large recommended) in your VPC. Configure the security group to allow inbound port 8443 from your CI/CD environment.
- Retrieve your API key from the instance dashboard.
- Submit a scan via REST API specifying SOC2, HIPAA, FedRAMP, or CMMC frameworks.
- Download your auditor-ready PDF evidence report.
Instance Sizing: m5.large (2 vCPU, 8 GB) supports up to 10 concurrent scans for projects up to 500 files. m5.xlarge (4 vCPU, 16 GB) handles up to 25 concurrent scans for large monorepos.
Need a free trial? Request a offer at aws@complyrim.com
Highlights
- Scan Terraform, CloudFormation, and CDK against SOC 2, HIPAA, FedRAMP Moderate, and CMMC Level 2 simultaneously. Unlike free scanners that output raw findings, ComplyRim maps every result to exact control IDs such as SOC 2 CC6.1, HIPAA 164.312(a)(2)(iv), FedRAMP SC-28, and CMMC SC.L2-3.13.16.
- Integrates directly into your CI/CD pipeline in minutes. Supported platforms include GitHub Actions, GitLab CI, Jenkins, AWS CodePipeline, and Terraform Cloud run tasks. Every finding includes Terraform and CloudFormation remediation code so developers fix issues before deployment. Export results as JSON for import into Drata, Vanta, ServiceNow GRC, or any evidence management platform. An executive summary page is included for CISO and board-level reporting.
- Runs entirely within your VPC as an AMI. No IaC files, scan results, or CUI ever leave your AWS account. This architecture meets the hard data-residency requirements for FedRAMP continuous monitoring and CMMC C3PAO assessments. Ideal for DoD contractors, federal agencies, FinTech, HealthTech, and B2B SaaS companies facing SOC 2 Type II contract requirements.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/month |
|---|---|---|
Basic | 50 scans/mo, SOC 2 + HIPAA, 3 users, 30-day audit log | $800.00 |
Standard | 250 scans/mo, all 4 frameworks, 10 users, 90-day audit log | $1,500.00 |
Professional | Unlimited scans and users, all 4 frameworks, 1-year audit log | $3,000.00 |
Vendor refund policy
Refund and cancellation requests are handled under the AWS Marketplace refund policy for contract subscriptions. Contact support@complyrim.com within 30 days of purchase and we will work with AWS Marketplace to process eligible requests.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
1.3.0: adds a User guide link to the app header and sign-in page, pointing at the published ComplyRim user guide. Includes everything in 1.2.0: Marketplace contract licence check so each buyer's purchased tier (Basic, Standard or Professional) is applied.
Additional details
Usage instructions
- Launch the AMI in a private subnet of your VPC using the CloudFormation or Terraform launch template from the product documentation (IMDSv2 is required; the appliance has no SSH and no public IP by default).
- Connect with AWS Systems Manager Session Manager to read the one-time setup address, then open https://<instance-private-ip>/ from inside your VPC and complete the setup wizard: create the admin user, set up MFA and review the licence tier.
- Create an API key in the dashboard and submit a scan through the REST API or the ComplyRim GitHub Action.
- Download the auditor-ready PDF, CSV or JSON evidence package with its signed manifest. The appliance runs entirely inside your VPC; no IaC files or scan results leave your account.
Support
Vendor support
Getting Started
Launch the ComplyRim IaC Compliance Validator AMI (m5.large recommended) in your VPC. Open inbound port 8443 from your CI/CD environment, retrieve your API key from the instance dashboard, and submit your first scan via the REST API or a supported CI/CD integration.
General support: support@complyrim.com Compliance-specific questions: aws@complyrim.com
Instance Sizing
- m5.large (2 vCPU / 8 GB): Up to 10 concurrent scans, projects up to 500 files
- m5.xlarge (4 vCPU / 16 GB): Up to 25 concurrent scans, suitable for large monorepos
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.