Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

CloudSploit

Free#30 of 39 in Cloud Security Posture Management Software

CloudSploit: A free, multi-cloud CLI auditor with compliance mappings and optional remediation. Ranked #30 of 39 in Cloud Security Posture Management Software by our editors (5.9/10); pricing: Free plan; best for teams wanting free CLI-based cloud auditing.

5.9/10Editor score
CloudSploit5.9 Visit CloudSploit

At a glance

  • Editor score
    5.9 / 10
  • Pricing
    Free plan
  • Best for
    Teams wanting free CLI-based cloud auditing
  • Free plan
    Yes
  • Paid from
    None
  • Multi-cloud support
    Yes
  • Founded
    2015 · Boston, Massachusetts, United States and Ramat Gan, Israel
  • Facts checked
    21 Sep 2026
CloudSploit screenshot
  • Where it wins

    • Audits AWS, Azure, GCP, OCI, and GitHub
    • Maps findings to HIPAA, PCI, and CIS requirements
    • Supports suppressions, multiple outputs, and remediation actions
  • Where it doesn't

    • Self-hosted CLI workflow requires technical setup
    • No verified IaC, identity-risk, or attack-path analysis
    • Focused on auditing rather than a broader security platform

Our verdict on CloudSploit

CloudSploit is an open-source cloud security posture management and auditing tool from Aqua Security. It scans Amazon Web Services, Microsoft Azure, Google Cloud Platform, Oracle Cloud Infrastructure, and GitHub for misconfigurations and security risks. The self-hosted command-line product is aimed at developers, security teams, and organizations managing cloud accounts that want direct control over scanning and output. Its two-phase process collects cloud metadata before running risk scans, while plugin-specific execution allows teams to target selected checks.

CloudSploit’s strongest fit is multi-cloud auditing with compliance context. It includes mappings for HIPAA, PCI, and CIS Benchmarks, and can produce console, CSV, JSON, and JUnit XML results for different reporting workflows. Finding suppressions help teams manage accepted issues, while non-zero exit codes for failed checks can support automated pipelines. Optional plugin remediation actions add a way to address selected findings from the tool. Docker deployment is available alongside installation with Node.js, giving technical teams two self-hosted deployment paths.

The product is free and open source, but its command-line and self-hosted model places more responsibility on the organization for deployment and operational management. CloudSploit is a good choice for teams that need a focused, multi-cloud auditor with compliance mappings, scriptable output, and optional remediation. It is less suitable for buyers seeking a broader cloud security posture platform with verified infrastructure-as-code analysis, identity-risk analysis, or attack-path analysis. Organizations that prefer a managed commercial experience may instead consider the hosted commercial offering associated with Aqua Security.

CloudSploit pricing

Plans Free planFree Free to use — no paid tier required for the core job.
See plans on github.com

CloudSploit fact sheet

Free planYes
Paid fromNone
Multi-cloud supportYes
Cloud asset inventoryYes
Compliance frameworksHIPAA, PCI DSS, CIS Benchmarks
IaC scanningNot verified
Identity risk analysisNot verified
Attack path analysisNot verified
Automated remediationYes
DeploymentCloud, Self-hosted
SupportDocs, Community
Built forSolo, Small business, Mid-market, Enterprise (editorial estimate)
PricingFree plan
Websitegithub.com
Facts checked21 Sep 2026

Alternatives to CloudSploit

See all CloudSploit alternatives →

Used CloudSploit? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used CloudSploit for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — CloudSploit 5.9/10

CloudSploit is listed in our Cloud Security Posture Management Software directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/cloudsploit/"><img src="https://www.itechguides.com/best/badge/cloudsploit.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.

Last updated · How we research and update