IaC security
Infrastructure-as-code (IaC) review evaluates infrastructure and CI configuration included in an authorized source snapshot.
Inputs
Add the project source and select the approved assessment coverage in Workbench. Terraform, container, Kubernetes, Helm, CI, and other configuration files are only evaluated when they are included in the source you authorize.
IaC review is not a live cloud-account inventory and does not prove that a remote deployment currently has the same configuration as the source file.
What a reviewer gets
Configuration findings remain associated with the project and source context that produced them. Use that context to decide whether the configuration is active, where ownership lies, and what change is appropriate.
Evidence and decision boundary
Treat a configuration result as a reviewable source signal. Confirm the deployed environment, policy exceptions, inheritance, and compensating controls before assigning production impact.
Availability
IaC is included from the Professional package. See Plans for the current package matrix and SAST languages for source-file classification context.
Need a workflow that is not documented here? Email contact@eresussec.com.