DevSecOps Automation
Compass continuously audits your AWS environment for security misconfigurations, maps each finding to the right code owner, scores automation risk, and ships remediation PRs — so your team spends time on decisions, not discovery.
| Finding | Severity | Auto-fix Risk | Status |
|---|---|---|---|
|
Public S3 bucket with write access Resource: prod-data-archive · Owner: Platform |
Critical | Medium | Queued for remediation PR |
|
Terraform drift: missing lifecycle policy Resource: cost-bucket · Owner: FinOps |
High | Low | PR #91 — ready for review |
|
Stale IAM users without MFA Resource: analytics-users · Owner: Security |
Medium | Low | Awaiting owner approval |
|
Security group allowing 0.0.0.0/0 on port 22 Resource: dev-bastion-sg · Owner: Platform |
High | Low | PR #92 — ready for review |
Sample data from Compass demo environment. Try the live demo →
Compass keeps every security finding tied to proof, ownership, and automation readiness — so you can decide what to automate and what needs human judgment.
Cloud and repo diffs, code owners, compliance mapping, and reproduction steps — everything needed to understand and fix a finding.
Auto-fix risk scoring tells you whether a finding is safe to remediate via PR or needs manual review before any code changes.
One click pushes a finding into the remediation queue. Compass generates the PR; your team reviews and merges. Guardrails stay attached.
Related Product
Beyond scanning for misconfigurations, Compass can deploy canary assets that detect active attackers the moment they move — with zero false positives. Fully managed via Terraform PRs.
Compass dashboard with prioritized findings, severity scoring, and CSV/JSON export
Code owner routing — findings go to the right Terraform module and GitHub team
AI-generated remediation PRs with risk scoring and rollback confidence
Policy recommendations mapped to your compliance controls (SOC 2, CIS, NIST)
Continuous re-scan as your infrastructure evolves — not a one-time report
Integration with your existing GitHub workflow — PRs look like any other infra change