Cloud Compliance Tools - Page 8

How Many Cloud Compliance Software Products Does G2 Track?

Total Products under this Category: 163

Category Stats (Sep 2026)

  • Average Rating: 4.56/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Flexera One (+1.44%) - Among all products in this category, Flexera One recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Cloud Compliance Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 16,200+ Authentic Reviews
  • 163+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Cloud Compliance Software

G2 Grid® for Cloud Compliance Software plotting products by satisfaction and market presence

Highlighted products: Vanta, Wiz, Sprinto, Drata, Microsoft Defender for Cloud, Scrut Automation, Secureframe, and Scytale.

Underlying data: [Grid® JSON](https://www.g2.com/categories/cloud-compliance/grids.json?focus%5B%5D=vanta&focus%5B%5D=wiz-wiz&focus%5B%5D=sprinto-inc&focus%5B%5D=drata&focus%5B%5D=microsoft-defender-for-cloud&focus%5B%5D=scrut-automation&focus%5B%5D=secureframe&focus%5B%5D=scytale-g2)

Lightrun

Named 2021 Gartner Cool Vendor, Lightrun builds an IDE-native observability & debugging platform that enables developers to securely add logs, metrics and traces to production and staging environments in real time, on demand. No hotfixes, redeployments or restarts required. Developers use Lightrun for multiple code-level observability needs, including: * Code-level alerts (Java, Node.js, Python, .NET) * Feature verification * Testing / debugging in production * Troubleshooting cloud native apps, Serverless, and more * Log optimization capabilities through a Log Optimizer(TM) By eliminating the need to reproduce bugs locally or issue a new software version for adding new logs or metrics to troubleshoot production issues, Lightrun's customers consistently reduce their MTTR by up to 50-60% and significantly improve development productivity. Issues that used to take 1-2 weeks to mitigate now take our customers on average less than an hour to solve. Lightrun empowers our customers' developers by eliminating the need for costly developer lifecycle operations like reproducing locally, or issuing a new software version just for adding new logs or metrics. Our customers, running petabyte-scale workloads with QPS in the high 100Ks across thousands of production servers, include companies that reach 44.5% of the internet's population and major, publicly-traded cybersecurity companies.

Average Rating: 4.8/5.0

Total Reviews: 67

How Do G2 Users Rate Lightrun?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.3/10)
  • Compliance Monitoring: 8.3/10 (Category avg: 9.1/10)
  • Auditing: 10.0/10 (Category avg: 9.0/10)
  • Cloud Gap Analytics: 8.3/10 (Category avg: 8.6/10)

Who Is the Company Behind Lightrun?

  • Seller: Lightrun
  • Year Founded: 2019
  • HQ Location: Tel Aviv, IL
  • Twitter: @Lightruntech
    282 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    90 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 43% Medium, 28% Large

What Do G2 Reviewers Say About Lightrun?

AI-generated summary from verified user reviews

Pros
  • Users value Lightrun for its easy integrations, enhancing real-time debugging and streamlining workflows effortlessly.
  • Users value the IDE integration of Lightrun, enhancing real-time debugging efficiency in production environments.
  • Users find Lightrun's ease of use facilitates intuitive real-time debugging, enhancing their development workflow significantly.
  • Users commend Lightrun for its performance optimization, enabling efficient real-time debugging directly in production environments.
  • Users value the time-saving capabilities of Lightrun, enabling quick troubleshooting and reducing debugging complexity.
Cons
  • Users seek improvements in UI and better documentation for a more effective debugging experience with Lightrun.
  • Users note that the poor UI design hinders functionality, calling for improvements to enhance usability and integration.
  • Users note that the UX could be significantly improved with better UI and user-friendly features for efficiency.
  • Users find the learning curve steep, particularly due to the IDE plugin difficulties and compiler limitations.
  • Users note that the UI needs improvement, suggesting enhancements for a better experience across platforms.

What Are Recent G2 Reviews of Lightrun?

What Are G2 Users Discussing About Lightrun?

Security Controls Optimization by Discern Security

Discern Security is an AI-powered platform integrated security controls assessment and policy management. Acting as a proactive security advisor, it continuously analyzes and optimizes security controls in real-time while fostering cross-platform intelligence by building a cybersecurity mesh. Here's how it works: - Baseline Establishment: Discern seamlessly integrates with major security platforms like EDR, SASE, Email, IAM, etc. and ingests information to establish a baseline for security controls and configurations, identifying existing protection gaps. - Scoring Process: Each security deployment undergoes meticulous scoring, assessing control effectiveness and associated risk factors. - Generative AI Assistance: Leveraging advanced generative AI, Discern addresses critical security queries and provides improvement roadmaps. For instance, it can answer questions like, "Why is my Crowdstrike score only 30%, and how can I improve it to 95%?" - Framework Mapping: Discern dynamically maps security controls to established frameworks (e.g., MITRE, CIS, NIST) for compliance, showcasing security program progress and ROI on investments. - Health Checks: Proactive health checks ensure control currency against recent ransomware threats, utilization of latest vendor features, and comprehensive coverage, facilitating swift deployment of configuration changes. - Metrics and Insights: Discern offers personalized metrics, actionable insights, and configuration recommendations tailored to department and user needs, automating implementation through triggered workflows. - Reporting Dashboards: Visualizing risk in a consumable manner, Discern's reporting dashboards highlight coverage gaps, top risks, and configuration optimization opportunities, enabling cost-saving measures. Already partnering with Fortune 500 corporations and top-tier cybersecurity firms, Discern's real-time cybersecurity health assessments, dynamic risk dashboards, and progress mapping empower CISOs to: - Maximize efficacy of security tools and investments. - Automate policy management and orchestration. - Focus on high-risk entities to reduce incidents. - Showcase real progress using relevant metrics and benchmarks.

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate Security Controls Optimization by Discern Security?

  • Compliance Monitoring: 6.7/10 (Category avg: 9.1/10)
  • Auditing: 10.0/10 (Category avg: 9.0/10)
  • Cloud Gap Analytics: 10.0/10 (Category avg: 8.6/10)

Who Is the Company Behind Security Controls Optimization by Discern Security?

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Security Controls Optimization by Discern Security?

ThreatStryker

ThreatStryker builds on the ThreatMapper open source platform. ThreatStryker extends the vulnerability discovery capabilities, adding runtime attack detection, prediction and protection. Map your applications, know the weak points, prioritise vulnerabilities for remediation. Observe security events (indicators of attack and indicators of compromise) using deep packet inspection and lightweight on-host sensors. Correlate events and vulnerabilities to track the risk posed by attacker behaviour, then intervene with quarantine and firewall actions to stop attackers in their tracks.

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate ThreatStryker?

  • Compliance Monitoring: 6.7/10 (Category avg: 9.1/10)
  • Auditing: 10.0/10 (Category avg: 9.0/10)
  • Cloud Gap Analytics: 8.3/10 (Category avg: 8.6/10)

Who Is the Company Behind ThreatStryker?

  • Seller: Deepfence
  • Year Founded: 2018
  • HQ Location: Palo Alto, US
  • Twitter: @deepfence
    574 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of ThreatStryker?

AWS Governance Intelligence Platform

AWS Governance Intelligence Platform transforms AWS environment evidence into board-ready documentation. It analyzes configuration data to create governance reports for board presentations and leadership reviews, replacing traditional methods using agents and questionnaires. The process begins with a CloudFormation template establishing a read-only role in the AWS environment. The platform assumes this role to examine configurations and generate a board pack documenting infrastructure observations. Existing systems remain unmodified, and access permissions expire on a set date. Using a read-only security architecture with federated access, the platform avoids storing AWS credentials. Explicit Deny policies block access to sensitive data, such as object contents, secrets, and logs. This ensures strict data boundaries while gathering governance evidence. The platform delivers factual, evidence-based assessments from actual infrastructure configurations.

Who Is the Company Behind AWS Governance Intelligence Platform?

Axonius

Axonius is the cybersecurity asset management platform that lets IT and Security teams see devices for what they are in order to manage and secure all.

Average Rating: 4.2/5.0

Total Reviews: 7

How Do G2 Users Rate Axonius?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.3/10)

Who Is the Company Behind Axonius?

  • Seller: Axonius
  • Year Founded: 2017
  • HQ Location: New York, New York, United States
  • Twitter: @AxoniusInc
    1,856 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    764 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 57% Large, 43% Medium

What Do G2 Reviewers Say About Axonius?

AI-generated summary from verified user reviews

Pros
  • Users value the visibility and intelligence of Axonius, effortlessly managing and identifying assets across their environment.
  • Users appreciate the centralized management of Axonius, enhancing visibility and simplifying asset identification across their environment.
  • Users value the enhanced visibility from Axonius, streamlining data management and improving asset identification significantly.
  • Users enjoy the ease of use of Axonius, praising its powerful queries and comprehensive visibility across environments.
  • Users praise the easy management of Axonius, simplifying data visibility and enhancing understanding of their environment.
Cons
  • Users find Axonius to have a steep learning curve, making initial use feel complex and overwhelming.
  • Users find the UI complex, especially for beginners, making it challenging to navigate and understand.
  • Users find the difficult learning curve of Axonius challenging, especially with complex queries and data integrations.
  • Users find Axonius to be expensive, which can be a drawback for budget-conscious organizations.
  • Users find Axonius to have a complex feature set, leading to confusion due to its steep learning curve.

What Are Recent G2 Reviews of Axonius?

What Are G2 Users Discussing About Axonius?

Boundera

Boundera automates FedRAMP 20x compliance from continuous evidence collection to certification package. The platform connects to a provider's cloud accounts and code repositories, collects evidence on an automatic schedule, and persistently validates every Key Security Indicator against the FedRAMP 2026 Consolidated Rules. Every result carries evidence lineage, and every run records score history, so providers can show a trend over time instead of a point-in-time snapshot. Vulnerability Detection and Response (VDR) is built in. Scanner findings and failed KSI assertions become tracked vulnerability records with due dates, dispositions, and remediation clocks aligned to FedRAMP timelines. For technical findings, Boundera's AI agent drafts code and infrastructure fixes as pull requests that engineers review before anything merges. Providers publish current posture through a branded Trust Center and grant assessors controlled access to KSIs, rules, evidence, vulnerabilities, SDR and other packages. Exports validate against the official FedRAMP 2026 JSON schemas. Boundera is available as a SaaS service or as a self-deployed installation that runs entirely within a customer's cloud environment. Boundera uses the same production platform internally to pursue its own FedRAMP 20x Class C certification.

Who Is the Company Behind Boundera?

CimTrak Integrity Suite

Cimcor is the leading provider of System Integrity Assurance with our award-winning CimTrak Integrity Suite that protects a wide range of physical, network, cloud, and virtual IT assets in real time. CimTrak provides detailed analysis, evidence, and automated workflows that enforce an unprecedented security posture, ensures operational availability, stops zero-day attacks, detects unexpected changes, and achieves and maintains continuous compliance in a simple and cost-effective manner.

Average Rating: 4.8/5.0

Total Reviews: 23

How Do G2 Users Rate CimTrak Integrity Suite?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.3/10)
  • Compliance Monitoring: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind CimTrak Integrity Suite?

  • Seller: Cimcor
  • Company Website:
  • Year Founded: 1997
  • HQ Location: Merrillville, Indiana, United States
  • Twitter: @cimtrak
    2,203 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    28 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Large, 33% Medium

What Do G2 Reviewers Say About CimTrak Integrity Suite?

AI-generated summary from verified user reviews

Pros
  • Users find the compliance checking feature of CimTrak Integrity Suite to be very useful and easy to navigate.
  • Users appreciate the useful compliance checking feature of CimTrak Integrity Suite, enhancing PCI Compliance management effectively.
  • Users highlight the unbeatable ease of use of CimTrak Integrity Suite, making compliance tasks straightforward and efficient.
  • Users rave about the outstanding customer support from CimTrak, noting the team's knowledge and availability.
  • Users value the real-time monitoring of CimTrak, allowing immediate detection of file modifications and potential threats.
Cons
  • Users find the dashboard issues and outdated report scheduler detract from the overall user experience of CimTrak.
  • Users find the upgrade process cumbersome, wishing for a more integrated solution to simplify updates.
  • Users note compliance issues due to outdated UI and a lack of effective dashboards in the CimTrak Integrity Suite.
  • Users feel a strong need for better guidance during upgrades, preferring an integrated upgrade process for efficiency.
  • Users find the poor customer support of CimTrak Integrity Suite frustrating, impacting their overall experience and effectiveness.

What Are Recent G2 Reviews of CimTrak Integrity Suite?

Cloudforte Platform

Unisys CloudForte® accelerates your digital transformation and maximizes innovation in the cloud without sacrificing security or governance. CloudForte® enables you to accelerate your success with self-service blueprints, automated governance and workflow, automated provisioning, security, reporting and advanced analytics.

Who Is the Company Behind Cloudforte Platform?

  • Seller: Unisys
  • HQ Location: Blue Bell, PA
  • Twitter: @unisys
    33,730 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,300 employees on LinkedIn®
  • Ownership: NYSE:UIS
  • Total Revenue (USD mm): $2,820

Cloud Raxak

Security Compliance for Cloud

Who Is the Company Behind Cloud Raxak?

  • Seller: Cloud Raxak
  • Year Founded: 2014
  • HQ Location: Los Gatos, US
  • Twitter: @cloudraxak
    249 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

CloudSploit

CloudSploit provide a software for security and configuration scanner that can detect threats in AWS account.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate CloudSploit?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.3/10)

Who Is the Company Behind CloudSploit?

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of CloudSploit?

What Are G2 Users Discussing About CloudSploit?

ComplianceCow

The Security GRC Controls Automation Studio for Your Custom Controls & Workflows. Extend your GRC platform. Reach into complex infrastructure for control checks, evidence collection, risk analysis, and remediation. No gaps. No blind spots. Shift left with Continuous Controls Management. Gain real-time assurance with automated compliance monitoring. Less effort. More security. Stop chasing compliance evidence. Avoid brittle scripts and manual audits. Adapt easily to changing frameworks, controls, and infrastructure. Catch and fix issues before audits.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate ComplianceCow?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.3/10)

Who Is the Company Behind ComplianceCow?

Who Uses This Product?

  • Company Size: 100% Large

What Do G2 Reviewers Say About ComplianceCow?

AI-generated summary from verified user reviews

Pros
  • Users commend the responsiveness and flexibility of ComplianceCow's staff and technology in solving complex issues.
  • Users value the customizability of ComplianceCow, appreciating the staff's responsiveness and flexible technology for problem-solving.
  • Users appreciate the responsiveness and eagerness of the staff to solve tough problems effectively.
  • Users value the team's expertise in solving complex issues and providing flexible technology solutions.
  • Users value the team's helpfulness in quickly addressing issues and providing flexible solutions for compliance needs.

What Are Recent G2 Reviews of ComplianceCow?

Compliance Warden

Compliance Warden is built for modern teams that want speed and security together. Every time a developer opens a pull request, our platform scans the code in real time against industry standards like SOC 2, ISO 27001, PCI DSS, and NIST. Developers get inline, AI-powered fixes right in GitHub or VS Code, while compliance officers gain instant visibility through dashboards, scoring, and audit-ready reports. With support for AWS, Azure, Terraform, CloudFormation, Pulumi, and more, Compliance Warden makes compliance continuous, proactive, and developer-friendly.

Who Is the Company Behind Compliance Warden?

Complyrim Readiness Snapshot (CRS)

ComplyRim Readiness Snapshot (CRS) is the fastest path to a defensible AWS compliance readiness report. Where a traditional compliance engagement costs $15,000 to $50,000 and takes 6 to 12 weeks, CRS delivers the same audit-ready output in under 30 minutes for $99 a month. CRS is built for AWS customers from 100 to 1,000 employees who need to prepare for their first SOC 2, ISO 27001, HIPAA, PCI DSS, or ISO 42001 audit — or maintain readiness between annual reviews — without hiring a compliance consultant or buying a $50K-per-year enterprise GRC platform. What it does: CRS performs 200+ automated security checks across the AWS services your auditors care about — IAM, S3, CloudTrail, VPC, EC2, RDS, and KMS. It maps every check to actual auditor classifications across SOC 2 Type II, ISO 27001, HIPAA, PCI DSS v4.0, and ISO 42001 (AI Management). The output is a Compliance Readiness Score, a Gap Analysis showing exactly where you fall short, and a prioritized Remediation Roadmap with step-by-step AWS Console fix instructions for every finding. How it deploys: CRS deploys via a CloudFormation template using a read-only IAM role. Setup is two minutes. There are no agents to install, no software to update, and zero production impact. CRS runs entirely in your AWS region — your data never leaves your AWS environment. What you get: an audit-ready PDF report formatted for the way auditors actually work — not just a marketing dashboard. Step-by-step AWS Console fix instructions are included for every finding so your team can remediate without further consulting fees. Reports re-run on demand and on a schedule. Why it matters: auditors reject spreadsheets. Consultants take three months. Enterprise GRC tools require six-month implementations and annual contracts north of $50,000. CRS is the third option — purpose-built for AWS customers who need the output of a compliance engagement without the time and cost of one. CRS is sold exclusively on AWS Marketplace, billed on your existing AWS invoice with no separate vendor contract or procurement cycle. AWS credits and committed spend apply. Pricing description (500 chars max) CRS Free trial: 14 days, full feature access. Standard subscription: $99/month

Who Is the Company Behind Complyrim Readiness Snapshot (CRS)?

ConformScan

ConformScan is a B2B SaaS compliance scanner for EU regulations. It automatically audits AWS, Azure, and GCP cloud infrastructure against NIS2, GDPR/DSGVO, BSI C5, ANSSI, CIS Benchmarks, and ISO 27001 frameworks. Features include automated findings with severity levels, SLA-based escalation tracking, PDF executive reports, IaC drift detection, and integrations with Jira, Slack, Microsoft Teams, and ServiceNow. Designed for DevOps and security teams in regulated industries across the EU.

Who Is the Company Behind ConformScan?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024