Your Dockerfile runs as root.

ConfigSafe scans Dockerfiles, Kubernetes manifests, Terraform, CI/CD pipelines, and Nginx configs for security misconfigurations. Locally. Before you deploy.

$ clawhub install configsafe click to copy
$ configsafe scan infrastructure/
 
🐳 ConfigSafe: Scanning 18 config files...
 
  !! CRITICAL  Dockerfile:1            Running as root (no USER)
     → Add USER directive: USER nonroot:nonroot
 
  !! CRITICAL  k8s/deploy.yaml:34     privileged: true
     → Remove privileged mode or use securityContext
 
  !  HIGH      terraform/main.tf:12    S3 bucket public access
     → Set block_public_acls = true
 
  Security Score: 41/100 (F)
  14 misconfigs found (4 critical, 6 high, 4 medium)

One misconfigured container. Full cluster compromise.

80% of Kubernetes breaches trace back to misconfigurations. A privileged container, an open port, a missing network policy. ConfigSafe catches them all before deployment.

80%
of K8s breaches from misconfigs
67%
of Dockerfiles run as root
$4.5M
avg cost of a cloud breach

Comprehensive infrastructure scanning

🐳

Docker Scanning

Dockerfiles, docker-compose, multi-stage builds. Catches root users, exposed ports, hardcoded secrets, and insecure base images.

☸️

Kubernetes

Deployments, services, RBAC, network policies, pod security. Validates privilege escalation, resource limits, and namespace isolation.

🏗️

Terraform

AWS, GCP, Azure resource security, state encryption. Detects public buckets, open security groups, and unencrypted volumes.

⚙️

CI/CD Pipelines

GitHub Actions, GitLab CI, Jenkinsfile security. Flags hardcoded tokens, overly permissive permissions, and insecure artifact handling.

🌐

Web Servers

Nginx, Apache security headers, SSL/TLS config. Validates HSTS, CSP, certificate chains, and cipher suite strength.

📋

CIS Benchmarks

Map findings to CIS Docker, K8s, and cloud benchmarks. Generate compliance reports aligned with industry standards.

How ConfigSafe compares

Feature ConfigSafe Checkov ($299/mo) Trivy ($0) Hadolint ($0)
Price Free / $19 / $39 $299/mo Free (complex) Free (Docker only)
Runs Locally
Docker Scanning
Kubernetes
Terraform
CI/CD Pipelines
Nginx / Apache
CIS Benchmarks
Pre-commit Hooks
Zero Config
Setup Time 30 seconds 20+ min 10+ min 5 min

Simple, transparent pricing

Start scanning for free. Upgrade for full infrastructure coverage.

Free
$0
  • Scan up to 5 config files
  • Security score + grade
  • 60+ built-in checks
  • CLI output
Install Free
Team
$39/user/mo
  • Everything in Pro
  • Policy enforcement
  • NIST compliance mapping
  • SARIF output
  • CI/CD integration
Get Team

Get notified about updates

No spam. One email per week max. Unsubscribe anytime.

Your infrastructure has misconfigs right now

Install ConfigSafe in 30 seconds. Find them before attackers do.

$ clawhub install configsafe click to copy