CloudCompliance — SOC2-Ready AWS IaC
Infrastructure as Code that provisions a SOC2-aligned AWS security baseline with 10 controls and 46 resources — deployable in one command. Includes drift detection, AI compliance assistant, score history, auto-remediation and a live dashboard.
The Problem
Startups spend 6–12 months retrofitting SOC2 controls onto infrastructure that was never designed to be compliant. Security is an afterthought — CloudTrail gets enabled after an incident, encryption gets added before an audit, RBAC gets tightened only when required.
This IaC eliminates that retrofit entirely. Every SOC2 control is provisioned automatically at infrastructure creation time.
Scope note: This IaC implements the technical infrastructure controls mapped to SOC2 Common Criteria CC6–CC8 and Availability A1. Full SOC2 Type II certification additionally requires organizational policies, vendor management, employee training, and 6–12 months of evidence collection.
Quick Start
Requirements: Python 3.9+, Terraform, Docker
# 1. Install CLI
pip install cloudcompliance
# 2. Clone the repo
git clone https://github.com/KADHIRAVANEG/cloudcompliance.git
cd cloudcompliance
cp .env.example .env # add your API keys
# 3. Start everything in one command
bash scripts/start.sh
# Or step by step:
docker run --rm -d -p 4566:4566 localstack/localstack:3.4.0
make deploy
cloudcompliance report
cloudcompliance drift
cloudcompliance serve # → http://localhost:8080
CLI Commands
# Deploy SOC2 baseline infrastructure
make deploy
# Generate SOC2 compliance evidence report
cloudcompliance report
# Detect infrastructure drift
cloudcompliance drift
# Auto-remediate drift findings
cloudcompliance remediate
cloudcompliance remediate --dry-run # preview without changes
# View compliance score history (SOC2 Type II evidence)
cloudcompliance history
cloudcompliance history --export # export JSON for auditors
# Ask AI about your compliance state
cloudcompliance ask "am I ready for a SOC2 audit?"
cloudcompliance ask "what is my biggest security risk?"
cloudcompliance ask "explain CC7.2 and how I implement it"
cloudcompliance ask "what controls am I missing?"
# Open live compliance dashboard
cloudcompliance serve # → http://localhost:8080
cloudcompliance serve --port 9090 # custom port
Live Dashboard
cloudcompliance serve
Opens a professional dashboard at http://localhost:8080 showing:
- Real-time compliance score ring
- All 10 SOC2 controls with pass/fail status
- Drift findings with PR links
- Compliance score history chart
- Auto-remediation actions log
- Auto-refreshes every 30 seconds
SOC2 Control Coverage
| Control | Title | Resources Enforced |
|---|---|---|
| CC6.1 | Network Isolation | VPC, private subnets, deny-all security group |
| CC6.2 | Authentication Controls | IAM password policy, MFA alert, least-privilege role |
| CC6.3 | Access Revocation | IAM role policies, access analyzer alarms |
| CC6.6 | Transmission Protection | HTTPS-only S3 bucket policy, TLS enforcement |
| CC6.7 | Encryption at Rest | KMS CMK, S3 server-side encryption |
| CC7.1 | Threat Detection | CloudWatch alarms, AWS Config recorder + rules |
| CC7.2 | Audit Logging | Versioned audit bucket, VPC flow logs, Config delivery |
| CC7.3 | Incident Response | Log metric filters, unauthorized API call detection |
| CC8.1 | Change Management | IaC-controlled infra, Config recorder status |
| A1.1 | Availability | S3 versioning, retention policies, backup role |
10 controls · 46 AWS resources · 100% compliance score
What Gets Provisioned (46 resources across 9 modules)
Networking — CC6.1
- Private VPC (
10.0.0.0/16) with 2 private subnets - No public subnets — zero internet exposure by default
- Default-deny security group
- VPC Flow Logs → CloudWatch (90-day retention)
Logging — CC7.2
- Dedicated audit S3 bucket with versioning
- Delete protection + HTTPS-only policy
- AWS Config delivery channel
Encryption — CC6.7
- KMS Customer Managed Key with automatic rotation
- S3 encrypted data bucket with KMS SSE
- HTTPS-only bucket policy
IAM — CC6.2 + CC6.3
- Password policy: 14 chars, complexity, 90-day rotation
- Least-privilege IAM role — S3 read + KMS decrypt only
- Access analyzer role + findings alarm
- SNS topic for root account alerts
Monitoring — CC7.1
- CloudWatch alarms: root login, public bucket detection
- AWS Config recorder — all resource types
- Config rules: S3 public read prohibited, S3 encryption required, root MFA
Incident Response — CC7.3
- CloudWatch log group for security events (365-day retention)
- Log metric filters: unauthorized API calls, console sign-in failures
- CloudWatch alarms wired to SNS
Availability — A1.1
- Versioned availability logs bucket
- Public access blocked
- Backup IAM role
Config — CC7.1 + CC7.2
- AWS Config recorder + delivery channel
- 3 managed Config rules
Change Management — CC8.1
- All resources IaC-controlled via Terraform
- Config recorder status tracking
- CI/CD gate on every PR
Auto-Remediation
When drift is detected, CloudCompliance closes the loop automatically:
- LOW RISK — patches resources instantly (tags, labels)
- HIGH RISK — opens a GitHub PR with exact fix for human review
- CRITICAL — alerts immediately with remediation steps
$ cloudcompliance drift
🟡 HIGH cloudcompliance-encrypted-data DELETED
$ cloudcompliance remediate
📋 PR opened: https://github.com/KADHIRAVANEG/cloudcompliance/pull/32
Remediation log saved → compliance/remediation_log.json
AI Compliance Assistant
Powered by NVIDIA NIM. Reads your actual tfstate and compliance reports.
export NVIDIA_API_KEY="your-key"
$ cloudcompliance ask "am I ready for a SOC2 audit?"
> Your compliance score is 100% (10/10 controls passing).
> One drift finding detected: encrypted S3 bucket deleted.
> Recommend: run 'cloudcompliance remediate' to open a fix PR.
Compliance Score History
SOC2 Type II requires evidence over time. Every report run is saved automatically.
$ cloudcompliance history
Date Score Controls Trend
2026-07-01 70% 7/10 —
2026-07-07 90% 9/10 ↑ +20%
2026-07-12 100% 10/10 ↑ +10%
$ cloudcompliance history --export
# Exports history_export.json for auditors
Environment Setup
Copy .env.example to .env and fill in your values:
cp .env.example .env
# Required for AI assistant
NVIDIA_API_KEY=your-nvidia-nim-key
# Required for auto-remediation PRs
GITHUB_TOKEN=your-github-token
GITHUB_REPO=KADHIRAVANEG/cloudcompliance
# LocalStack endpoint (leave as-is for local dev)
LOCALSTACK_ENDPOINT=http://localhost:4566
CI/CD Compliance Gate
Every pull request automatically runs:
- Terraform Validate — format + syntax check
- Checkov Security Scan — 500+ security rules
- SOC2 Compliance Check — deploys to LocalStack, runs report, blocks if score < 100%
Project Structure
cloudcompliance/
├── terraform/
│ ├── main.tf
│ ├── variables.tf
│ ├── local.tfvars # LocalStack config
│ ├── prod.tfvars # Real AWS config
│ └── modules/
│ ├── networking/ # CC6.1 — VPC, subnets, flow logs
│ ├── logging/ # CC7.2 — Audit bucket
│ ├── encryption/ # CC6.7 — KMS, encrypted S3
│ ├── iam/ # CC6.2 — Password policy, roles
│ ├── monitoring/ # CC7.1 — CloudWatch alarms
│ ├── config/ # CC7.1 + CC7.2 — Config rules
│ ├── incident_response/ # CC7.3 — Log metric filters
│ ├── access_analyzer/ # CC6.3 — IAM access analyzer
│ └── availability/ # A1.1 — Versioning, backup
├── cloudcompliance/
│ ├── report.py # SOC2 evidence generator + CLI
│ ├── history.py # Score timeline (SQLite)
│ ├── assistant.py # AI compliance assistant (NVIDIA NIM)
│ ├── dashboard.py # Live dashboard (FastAPI)
│ ├── drift/
│ │ └── detector.py # Drift detection engine
│ └── remediation.py # Auto-remediation engine
├── compliance/ # Generated reports
│ ├── compliance_report.json
│ ├── compliance_report.md
│ ├── drift_report.json
│ ├── remediation_log.json
│ ├── history.db
│ └── history_export.json
├── docs/ # Project website (GitHub Pages)
├── scripts/
│ └── start.sh # One-command startup
├── .github/workflows/ # CI/CD gate
├── .env.example # Environment variables template
└── Makefile
Chart
flowchart TD
%% Styling Definitions
classDef infra fill:#2980b9,stroke:#fff,color:#fff;
classDef module fill:#34495e,stroke:#fff,color:#fff;
classDef glue fill:#f39c12,stroke:#000,color:#000;
classDef core fill:#27ae60,stroke:#fff,color:#fff;
%% Orchestration Layer
MK[Makefile]:::glue
CI[.github/workflows/]:::glue
%% Terraform Root
TF_Root[terraform/]:::infra
TF_Root --> Main[main.tf]
TF_Root --> Mod[modules/]:::module
%% Module Layer & SOC2 Mapping
Mod --> N[networking - CC6.1]:::module
Mod --> L[logging - CC7.2]:::module
Mod --> E[encryption - CC6.7]:::module
Mod --> I[iam - CC6.2]:::module
Mod --> M[monitoring - CC7.1]:::module
Mod --> C[config - CC7.1/7.2]:::module
Mod --> IR[incident_response - CC7.3]:::module
Mod --> AA[access_analyzer - CC6.3]:::module
Mod --> AV[availability - A1.1]:::module
%% Core Logic Layer
Core[cloudcompliance/]:::core
Core --> Rep[report.py]
Core --> Hist[history.py]
Core --> Asst[assistant.py]
Core --> Drift[drift/detector.py]
Core --> Rem[remediation.py]
%% Connections
MK -->|deploy| TF_Root
MK -->|audit| Core
CI -->|gate| TF_Root
CI -->|check| Core
Drift -.-> Rem
Core -->|outputs| Comp[compliance/]
Makefile Commands
make start # Start LocalStack + deploy + report + dashboard
make deploy # Deploy all SOC2 controls to LocalStack
make deploy-prod # Deploy to real AWS
make validate # Terraform format + validate
make report # Generate SOC2 evidence report
make drift # Run drift detection
make history # Show score history
make history-export # Export audit evidence JSON
make remediate # Auto-remediate drift findings
make remediate-dry # Preview remediation without changes
make serve # Open live dashboard at :8080
make destroy # Tear down all infrastructure
make all # deploy + report + drift + history
Use as a Terraform Module
module "soc2_baseline" {
source = "KADHIRAVANEG/cloudcompliance/aws"
version = "1.5.0"
project_name = "my-startup"
environment = "prod"
aws_region = "us-east-1"
}
Install Options
# Python CLI (recommended)
pip install cloudcompliance
# Docker
docker pull ghcr.io/kadhiravaneg/cloudcompliance:latest
docker run -v ~/cloudcompliance/terraform:/app/terraform \
ghcr.io/kadhiravaneg/cloudcompliance:latest
# Terraform Registry
source = "KADHIRAVANEG/cloudcompliance/aws"
version = "1.5.0"
LocalStack vs Real AWS
| Feature | LocalStack (free) | Real AWS |
|---|---|---|
| VPC / Subnets | ✅ | ✅ |
| S3 + Encryption | ✅ | ✅ |
| KMS | ✅ | ✅ |
| IAM | ✅ | ✅ |
| CloudWatch | ✅ | ✅ |
| AWS Config | ✅ | ✅ |
| SNS | ✅ | ✅ |
| CloudTrail | ⚠️ Pro only | ✅ |
| GuardDuty | ⚠️ Pro only | ✅ |
Standards Referenced
- AICPA SOC2 Trust Services Criteria 2017
- CIS AWS Foundations Benchmark v2.0
- NIST SP 800-53 Rev 5
- AWS Security Reference Architecture
Tech Stack
Terraform · Python · FastAPI · AWS · LocalStack · GitHub Actions · NVIDIA NIM · SQLite · KMS · IAM · CloudWatch · SNS · AWS Config
Changelog
| Version | What's new |
|---|---|
| v1.5.0 | Live dashboard — cloudcompliance serve |
| v1.4.0 | Auto-remediation — GitHub PR for high-risk drift |
| v1.3.0 | Compliance score history — SOC2 Type II evidence |
| v1.2.0 | Drift detection — cloudcompliance drift |
| v1.1.0 | 10 SOC2 controls, 46 resources, markdown reports |
| v1.0.0 | Initial release — SOC2 baseline IaC |
Author
Kadhiravan E.G. — Cybersecurity student
GitHub: @KADHIRAVANEG
Website: CloudCompliance
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file cloudcompliance-1.6.0.tar.gz.
File metadata
- Download URL: cloudcompliance-1.6.0.tar.gz
- Upload date:
- Size: 31.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/6.2.0 CPython/3.14.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f4d8f735992fa1e18b49f7b8426903de960d48e836de78ab2a73bf8d1801490f
|
|
| MD5 |
9a68a32d852d8a44e17c2e62a99d3f47
|
|
| BLAKE2b-256 |
fc71104330bd927adab7213fe8830f36476f62cf7cb7e04d002c1516c29e281c
|
File details
Details for the file cloudcompliance-1.6.0-py3-none-any.whl.
File metadata
- Download URL: cloudcompliance-1.6.0-py3-none-any.whl
- Upload date:
- Size: 31.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/6.2.0 CPython/3.14.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ccd35b29067d769fcb49406c446fe11c53e3f9f9a4eddcb6e5263d15b926c3f4
|
|
| MD5 |
5fc44a3524e0e4de575ba143148f6bcf
|
|
| BLAKE2b-256 |
7687b1c82bf096c2444743ad096a010bcb7907519b815f639f4570a52e70be6c
|