Pre-Beta Pre-beta signups are open now. The full audytx engine is live for pre-beta. Everything free today stays free — paid tiers arrive Sep 01, 2026 from $20/month for unlimited repositories.
AWS · Terraform · deterministic engine

Check the infrastructure your agents write. In one line.

No CI step, no source upload, no model in the loop. Point your coding agent at the MCP server and read the verdict on your next pull request.

$ claude mcp add --transport http audytx https://audytx.com/mcp \ --header "X-Client-ID: YOUR_CLIENT_ID"
Works with AWS + Terraform CloudFormation GitHub GitLab Cursor Windsurf Claude Codex VS Code Antigravity
36×
fewer false positives than Checkov, on 21 clean modules
100%
recall on 31 documented IAM privilege-escalation paths
<1s
deterministic verdict · 266 checks, 24 reasoning axes
One engine · three stages

Checked everywhere your Terraform is created and shipped.

audytx · review agent change · 23 resources deterministic
CRIT iam_role.app_adminFLAGGED
CRIT sg.web · 0.0.0.0/0FLAGGED
HIGH db.main · unencryptedFIX READY
reasoned about 3 findings — suppressed
· lambda.api — DLQ not needed (sync-invoked)
· sqs.jobs_dlq — is itself a dead-letter queue
· dynamodb.sessions — PITR skipped: TTL set
2 flagged1 fix ready3 reasoned awaySARIF → Code Scanning
One comment on the pull request — inline fixes, and it reads past the diff.
In a market full of "AI-powered"

The one security tool that never calls a model.

Deterministic, hand-written Rust. Your Terraform is scanned and discarded in the same request — never stored, never sent to an LLM. Every finding audits back to its exact check.

Read the trust page →
What we can prove
No LLM anywhere in the loop
Source discarded in-request — never stored
Identical input → identical findings
SARIF → GitHub Code Scanning
Every verdict cites its exact check
Stateless MCP·OIDC plan upload·never touches your cloud
Teams mute noisy scanners in a week

The scanner your team won't turn off.

audytx reasons across your resources before it flags anything — real risks stay loud, benign ones go quiet, each with the reason shown.

CRITiam_role.app_admin — privilege escalation▮▮▮▮
CRITsg.web — open to 0.0.0.0/0▮▮▮▮
lambda.api — DLQ not needed (sync-invoked)muted ▁
sqs.jobs_dlq — is itself a dead-letter queuemuted ▁
dynamodb.sessions — TTL set ⇒ ephemeralmuted ▁

Start free during the open beta.

Install on one repo, point your agent at the MCP server, and see what it catches on the first push. Free for every team — and the free tier stays free.