AWS · Terraform · deterministic engine
Check the infrastructure your agents write. In one line.
No CI step, no source upload, no model in the loop. Point your coding agent at the MCP server and read the verdict on your next pull request.
$
claude mcp add --transport http audytx https://audytx.com/mcp \
--header "X-Client-ID: YOUR_CLIENT_ID"
Get a free Client ID · or install the GitHub App · free during beta
Works with
AWS + Terraform
CloudFormation
GitHub
GitLab
Cursor
Windsurf
Claude
Codex
VS Code
Antigravity
36×
fewer false positives than Checkov, on 21 clean modules
100%
recall on 31 documented IAM privilege-escalation paths
<1s
deterministic verdict · 266 checks, 24 reasoning axes
One engine · three stages
Checked everywhere your Terraform is created and shipped.
agent session · claude code · modules/iam.tf
› agent wrote 23 resources — checking with audytx before opening a PR…
toolaudytx.scan_terraform
✗ 2 critical · 1 high · 3 reasoned away
toolaudytx.autofix_terraform
✓ applied 3 sound fixes · re-scanned to verify
clean — verified before a pull request ever exists
The agent that wrote the Terraform gets the finding — and the fix.
audytx · review agent change · 23 resources
deterministic
CRIT iam_role.app_adminFLAGGED
CRIT sg.web · 0.0.0.0/0FLAGGED
HIGH db.main · unencryptedFIX READY
reasoned about 3 findings — suppressed
· lambda.api — DLQ not needed (sync-invoked)
· sqs.jobs_dlq — is itself a dead-letter queue
· dynamodb.sessions — PITR skipped: TTL set
2 flagged1 fix ready3 reasoned awaySARIF → Code Scanning
One comment on the pull request — inline fixes, and it reads past the diff.
terraform plan · signed upload (OIDC) · 41 resources resolved
CRIT iam_policy.deploy — variable resolves to action: *:*only visible at plan-time
HIGH kms.key — rotation disabled in resolved planFIX READY
no shared secret · OIDC-authenticatedHCP run task ✓
Checks the resolved plan — catching what only the plan reveals.
In a market full of "AI-powered"
The one security tool that never calls a model.
Deterministic, hand-written Rust. Your Terraform is scanned and discarded in the same request — never stored, never sent to an LLM. Every finding audits back to its exact check.
Read the trust page →What we can prove
✓No LLM anywhere in the loop
✓Source discarded in-request — never stored
✓Identical input → identical findings
✓SARIF → GitHub Code Scanning
✓Every verdict cites its exact check
Stateless MCP·OIDC plan upload·never touches your cloud
Teams mute noisy scanners in a week
The scanner your team won't turn off.
audytx reasons across your resources before it flags anything — real risks stay loud, benign ones go quiet, each with the reason shown.
CRITiam_role.app_admin — privilege escalation
CRITsg.web — open to 0.0.0.0/0
lambda.api — DLQ not needed (sync-invoked)muted ▁
sqs.jobs_dlq — is itself a dead-letter queuemuted ▁
dynamodb.sessions — TTL set ⇒ ephemeralmuted ▁
Start free during the open beta.
Install on one repo, point your agent at the MCP server, and see what it catches on the first push. Free for every team — and the free tier stays free.