Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

Steampipe

SQL layer over cloud and SaaS APIs—compose compliance and inventory queries across AWS, Azure, GCP, GitHub, Okta, and hundreds of plugins.

Why it is included

Turbot-maintained open core for cloud security posture reporting without writing bespoke SDK glue per provider.

Best for

Security architects and DevSecOps writing scheduled CIS-style checks and asset graphs from live APIs.

Strengths

  • Huge plugin ecosystem
  • SQL ergonomics
  • Turbot commercial path optional

Limitations

  • AGPL-3.0 network copyleft—review if you ship multi-tenant services

Good alternatives

Cloud Custodian · Prowler · ScoutSuite

Related tools