# Cloud Custodian vs ZeroThreat.ai

| Attribute | Cloud Custodian | ZeroThreat.ai |
|---|---|---|
| **Vioscale score** | 52.9 (41% (low)) | 51.8 (54% (medium)) |
| activity.commits_last_30d | 45 | - |
| adoption.dependent_repos | 80 | - |
| adoption.github_stars | 6,053 | - |
| deployment.options | `{"cloud":true,"self_hosted":true}` | `{"cloud":true}` |
| description.long | Cloud Custodian enables management of cloud resources through filtering, tagging, and policy-driven actions using a YAML DSL. It supports real-time compliance enforcement and cost optimization across AWS, Azure, GCP, and other cloud platforms. | ZeroThreat.ai is an AI-powered automated penetration testing platform that uncovers real, exploitable vulnerabilities across modern web applications and APIs with proof-based validation and real-time CVE coverage. It uses Agentic AI to execute adaptive attacker workflows, combining deep vulnerability coverage, authenticated testing, business logic testing, and community-driven attack templates to help teams prioritize real risk and eliminate false positives. |
| features.capabilities | `{"ciem":false,"cspm":true,"cwpp":false,"dspm":false,"kspm":true,"iac_scanning":true,"cloud_coverage":"AWS, Azure, GCP (primary); Kubernetes, Tencent Cloud, OpenStack (beta)","open_core_scanner":true,"agentless_scanning":true,"runtime_protection":false}` | `{"ciem":false,"cspm":false,"cwpp":false,"dspm":false,"kspm":false,"iac_scanning":false,"cloud_coverage":"Web application and API security scanning, shadow/zombie API discovery, cloud mi","agentless_scanning":true,"runtime_protection":false,"compliance_frameworks":"OWASP, CWE, SANS, PCI DSS, HIPAA, ISO 27001, GDPR"}` |
| integrations.count | 1 | 15 |
| integrations.list | `[{"name":"Terraform"}]` | `[{"name":"GitHub Actions"},{"name":"GitHub"},{"name":"Azure Pipelines"},{"name":"CircleCI"},{"name":"GitLab CI/CD"},{"name":"GitLab"},{"name":"TeamCity"},{"name":"AWS CodePipeline"},{"name":"Bamboo"},{"name":"Jenkins"},{"name":"Travis CI"},{"name":"Jira"},{"name":"Slack"},{"name":"Burp"},{"name":"Nuclei"}]` |
| language.primary | Python | - |
| license.spdx | Apache-2.0 | - |
| market.availability | - | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true}` | `{"web":true}` |
| pricing | `{"type":"open_source","summary":"Open source and free under Apache 2.0 license","sourceUrl":"https://cloudcustodian.io/","retrievedAt":"2026-08-13T16:47:00.704Z"}` | `{"type":"hybrid","plans":[{"free":true,"name":"Free","summary":"Free with 1 scan credit/month","features":["1 scan credit per month","1 target per account","Limited vulnerability insights preview","Web applications & APIs","OWASP top 10 & CWE-based detection","Authenticated scanning","No setup required"],"components":[{"kind":"fixed","amount":0,"period":"month","currency":"USD"}],"description":"Limited vulnerability preview across one application target","contactSales":false,"includedLimits":{"targets":"1","scan_credits":"1/month"}},{"free":false,"name":"Professional","summary":"$100/target/month (or $80/target/month with annual commitment, 20% discount). Additional targets $75 each.","features":["Unlimited scans per target","Scheduled automated scans","AI remediation guidance & executive summaries","Sensitive data & cloud misconfiguration detection","130K+ vulnerability coverage","CVE Intelligence updated monthly","Authenticated scanning with MFA/SSO support","Business logic testing (BOLA, IDOR, access control)","API pentesting (REST, GraphQL, SOAP, gRPC)","Region-based data storage & access control","Compliance continuous coverage (GDPR, ISO27001, PCI-DSS, HIPAA)","Audit-ready compliance reports","Unlimited retesting & verification","Target URL changes within 30-day cooling period","99.9% accurate results"],"commitment":"monthly","components":[{"kind":"fixed","amount":100,"period":"month","currency":"USD"}],"description":"Unlimited scans per application target with full vulnerability visibility and compliance reporting","contactSales":false,"includedLimits":{"per_target":"unlimited scans","additional_targets":"$75 each"}},{"free":false,"name":"Pay Per Scan","summary":"$25/scan credit. Volume discounts: 5% off (10–20 credits), 10% off (30–50), 15% off (75–100), 20% off (250+)","features":["Unlimited targets","AI remediation & executive summaries","Sensitive data & cloud misconfiguration detection","7-day unlimited retest window","CVE-based attack coverage","Authenticated scanning","Business logic security testing (BOLA, IDOR, access control)","API pentesting (REST, GraphQL, SOAP, gRPC)","Region-based data storage & access control","Compliance view (GDPR, ISO27001, PCI-DSS, HIPAA)","Audit-ready compliance reports","99.9% accurate results"],"components":[{"kind":"fixed","unit":"scan credit","amount":25,"period":"one_time","currency":"USD"}],"description":"On-demand security testing across unlimited application targets with flexible credit purchasing","contactSales":false,"includedLimits":{"targets":"unlimited"}}],"summary":"Free tier with 1 scan credit/month. Professional from $100/target/month. Pay-as-you-go at $25/scan credit with volume discounts to 20%.","currency":"USD","freeTier":true,"sourceUrl":"https://zerothreat.ai/pricing","retrievedAt":"2026-08-18T13:35:56.966Z","startingPrice":{"amount":100,"period":"month","currency":"USD"},"billingPeriods":["month","year"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | open_source | freemium |
| pricing.price_level | free | high |
| pricing.starting_price | - | `{"amount":100,"currency":"USD"}` |
| pricing.transparent | yes | yes |
| release.cadence_days | 54 | - |
| release.history | `[{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.51.0","date":"2026-05-28T19:52:40Z","type":"stable","version":"0.9.51.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.50.0","date":"2026-03-18T17:16:59Z","type":"stable","version":"0.9.50.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.49.0","date":"2026-01-16T21:21:11Z","type":"stable","version":"0.9.49.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.48.0","date":"2025-12-01T19:04:50Z","type":"stable","version":"0.9.48.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.47.0","date":"2025-09-22T18:14:42Z","type":"stable","version":"0.9.47.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.46.0","date":"2025-07-17T18:42:30Z","type":"stable","version":"0.9.46.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.45.0","date":"2025-06-02T20:24:02Z","type":"stable","version":"0.9.45.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.44.0","date":"2025-04-24T14:12:18Z","type":"stable","version":"0.9.44.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.43.0","date":"2025-02-04T15:27:59Z","type":"stable","version":"0.9.43.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.42.0","date":"2024-11-14T20:21:44Z","type":"stable","version":"0.9.42.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.41.0","date":"2024-09-18T19:08:29Z","type":"stable","version":"0.9.41.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.40.0","date":"2024-07-23T20:06:17Z","type":"stable","version":"0.9.40.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.39.0","date":"2024-07-23T13:55:45Z","type":"stable","version":"0.9.39.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.38.0","date":"2024-06-18T11:56:41Z","type":"stable","version":"0.9.38.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.37.0","date":"2024-06-05T14:04:13Z","type":"stable","version":"0.9.37.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.36.0","date":"2024-04-29T13:09:49Z","type":"stable","version":"0.9.36.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.35.0","date":"2024-03-05T21:30:15Z","type":"stable","version":"0.9.35.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.34.0","date":"2024-01-18T18:30:11Z","type":"stable","version":"0.9.34.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.33.0","date":"2023-11-29T17:07:21Z","type":"stable","version":"0.9.33.0"},{"url":"https://github.com/cloud-custodian/cloud-custodian/releases/tag/0.9.32.0","date":"2023-10-03T15:46:00Z","type":"stable","version":"0.9.32.0"}]` | - |
| reliability.status_page | yes | - |
| security.gdpr | - | yes |
| security.hipaa | - | yes |
| security.iso27001 | - | yes |
| security.pci | - | yes |
| security.scorecard | 8.7 | - |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=c7n&per_page=100","last_12m":0,"max_severity":null}` | - |

## Capabilities (Cloud Security Software)

| Capability | Cloud Custodian | ZeroThreat.ai |
|---|:--:|:--:|
| **Posture** |  |  |
| CSPM (posture / misconfig) | ✓ | ✗ |
| KSPM (Kubernetes posture) | ✓ | ✗ |
| **Workload** |  |  |
| CWPP (workload protection) | ✗ | ✗ |
| **Entitlements** |  |  |
| CIEM (entitlements) | ✗ | ✗ |
| **Data** |  |  |
| DSPM (data posture) | ✗ | ✗ |
| **Pipeline** |  |  |
| IaC / pipeline scanning | ✓ | ✗ |
| **Architecture** |  |  |
| Agentless scanning | ✓ | ✓ |
| **Runtime** |  |  |
| Runtime protection | ✗ | ✗ |
| **Coverage** |  |  |
| Cloud coverage | AWS, Azure, GCP (primary); Kubernetes, Tencent Cloud, OpenStack (beta) | Web application and API security scanning, shadow/zombie API discovery, cloud mi |
| **Compliance** |  |  |
| Compliance frameworks assessed | - | OWASP, CWE, SANS, PCI DSS, HIPAA, ISO 27001, GDPR |
| **Licensing** |  |  |
| Open-core scanner available | ✓ | - |

*Source: Vioscale. Generated 2026-09-01T17:14:20.128Z. "-" = undocumented, not absent.*
