Software Security
All Prowler code goes through the same security pipeline, whether running on Prowler Cloud or self-managed infrastructure: DAST, SAST, SCA, container scanning, and secrets detection on every build.Software Security
Security tools and practices applied to all Prowler code.
Prowler Cloud vs Prowler OSS (Self-Managed)
Self-Managed includes Prowler Local Server and Prowler CLI. They can run anywhere — any cloud provider, any region, on-premises, or air-gapped environments. Full control over data residency and infrastructure decisions. See the Prowler Local Server Installation Guide to get started.
Prowler Cloud
This section covers security and compliance for Prowler Cloud, the managed infrastructure.Trust & Compliance
Prowler Cloud holds compliance certifications and undergoes regular audits.
Compliance data and reports: trust.prowler.com
Security
Encryption
Data encrypted at rest (AES-256) and in transit (TLS 1.2+).
Data Regions
EU-hosted infrastructure with high availability and disaster recovery.
Networking
Static egress IPs for firewall allowlisting.

