Cloudeval evaluation surface
Published coverage counts
This is a conservative public lower bound, not a promise that every project runs every check. Cloudeval rounds down because applicability can change when providers, IaC formats, resources, project configuration, and policies change. Cloudeval’s project model, graph, cost context, reports, and evidence treatment add practical value around those checks without being presented as a separate numerical count.
How Cloudeval uses evidence
Third-party catalog snapshot
Snapshot date: July 11, 2026.Workflow counts overlap and must not be added together. A scanner check can apply to more than one workflow or IaC format.
Third-party roles
Count methodology
Licensing and attribution
Cloudeval integrates permissively licensed open-source tools as evidence sources. Cloudeval independently evaluates, normalizes, and presents results. These third-party projects are independent of Cloudeval; no affiliation, certification, sponsorship, or approval is implied.
Cloudeval uses project names as text attribution. It does not use project logos unless separate trademark clearance exists.
Coverage boundaries
- The
1,650+ attributed cloud and IaC checkscount is a pinned-catalog lower bound, not a per-project result count. - Workflow counts overlap and are not additive.
- Not every project runs every check.
- AWS CloudFormation beta support is not an end-to-end AWS Well-Architected assessment.
- Checkov observations appear as additional IaC findings unless Cloudeval has reviewed a different output treatment.
- Third-party projects are independent; no affiliation, certification, sponsorship, or approval is implied.