Skip to content

KafkaGuard

Compliance for Kafka, Delivered Automatically.

40+ Production-Ready Controls

Comprehensive security, reliability, and operational controls including 15 security controls (SASL, SSL/TLS, ACLs, certificate validation), 12 reliability controls (replication, ISR, fault tolerance), and 13 operational controls (configuration, performance, monitoring).

4 Report Formats

Generate reports in multiple formats: JSON for automation and CI/CD integration, HTML for web-viewable reports with executive summaries, PDF for audit-ready reports with compliance mapping, and CSV for tabular exports and spreadsheet analysis.

Enterprise Security Support

Full support for enterprise authentication and encryption: SASL authentication (PLAIN, SCRAM-SHA-256, SCRAM-SHA-512), SSL/TLS encryption with certificate validation, Mutual TLS (mTLS) for highly secured environments, security protocol auto-detection, and Kerberos (GSSAPI) support for enterprise authentication.

Fast and Lightweight

Optimized for speed and efficiency: scans complete in ~10 seconds for a 3-node cluster, single static binary under 50MB, memory usage under 200MB during scans, with multi-platform support for Linux, macOS, and Docker.

Compliance Ready

Built-in compliance mappings for major standards: PCI-DSS requirements mapping, SOC2 Trust Service Criteria alignment, ISO 27001 controls correlation, with automated remediation guidance to help teams meet regulatory requirements.

CI/CD Native

Designed for automation and integration: native GitHub Actions support, structured JSON output for pipeline integration, exit codes for automated decision-making, and seamless integration with existing DevOps workflows.

Get Started in 5 Minutes

Run your first KafkaGuard scan and see results in under 5 minutes. Perfect for validating cluster configurations and identifying security issues quickly.

View Quick Start Guide

Download

Supported Platforms

Linux
macOS
Docker

Security Matrix

Supported Protocols

PLAINTEXT

Development only (non-secure)

SSL

TLS encryption only

SASL_PLAINTEXT

Test environments only

Authentication Mechanisms

PLAIN
SCRAM-SHA-256
SCRAM-SHA-512
Kerberos (GSSAPI)

Policy Tiers

baseline-dev

20 controls

Reliability and operational checks for development clusters

enterprise-default

40 controls

Full security, reliability, and operational validation for production

finance-iso

50 controls

Advanced compliance controls for regulated industries

Coming Soon

How It Works

1

Connect

Connect to your Kafka cluster using bootstrap servers and authentication credentials

2

Evaluate Controls

KafkaGuard evaluates 40+ security, reliability, and operational controls based on your selected policy tier

3

Generate Reports

Receive comprehensive reports in JSON, HTML, PDF, or CSV format with detailed findings and remediation guidance

Get in Touch