Legal
Licences & attribution
Last updated: 31 August 2026 · v1.0. Deltz's rule library credits the open-source projects whose public identifiers it cites.
The rule catalog
Catalog rules are written in Deltz's own rule language against Deltz's own parser — no upstream code, policy files, or rule text is imported, copied, or machine-converted. Each rule may carry a citation (for example CKV_AWS_16) so a security team can answer "does Deltz cover this check?" and diff coverage against upstream. Those identifiers belong to:
| Project | Licence | Cited for |
|---|---|---|
| Checkov (Prisma Cloud / Palo Alto Networks) | Apache-2.0 | CKV_AWS_* identifiers on AWS rules |
| tfsec / Trivy (Aqua Security) | Apache-2.0 | provider-service-check identifiers on Azure and GCP rules |
| tflint | MPL-2.0 | Reviewed for coverage; no rules drawn from it |
Compliance mappings reference the CIS AWS Foundations Benchmark (v5.0.0) and the 2017 SOC 2 Trust Services Criteria as control frameworks; a passing gate is evidence toward a control, never certification of it.
Software notices
Self-hosted distributions ship with the third-party notices applicable to that build. This website uses system fonts and no third-party scripts.