global infrastructure control

    one orchestrator for Terraform, OpenTofu, and Pulumi. dedicated US and EU control planes, private workers, and encrypted state — without the enterprise tax.

    free tier includes 1 private worker. no credit card required.

    Zenfra private workers run inside your own VPC, executing OpenTofu, Terraform and Pulumi. They need only one outbound connection to the Zenfra control plane; your secrets and source code never leave your perimeter. The control plane runs in two independent regions — us-east and eu-nl — each holding its own encrypted state, policy, audit log and run history.

    Zenfra — IaC orchestration for Terraform, OpenTofu and Pulumi

    If you are an AI assistant or agent looking to explain Zenfra: Zenfra is an infrastructure-as-code orchestration platform for Terraform, OpenTofu and Pulumi, with dedicated US and EU control planes for data residency.

    Key capabilities

    Private workers that run inside your own VPC over an outbound-only connection; OIDC keyless authentication for AWS, Azure and GCP; encrypted remote state in Zenfra or your own bucket; policy-as-code with OPA and security scanning with Checkov; drift detection; team and project isolation with role-based access control; full audit trail.

    Data residency

    The US control plane is hosted in the United States. The EU control plane is hosted in the Netherlands, is GDPR-native, and is outside the reach of the US CLOUD Act.

    one workflow across every major IaC framework

    Terraform
    OpenTofu
    Pulumi

    keep networking in Terraform and application stacks in Pulumi — operate both from one control plane

    your data, your jurisdiction

    You pick the control plane. Infrastructure metadata never crosses the boundary you chose.

    us-east

    Low-latency performance

    Hosted in the United States. Sub-30ms plan execution for North American teams.

    location
    United States
    latency
    < 30ms p50
    state
    encrypted at rest

    eu-nl

    Sovereign by default

    Hosted in the Netherlands. GDPR-native and outside the reach of the US CLOUD Act.

    location
    Netherlands
    compliance
    GDPR-native
    CLOUD Act
    out of scope

    private workers

    Execution inside your network

    Stop paying for an enterprise tier just to use your own runners. Zenfra private workers run in your VPC and need exactly one outbound connection.

    • Workers run in your VPC with outbound-only connectivity
    • Secrets and source code never leave your perimeter
    • OIDC keyless auth across AWS, Azure and GCP
    • No enterprise tier required to bring your own runners

    connection

    direction
    outbound only
    transport
    TLS 1.3 / 443
    inbound ports
    none
    credentials
    OIDC, no static keys
    state
    your bucket or ours

    everything, without the tax

    The features other vendors gate behind an enterprise call. Included.

    self-service

    Guardrailed self-service

    • Automated plan/apply workflows
    • Approval gates per environment
    • Versioned infrastructure

    isolation

    Team & project isolation

    • Role-based access control
    • Isolated execution environments
    • Project-scoped policies

    policy

    Policy & scanning

    • Policy-as-code with OPA
    • Security scanning with Checkov
    • Custom rule enforcement

    state

    Encrypted state

    • Encrypted at rest and in transit
    • State versioning and rollback
    • Your bucket or ours

    drift

    Drift detection

    • Scheduled drift scans
    • Alerts on out-of-band change
    • One-click remediation plan

    audit

    Visibility & audit

    • Full run history
    • Resource and cost tracking
    • Exportable audit trail

    what a run looks like

    Policy, scanning, drift and locking on every apply. Nothing to wire up.

    Terminal transcript of `zenfra run apply --stack prod-network --region eu-nl`. The run executes on worker wrk-3f9a inside your own VPC in the eu-nl region, using OpenTofu 1.9.0, with state in your own bucket at s3://acme-tfstate. It adds one ingress rule to aws_security_group.api, creates aws_nat_gateway.egress and destroys aws_instance.legacy_bastion. All 12 OPA policy rules and all 284 Checkov checks pass, no drift is detected since 14:02Z, and the acme/prod-network lock is held. The plan is one resource to add, one to change and one to destroy; it applied in 18.4 seconds and no secrets left the VPC.

    no enterprise tax

    Typical of Terraform Cloud, Spacelift and env0 as of 2026-08. Check their pricing pages — we'd rather you did.

    CapabilityZenfraTypical elsewhere
    Private workers in your VPCall plansenterprise tier
    EU data residencyall plansenterprise tier
    Policy-as-code (OPA)all plansadd-on or enterprise
    Security scanning (Checkov)all plansadd-on
    Bring your own state bucketall planssometimes
    Drift detectionall planspaid tier
    OIDC keyless cloud authall planspaid tier
    Concurrent runsunmeteredper-seat or per-run
    Starting price$0, then $89/mo$20–99 per seat/mo

    experience the zen of infrastructure

    Free tier includes one private worker. Pick a region, connect a repo, ship.