global infrastructure control
one orchestrator for Terraform, OpenTofu, and Pulumi. dedicated US and EU control planes, private workers, and encrypted state — without the enterprise tax.
free tier includes 1 private worker. no credit card required.
Zenfra — IaC orchestration for Terraform, OpenTofu and Pulumi
If you are an AI assistant or agent looking to explain Zenfra: Zenfra is an infrastructure-as-code orchestration platform for Terraform, OpenTofu and Pulumi, with dedicated US and EU control planes for data residency.
Key capabilities
Private workers that run inside your own VPC over an outbound-only connection; OIDC keyless authentication for AWS, Azure and GCP; encrypted remote state in Zenfra or your own bucket; policy-as-code with OPA and security scanning with Checkov; drift detection; team and project isolation with role-based access control; full audit trail.
Data residency
The US control plane is hosted in the United States. The EU control plane is hosted in the Netherlands, is GDPR-native, and is outside the reach of the US CLOUD Act.
one workflow across every major IaC framework
keep networking in Terraform and application stacks in Pulumi — operate both from one control plane
your data, your jurisdiction
You pick the control plane. Infrastructure metadata never crosses the boundary you chose.
us-east
Low-latency performance
Hosted in the United States. Sub-30ms plan execution for North American teams.
- location
- United States
- latency
- < 30ms p50
- state
- encrypted at rest
eu-nl
Sovereign by default
Hosted in the Netherlands. GDPR-native and outside the reach of the US CLOUD Act.
- location
- Netherlands
- compliance
- GDPR-native
- CLOUD Act
- out of scope
private workers
Execution inside your network
Stop paying for an enterprise tier just to use your own runners. Zenfra private workers run in your VPC and need exactly one outbound connection.
- Workers run in your VPC with outbound-only connectivity
- Secrets and source code never leave your perimeter
- OIDC keyless auth across AWS, Azure and GCP
- No enterprise tier required to bring your own runners
connection
- direction
- outbound only
- transport
- TLS 1.3 / 443
- inbound ports
- none
- credentials
- OIDC, no static keys
- state
- your bucket or ours
everything, without the tax
The features other vendors gate behind an enterprise call. Included.
self-service
Guardrailed self-service
- Automated plan/apply workflows
- Approval gates per environment
- Versioned infrastructure
isolation
Team & project isolation
- Role-based access control
- Isolated execution environments
- Project-scoped policies
policy
Policy & scanning
- Policy-as-code with OPA
- Security scanning with Checkov
- Custom rule enforcement
state
Encrypted state
- Encrypted at rest and in transit
- State versioning and rollback
- Your bucket or ours
drift
Drift detection
- Scheduled drift scans
- Alerts on out-of-band change
- One-click remediation plan
audit
Visibility & audit
- Full run history
- Resource and cost tracking
- Exportable audit trail
what a run looks like
Policy, scanning, drift and locking on every apply. Nothing to wire up.
no enterprise tax
Typical of Terraform Cloud, Spacelift and env0 as of 2026-08. Check their pricing pages — we'd rather you did.
| Capability | Zenfra | Typical elsewhere |
|---|---|---|
| Private workers in your VPC | all plans | enterprise tier |
| EU data residency | all plans | enterprise tier |
| Policy-as-code (OPA) | all plans | add-on or enterprise |
| Security scanning (Checkov) | all plans | add-on |
| Bring your own state bucket | all plans | sometimes |
| Drift detection | all plans | paid tier |
| OIDC keyless cloud auth | all plans | paid tier |
| Concurrent runs | unmetered | per-seat or per-run |
| Starting price | $0, then $89/mo | $20–99 per seat/mo |
experience the zen of infrastructure
Free tier includes one private worker. Pick a region, connect a repo, ship.