Turul is a desktop app for AWS and GCP. 200+ scanners across cost, security posture, IAM, network reachability, CIS compliance, and Well-Architected — with built-in AI chat. Credentials live in your OS keychain. The database lives on your machine. Nothing is sent to a third-party SaaS.
Latest release: v0.9.3 · Pick your platform.
glibc 2.28+ (Ubuntu 22.04+, Fedora 38+).
macOS builds are not yet notarized — on first launch, right-click the app icon and choose Open to bypass Gatekeeper.
For solo engineers, freelancers, small teams, and regulated environments where data can't leave the laptop.
| Turul | SaaS CSPMs (Wiz, Prisma) | CLI tools (Steampipe, CloudQuery) | |
|---|---|---|---|
| Where data lives | Local SQLite on your laptop | Vendor cloud | Local DB / DW (BYO) |
| Setup time | Install installer, point at AWS / gcloud | Org rollout, cross-account IAM roles | Install + write SQL |
| UI | Native desktop app | Web console | None — bring-your-own |
| Cost analysis | Cost Explorer + GCP Billing + GKE drill-down | Vendor pricing | DIY queries |
| Multi-cloud | AWS + GCP | Yes | Yes |
| Open source | Apache-2.0 | No | Apache-2.0 / MPL |
Everything an engineer needs to understand a single AWS / GCP environment.
117 service scanners, multi-region, multi-account.
85 service scanners, multi-project, multi-account.
Cost Explorer + GCP Billing with trends, forecasts, and GKE cluster / namespace / workload drill-down.
Security Hub, SCC, AWS CIS v3 (120+ controls), GCP CIS, best-practice checks.
Unused roles, overly-permissive policies, cross-account / cross-project trust, service-account keys.
EC2 / RDS via security groups + NACLs, GCP VPC firewall analysis.
AWS 6-pillar reviews via the WA API; GCP-native 5-pillar checks.
Network, Application, and Data views — plus a full topology graph.
Cost / Security / Reliability / Compliance / IAM A–F grades with persisted history.
9-layer async pipeline for AWS tags and GCP labels.
AWS Bedrock-powered assistant with tool calling over AWS, GCP, and the local DB.
PDF, Excel, and CSV export for assessments, costs, and optimization.
main, signed-tag releases, CodeQL, OSSF Scorecard, Trivy, dependency review, secret scanning + push protection, all third-party Actions pinned to commit SHAs.