Back to the registry
Agent passport

HCLTech WAFER: Well-Architected Framework for Enterprise Remediation

HCLTech · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownProfessional service
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Traditional Well-Architected Framework Reviews (WAFRs) are often slow, subjective, and limited in scope. They rely on human memory and interview-based discovery, typically covering only a fraction of critical workloads. This manual approach creates high operational overhead, takes weeks to deliver, and results in static PDF reports that leave the heavy lifting of remediation to your engineering teams.

The HCLTech Automated WAFR Engine transforms this process by leveraging a Multi-Agent GenAI architecture powered by AWS Bedrock. By scanning live state, logs, and Infrastructure-as-Code (Terraform, CloudFormation, CDK), the tool provides an absolute factual view of your environment. Unlike static scanners, our Agentic Workflow engages in reasoning and negotiates trade-offs between cost and security, validating corporate compliance (SOPs), and generating battle-tested remediation code.

Show the rest of the publisher’s description (29 more lines)

**Key Benefits and Features:**

Unmatched Accuracy and Scope

o Configuration-Based Discovery: Moves beyond subjective interviews to automated scanning of live state and IaC artifacts for absolute factual accuracy.

o Comprehensive Audit: Analyzes 100% of resources and dependencies simultaneously, eliminating the "blind spots" common in manual sampling.

Agentic AI-Powered Remediation & Negotiation

o Interactive Architectural Negotiation: The Negotiation Agent helps to reason through issues by analyzing high-risk findings and presents side-by-side trade-offs (e.g., "Best Practice" vs. "Operational Efficiency"), allowing architects to make informed decisions before code is generated.

o Context-Aware Compliance: The SOP Agent validates selected remediation paths against any specific corporate policies (Standard Operating Procedures), ensuring that "technically correct" fixes are also "organizationally compliant."

o Prescriptive Remediation: The Remediation Agent generates precise, context-aware Infrastructure-as-Code patches (Terraform/CFN) tailored to the specific codebase, ready for a Pull Request.

Speed to Insight & Reduced TCO

o Near Real-Time Results: Discovery and Gap Analysis are completed in minutes rather than weeks.

o Low Touch Engagement: Automated data gathering frees core engineering teams and SMEs from lengthy discovery workshops.

Secure & Observable Architecture

o Auditability: Every decision is tracked. The tool provides a version-controlled history of your IaC scripts, ensuring full traceability and a "Zero-Risk" validation loop before you ever hit deploy.

o Continuous Tracking: Integrated Amazon QuickSight dashboards visualize results across multiple scans, tracking improvements over time and supporting iterative rescans.

**Our Proven Methodology**

Our workflow is designed for minimal friction and maximum impact:

  • Ingest: Users upload IaC artifacts (Terraform, CloudFormation, CDK) via the secure UI. The Discovery Module parses templates to build a comprehensive graph of the workload.
  • Analyze: Automatically identify and categorize risks across all Six Pillars of the Well-Architected Framework.
  • Negotiate: A Negotiation Agent engages the user to review high-severity findings, offering comparative analysis of potential fixes (balancing Cost, Security, and Effort) to align with business context.
  • Validate: An SOP Agent checks the chosen remediation path against corporate guardrails to ensure compliance.
  • Remediate: A Remediation Agent generates the actual code patches for the approved solution.
  • Visualize: Track ROI, risk reduction deltas, and multi-scan trends via Amazon QuickSight dashboards.

**Solution Scope, Prerequisites, and Responsibilities**

  • Scope of Offering: This offering includes the deployment of the WAFR Automation platform into the customer environment, configuration of the GenAI context parameters, and an initial automated review.
  • Prerequisites: Customer must have an active AWS account. Access to Infrastructure-as-Code repositories (Terraform, CloudFormation, or CDK) or architecture diagrams. Enabled model access for AWS Bedrock in the target region.
  • Shared Responsibility Model:

•HCLTech: Deploys the automation platform, maintains the analyzer logic, and fine-tunes the GenAI prompts for remediation accuracy.

•Customer: Provides read-access to IaC repositories/artifacts and authorizes the execution of the analyzer.

•AWS: Provides the underlying compute (Fargate/Lambda) and AI services (Bedrock) ensuring infrastructure security and availability.

Highlights

Highlighted by the publisher on AWS Marketplace.

Agentic Reasoning & Negotiation: Moves beyond simple "linting" to interactive, AI-driven negotiation that balances cost and security trade-offs for every finding.

100% Factual Evidence-Based Discovery: Eliminates reliance on human memory by automatically scanning 100% of Infrastructure-as-Code (IaC) and live configurations.

Instant ROI via Automated Remediation: Compresses multi-week manual audits into minutes and delivers deployable code patches (Terraform/CFN) to resolve high-risk issues immediately.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-07-01

CompanyHCL Technologies LimitedAutomated
HQIndiaAutomated
IndustryTechnologyAutomated
Websitehttps://www.hcltech.com/

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Professional service
This offering includes support during the deployment and initial scan phases. Customers can engage HCLTech for ongoing Managed WAFR services or custom GenAI tuning under a separate agreement. Standard AWS Support models apply to the underlying services (Bedrock, Fargate, S3). For more information, please reach out at awsecosystembu@hcltech.com
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.