DevOps Sign in

Multi-provider control plane

Every environment you run, on one map.

Connect your cloud accounts. Get one inventory, real architecture diagrams, and what every resource costs — read from the providers themselves, not guessed.

Thirty seconds. Tell us what you run and we’ll reply within one working day.

architecture · production · scanned 4 min ago
vpc-0a41c8 · us-east-1 subnet · public subnet · private internet inbound edge-alb load-balancer active api ecs-service 4/4 running worker ecs-service 2/3 running identity apprunner-service running orders-db rds-instance available sessions atlas-cluster idle why this edge exists: sg-0db allows tcp/5432 from sg-0app
reach ingress declared swipe → 7 relationships · 0 inferred
Connects AWS Azure MongoDB Atlas Google Cloud Cloudflare SendGrid Firebase Azure DevOps Self-hosted Postgres & MongoDB

How it is organised

Three levels. Nothing above them to think about.

Project

The thing you ship

Its own pipelines, alerts, roles and costs.

acme-orders

Environment

Where it runs

QA, staging, production. Production is treated differently, on purpose.

acme-orders / production

Connection

The account behind it

One account, one region, one stored secret. Never logged, never returned.

acme-orders / production / aws 4417… us-east-1

Architecture discovery

We only draw a line when the provider told us it exists.

An edge appears when the target’s security group admits the source’s — and the diagram carries that rule as the reason.

the one rule the scanner is built around

Sharing a VPC is never enough — read that way, a forty-resource VPC becomes sixteen hundred meaningless lines.

Never drawn

“Same VPC, so connect them.”

“It’s a Lambda, so it probably reads the queue.”

A real edge

sg-0db allows tcp/5432 from sg-0app

HTTPS:443 /api/* → target group orders-tg

rtb-0f2 routes 0.0.0.0/0 via nat-04c

When a credential can’t read something

The scan names the gap and returns the rest.

Capabilities

The day-to-day, without four consoles and a spreadsheet.

Inventory

One resource catalog

  • Import what already exists
  • Table, cards, topology, architecture
  • Owner, repo and docs on every resource
  • Status refreshed on a schedule

ecs-service orders-api · 4/4 running · us-east-1

Cost

What each resource costs

  • Priced from live configuration
  • Not a billing export a day late
  • Rolls up per environment and project
  • Stated as a list-price estimate

m5.large · us-east-1 · $0.096/hr × 730h

Databases

Backup, restore, query

  • Provider snapshots and real dumps
  • Restore always creates a new resource
  • SQL, Redis and OpenSearch consoles
  • Access grants that expire themselves

pg_dump orders → s3://acme-backups/ · 14d

Delivery

Pipelines and jobs

  • Guided form or a visual canvas
  • Live build status and run history
  • Every long job in one list
  • A notification when yours finishes

job architecture-scan · RUNNING · 3 of 5 connections

Signals

Alerts that know the difference

  • Failure spikes, flapping, disk pressure
  • Running capacity below desired
  • A rollout in progress is not an outage
  • Mute the legitimate exceptions

service-unhealthy 2/3 running · status still ACTIVE

Application

Your own /metrics, charted

  • Point it at a Prometheus endpoint
  • Panels build themselves
  • Histograms as p50 / p95 / p99
  • Failed scrapes recorded, not skipped

http_request_duration p95 324ms · 89 routes

Guardrails

Built for the moment somebody clicks the wrong thing.

None of it held back for the expensive plan.

Production

Two people, not one

A second admin approves. Atomic, so a race can’t start it twice.

run PENDING_APPROVAL → approved by a different admin

Credentials

Secrets never round-trip

Stored on the way in, stripped before anything is saved or returned.

connection holds a secretRef, never the secret

Audit

Every change, recorded

Written by the router, not the route — so nothing can forget.

audit actor · action · entity · project · timestamp

Identity

Federated sign-on only

GitHub, Microsoft or Google. No password to leak.

oidc github | microsoft | google · + device biometric

Access

Roles you can shape

Viewer, operator, admin — or build your own permission set.

role held per membership, with per-project overrides

Tenancy

One org can’t see another

Enforced in the type system and again at the router.

a cross-tenant query is a compile error

Pricing

Start on Free. Stay on it as long as it fits.

Flat monthly, per organisation. Every plan includes the audit trail, roles, alerts and two-person production approval.

Free

$0 / month

One project, connected properly.

Projects
1
Connections
2
Environments
2 per project
Tracked resources
25
Members
3
  • Inventory, costs and pipelines
  • Alerts, roles and the full audit trail
  • Two-person production approval
  • Community support

Business

$499 / month

For an estate spanning accounts and teams.

Projects
Unlimited
Connections
Unlimited
Environments
Unlimited
Tracked resources
2,000
Members
100
  • Everything in Pro
  • Self-hosted database backup
  • Stored database credentials
  • Restrict sign-on providers
  • Priority support, with an SLA

Connect one account. See what you actually have.

The first scan takes minutes, and reads nothing it wasn’t given permission to.

Request a demo

Rather see it against your own estate?

We’ll walk you through it on infrastructure you recognise — not a sandbox with three tidy resources in it.

  1. 01

    You send this form

    Thirty seconds.

  2. 02

    We reply within one working day

    With times, and a read-only policy to review.

  3. 03

    Thirty minutes, screen shared

    Connect an account, scan it, read the diagram together.

  4. 04

    You keep the organisation

    A real Free organisation, not a trial that expires.

demo-request · new