Multi-provider control plane
Every environment you run, on one map.
Connect your cloud accounts. Get one inventory, real architecture diagrams, and what every resource costs — read from the providers themselves, not guessed.
Thirty seconds. Tell us what you run and we’ll reply within one working day.
How it is organised
Three levels. Nothing above them to think about.
Project
The thing you ship
Its own pipelines, alerts, roles and costs.
acme-orders
Environment
Where it runs
QA, staging, production. Production is treated differently, on purpose.
acme-orders / production
Connection
The account behind it
One account, one region, one stored secret. Never logged, never returned.
acme-orders / production / aws 4417… us-east-1
Architecture discovery
We only draw a line when the provider told us it exists.
An edge appears when the target’s security group admits the source’s — and the diagram carries that rule as the reason.
the one rule the scanner is built around
Sharing a VPC is never enough — read that way, a forty-resource VPC becomes sixteen hundred meaningless lines.
Never drawn
“Same VPC, so connect them.”
“It’s a Lambda, so it probably reads the queue.”
A real edge
sg-0db allows tcp/5432 from sg-0app
HTTPS:443 /api/* → target group orders-tg
rtb-0f2 routes 0.0.0.0/0 via nat-04c
When a credential can’t read something
The scan names the gap and returns the rest.
Capabilities
The day-to-day, without four consoles and a spreadsheet.
Inventory
One resource catalog
- Import what already exists
- Table, cards, topology, architecture
- Owner, repo and docs on every resource
- Status refreshed on a schedule
ecs-service orders-api · 4/4 running · us-east-1
Cost
What each resource costs
- Priced from live configuration
- Not a billing export a day late
- Rolls up per environment and project
- Stated as a list-price estimate
m5.large · us-east-1 · $0.096/hr × 730h
Databases
Backup, restore, query
- Provider snapshots and real dumps
- Restore always creates a new resource
- SQL, Redis and OpenSearch consoles
- Access grants that expire themselves
pg_dump orders → s3://acme-backups/ · 14d
Delivery
Pipelines and jobs
- Guided form or a visual canvas
- Live build status and run history
- Every long job in one list
- A notification when yours finishes
job architecture-scan · RUNNING · 3 of 5 connections
Signals
Alerts that know the difference
- Failure spikes, flapping, disk pressure
- Running capacity below desired
- A rollout in progress is not an outage
- Mute the legitimate exceptions
service-unhealthy 2/3 running · status still ACTIVE
Application
Your own /metrics, charted
- Point it at a Prometheus endpoint
- Panels build themselves
- Histograms as p50 / p95 / p99
- Failed scrapes recorded, not skipped
http_request_duration p95 324ms · 89 routes
Guardrails
Built for the moment somebody clicks the wrong thing.
None of it held back for the expensive plan.
Production
Two people, not one
A second admin approves. Atomic, so a race can’t start it twice.
run PENDING_APPROVAL → approved by a different admin
Credentials
Secrets never round-trip
Stored on the way in, stripped before anything is saved or returned.
connection holds a secretRef, never the secret
Audit
Every change, recorded
Written by the router, not the route — so nothing can forget.
audit actor · action · entity · project · timestamp
Identity
Federated sign-on only
GitHub, Microsoft or Google. No password to leak.
oidc github | microsoft | google · + device biometric
Access
Roles you can shape
Viewer, operator, admin — or build your own permission set.
role held per membership, with per-project overrides
Tenancy
One org can’t see another
Enforced in the type system and again at the router.
a cross-tenant query is a compile error
Pricing
Start on Free. Stay on it as long as it fits.
Flat monthly, per organisation. Every plan includes the audit trail, roles, alerts and two-person production approval.
Free
$0 / month
One project, connected properly.
- Projects
- 1
- Connections
- 2
- Environments
- 2 per project
- Tracked resources
- 25
- Members
- 3
- Inventory, costs and pipelines
- Alerts, roles and the full audit trail
- Two-person production approval
- Community support
Pro Most teams
$149 / month
The full toolkit for a working team.
- Projects
- 5
- Connections
- 10
- Environments
- Unlimited
- Tracked resources
- 250
- Members
- 15
- Architecture scanning and diagrams
- Database backup, schedules and restore
- SQL, Redis and OpenSearch consoles
- Blueprint provisioning and DR scan
- Alert email and service accounts
- Email support
Business
$499 / month
For an estate spanning accounts and teams.
- Projects
- Unlimited
- Connections
- Unlimited
- Environments
- Unlimited
- Tracked resources
- 2,000
- Members
- 100
- Everything in Pro
- Self-hosted database backup
- Stored database credentials
- Restrict sign-on providers
- Priority support, with an SLA
Connect one account. See what you actually have.
The first scan takes minutes, and reads nothing it wasn’t given permission to.
Request a demo
Rather see it against your own estate?
We’ll walk you through it on infrastructure you recognise — not a sandbox with three tidy resources in it.
-
01
You send this form
Thirty seconds.
-
02
We reply within one working day
With times, and a read-only policy to review.
-
03
Thirty minutes, screen shared
Connect an account, scan it, read the diagram together.
-
04
You keep the organisation
A real Free organisation, not a trial that expires.
Request received
Thanks — we’ll email you within one working day with times and a read-only policy to review.
Already have an account? Sign in.