Skip to main content
CloudArq
solutions · who cloudarq is for

AWS security & cost, handled — for DevOps teams and CTOs without an AWS hire.

Two jobs. One product.

CloudArq runs up to 193 checks · 6 pillars · CIS mappings where applicable — coverage scales with tier. What changes between roles is which findings rise to the top, what alerts fire, and what shape the export takes.

193
checks
6
pillars
0
agents
six lenses · one read-only scan
§ 02 · two jobs

One product, weighted to your role.

§ 01 · for · devops + sre

Stop being the bottleneck on cloud questions.

Your CTO asks "are we secure?" once a quarter. CloudArq gives you a one-glance scoreboard so the answer is a screenshot, not a sprint.

  • Pre-deploy: run a scan in CI · block PRs that introduce critical findings.
  • On-call: every finding ships with remediation steps you can paste-and-resolve.
  • Slack alerts you can ignore — criticals only, not the medium-severity noise.
  • Diff audits across deploys to see what your team actually changed in AWS.
what we look for

Scans run up to 193 checks (44 on Starter, 109 on Pro, 193 on Max & Org) across security, cost, reliability, performance, operations, and sustainability. The persona above weights the report so the findings that matter to your role land at the top.

§ 02 · for · founders + ctos

Sleep through the night without an AWS hire.

You shipped fast. The bill went up. CloudArq tells you what cost money you didn't realize, what got exposed in a 2 a.m. push, and what to fix this Friday.

  • AI Workload lens: your Bedrock agents' blast radius, excessive agency, guardrail gaps, and RAG-source exposure — read-only, configuration-based, no agent installed. Max.
  • Cost Intelligence: catch runaway AI & AWS spend — Bedrock has no spend cap, so a runaway agent or a stolen key (LLMjacking) can run up five figures before you notice. Pro and up.
  • Weekly digest in your inbox — no dashboard you have to remember to check.
  • Spend report by AWS service · with a one-line "fix this" for each line item.
  • Set up cost controls in one step — generated Terraform & CloudFormation for AWS Budgets + a billing alarm, templated from your real spend. (Honest: budgets alert you early; AWS has no hard spend cap.) Export the fix for every cost finding as one bundle.
  • Investor-ready PDF audit on demand, with severity-sorted findings.
  • Tier-upgrade nudges when usage crosses thresholds — no surprise overages.
what we look for

Scans run up to 193 checks (44 on Starter, 109 on Pro, 193 on Max & Org) across security, cost, reliability, performance, operations, and sustainability. The persona above weights the report so the findings that matter to your role land at the top.

§ 03 · what we look for

Each pillar, distilled to a sentence.

One scan applies 193 checks across 6 lenses — what changes by role is which findings rise to the top.

pillar · checkswhat we look for
security

IAM mis-config, public S3 buckets, open ports, no-MFA root, unrotated keys, KMS rotation, GuardDuty status, Security Hub coverage.

cost

Unattached EBS volumes, idle NAT gateways, oversized EC2, gp2 → gp3 conversions, stopped instances with attached volumes, unused EIPs. Cost Intelligence (Pro+) adds where your AWS spend — including AI/Bedrock — is going, with spend-spike and possible-LLMjacking detection, each with the fix.

reliability

Missing RDS backups, single-AZ databases, no auto-recovery, missing CloudWatch alarms, DynamoDB without PITR, single-AZ load balancers.

performance

Burstable EC2 with depleted credits, missing CloudFront caching, RDS read replicas, Lambda memory tuning, S3 transfer acceleration.

operations

Missing CloudWatch log retention, no CloudFormation drift detection, IAM Access Analyzer disabled, Systems Manager unmanaged hosts.

sustainability

Workloads in non-renewable regions, Graviton candidates, unused snapshots, oversized Lambda packages, S3 lifecycle gaps.

· This is a sample — not the full scanner enumeration. View the complete check set in the docs.

§ 04 · api + integrations

Pull every finding into your own tools.

The public REST API lives at /api/v1. Authenticate with an X-API-Key header (mint keys from API Docs in-app). API access is a Max-tier feature. Pair it with Slack, PagerDuty, and signed webhooks (Pro+) to wire findings straight into your incident flow.

endpointread-only · X-API-Key
GET /api/v1/audits

List completed audits with scores, finding counts, and waste totals.

GET /api/v1/audits/{id}/findings

Every finding for an audit — severity, service, remediation.

GET /api/v1/connections/{id}/cost

Cost breakdown by AWS service, plus the AI/Bedrock spend view.

POST /api/v1/scan

Kick off a read-only scan on a connection from CI or a cron.

· Every API call is read-only against your AWS account. Full reference + auth flow in the docs.

§ 05 · inside the app

The workspace you sign in to.

Score, waste, and severity-ranked findings at a glance. The shipped app wires every tile to your account's live scan.

CloudArq Search…
Dashboard
last scan · just now · eu-north-1
product preview · illustrative
Security score
82/100
▲ 6 vs last scan
Open findings
37
3 critical · 9 high
Monthly waste
$1,240/mo
across 14 resources
Connections
3
all healthy
Top findingsseverity-ranked
Public S3 bucket (read)Critical
IAM key, no MFA, 400+ daysHigh
RDS without Multi-AZHigh
Unattached EBS volumeMedium
gp2 volume — migrate to gp3Low

Representative layout — the shipped app wires every tile and finding to your account's live scan data.

§ 06 · explore the platform

Go deeper on any lens.

Five focused guides on the checks behind the scan — the Max-tier AI Workload lens plus the compliance benchmarks CloudArq maps your findings to.

ai workload · max

AI Workload Security

Read your Bedrock agents' blast radius, excessive agency, guardrail gaps, and RAG-source exposure — configuration-based, no agent installed.

Explore
amazon bedrock

Amazon Bedrock Security

The Amazon Bedrock attack surface, mapped — agents, action groups, knowledge bases, and the guardrails meant to contain them.

Explore
llmjacking

LLMjacking Detection

How stolen AWS credentials get used to run models on your bill, and the cost + security signals that surface it early.

Explore
soc 2

SOC 2 AWS Checklist

Which automated AWS checks map to SOC 2 controls, so you can evidence your posture without spreadsheet archaeology.

Explore
cis benchmark

CIS AWS Benchmark

Automated checks mapped to the CIS AWS Foundations Benchmark, each finding shipped with the exact fix.

Explore
aws cost

AWS Cost Optimization

Idle, oversized, and orphaned resources across compute, storage, networking, databases, and AI spend — each flagged with the exact fix.

Explore
hipaa

HIPAA on AWS

Read-only AWS checks mapped to the HIPAA Security Rule's technical safeguards — access control, encryption, audit controls, transmission security.

Explore
pci dss

PCI DSS on AWS

Which AWS-infrastructure checks evidence PCI DSS requirements — inbound restriction, encryption at rest and in transit, least privilege, audit trails.

Explore
iso 27001

ISO 27001 on AWS

Read-only checks mapped to ISO/IEC 27001:2022 Annex A technical controls — access, cryptography, logging, and network security.

Explore
nist 800-53

NIST 800-53 on AWS

Your AWS configuration mapped to NIST 800-53 control families — AC, AU, CM, CP, IA, SC, SI — with the fix for each gap.

Explore
well-architected

Well-Architected Review

An automated review across all six Well-Architected pillars — security, cost, reliability, performance, operations, and sustainability.

Explore
gdpr

GDPR on AWS

Read-only checks mapped to the technical GDPR measures under Art. 25 and Art. 32 — encryption, access restriction, availability, and logging.

Explore
aws cspm

AWS CSPM

What cloud security posture management means on AWS, and how an agentless, read-only audit covers posture, cost, and AI risk in one pass.

Explore
guides

AWS Security & Cost Guides

Step-by-step how-tos — audit public S3 access, rotate stale IAM keys, set up Bedrock guardrails, and cut AWS cost waste.

Explore
compare

CloudArq vs AWS-native tools

How CloudArq and the AWS-native services (Security Hub, GuardDuty, Config, Trusted Advisor) fit together — complementary, not either/or.

Explore
compare

AWS scanner: build vs buy

The honest trade-offs between a DIY open-source scanner and a managed audit — maintenance, coverage drift, framework mapping, remediation.

Explore

Not sure which one is you? That's fine — run a scan.

The first scan is free on the Starter tier. We'll show you what the platform finds in your account — and which persona ranking surfaces the most relevant findings.