AWS security & cost, handled — for DevOps teams and CTOs without an AWS hire.
Two jobs. One product.
CloudArq runs up to 193 checks · 6 pillars · CIS mappings where applicable — coverage scales with tier. What changes between roles is which findings rise to the top, what alerts fire, and what shape the export takes.
One product, weighted to your role.
Stop being the bottleneck on cloud questions.
Your CTO asks "are we secure?" once a quarter. CloudArq gives you a one-glance scoreboard so the answer is a screenshot, not a sprint.
- Pre-deploy: run a scan in CI · block PRs that introduce critical findings.
- On-call: every finding ships with remediation steps you can paste-and-resolve.
- Slack alerts you can ignore — criticals only, not the medium-severity noise.
- Diff audits across deploys to see what your team actually changed in AWS.
Sleep through the night without an AWS hire.
You shipped fast. The bill went up. CloudArq tells you what cost money you didn't realize, what got exposed in a 2 a.m. push, and what to fix this Friday.
- AI Workload lens: your Bedrock agents' blast radius, excessive agency, guardrail gaps, and RAG-source exposure — read-only, configuration-based, no agent installed. Max.
- Cost Intelligence: catch runaway AI & AWS spend — Bedrock has no spend cap, so a runaway agent or a stolen key (LLMjacking) can run up five figures before you notice. Pro and up.
- Weekly digest in your inbox — no dashboard you have to remember to check.
- Spend report by AWS service · with a one-line "fix this" for each line item.
- Set up cost controls in one step — generated Terraform & CloudFormation for AWS Budgets + a billing alarm, templated from your real spend. (Honest: budgets alert you early; AWS has no hard spend cap.) Export the fix for every cost finding as one bundle.
- Investor-ready PDF audit on demand, with severity-sorted findings.
- Tier-upgrade nudges when usage crosses thresholds — no surprise overages.
Each pillar, distilled to a sentence.
One scan applies 193 checks across 6 lenses — what changes by role is which findings rise to the top.
IAM mis-config, public S3 buckets, open ports, no-MFA root, unrotated keys, KMS rotation, GuardDuty status, Security Hub coverage.
Unattached EBS volumes, idle NAT gateways, oversized EC2, gp2 → gp3 conversions, stopped instances with attached volumes, unused EIPs. Cost Intelligence (Pro+) adds where your AWS spend — including AI/Bedrock — is going, with spend-spike and possible-LLMjacking detection, each with the fix.
Missing RDS backups, single-AZ databases, no auto-recovery, missing CloudWatch alarms, DynamoDB without PITR, single-AZ load balancers.
Burstable EC2 with depleted credits, missing CloudFront caching, RDS read replicas, Lambda memory tuning, S3 transfer acceleration.
Missing CloudWatch log retention, no CloudFormation drift detection, IAM Access Analyzer disabled, Systems Manager unmanaged hosts.
Workloads in non-renewable regions, Graviton candidates, unused snapshots, oversized Lambda packages, S3 lifecycle gaps.
· This is a sample — not the full scanner enumeration. View the complete check set in the docs.
Pull every finding into your own tools.
The public REST API lives at /api/v1. Authenticate with an X-API-Key header (mint keys from API Docs in-app). API access is a Max-tier feature. Pair it with Slack, PagerDuty, and signed webhooks (Pro+) to wire findings straight into your incident flow.
List completed audits with scores, finding counts, and waste totals.
Every finding for an audit — severity, service, remediation.
Cost breakdown by AWS service, plus the AI/Bedrock spend view.
Kick off a read-only scan on a connection from CI or a cron.
· Every API call is read-only against your AWS account. Full reference + auth flow in the docs.
The workspace you sign in to.
Score, waste, and severity-ranked findings at a glance. The shipped app wires every tile to your account's live scan.
Representative layout — the shipped app wires every tile and finding to your account's live scan data.
Go deeper on any lens.
Five focused guides on the checks behind the scan — the Max-tier AI Workload lens plus the compliance benchmarks CloudArq maps your findings to.
AI Workload Security
Read your Bedrock agents' blast radius, excessive agency, guardrail gaps, and RAG-source exposure — configuration-based, no agent installed.
Explore amazon bedrockAmazon Bedrock Security
The Amazon Bedrock attack surface, mapped — agents, action groups, knowledge bases, and the guardrails meant to contain them.
Explore llmjackingLLMjacking Detection
How stolen AWS credentials get used to run models on your bill, and the cost + security signals that surface it early.
Explore soc 2SOC 2 AWS Checklist
Which automated AWS checks map to SOC 2 controls, so you can evidence your posture without spreadsheet archaeology.
Explore cis benchmarkCIS AWS Benchmark
Automated checks mapped to the CIS AWS Foundations Benchmark, each finding shipped with the exact fix.
Explore aws costAWS Cost Optimization
Idle, oversized, and orphaned resources across compute, storage, networking, databases, and AI spend — each flagged with the exact fix.
Explore hipaaHIPAA on AWS
Read-only AWS checks mapped to the HIPAA Security Rule's technical safeguards — access control, encryption, audit controls, transmission security.
Explore pci dssPCI DSS on AWS
Which AWS-infrastructure checks evidence PCI DSS requirements — inbound restriction, encryption at rest and in transit, least privilege, audit trails.
Explore iso 27001ISO 27001 on AWS
Read-only checks mapped to ISO/IEC 27001:2022 Annex A technical controls — access, cryptography, logging, and network security.
Explore nist 800-53NIST 800-53 on AWS
Your AWS configuration mapped to NIST 800-53 control families — AC, AU, CM, CP, IA, SC, SI — with the fix for each gap.
Explore well-architectedWell-Architected Review
An automated review across all six Well-Architected pillars — security, cost, reliability, performance, operations, and sustainability.
Explore gdprGDPR on AWS
Read-only checks mapped to the technical GDPR measures under Art. 25 and Art. 32 — encryption, access restriction, availability, and logging.
Explore aws cspmAWS CSPM
What cloud security posture management means on AWS, and how an agentless, read-only audit covers posture, cost, and AI risk in one pass.
Explore guidesAWS Security & Cost Guides
Step-by-step how-tos — audit public S3 access, rotate stale IAM keys, set up Bedrock guardrails, and cut AWS cost waste.
Explore compareCloudArq vs AWS-native tools
How CloudArq and the AWS-native services (Security Hub, GuardDuty, Config, Trusted Advisor) fit together — complementary, not either/or.
Explore compareAWS scanner: build vs buy
The honest trade-offs between a DIY open-source scanner and a managed audit — maintenance, coverage drift, framework mapping, remediation.
Explore