Trust Center
Security, compliance and privacy for CloudFix and RightSpend.
How CloudFix connects to your AWS accounts, what it can read and change, who approves each change, and where the record of it lives.
At a glance
- SOC 2 Type 2 audited, security and availability
- Least-privilege IAM roles deployed by CloudFormation you can read first
- Nothing runs without your approval, and every run is logged
- All activity in your CloudTrail, independent of CloudFix logs
- One region: AWS us-east-1
Quick facts
What a security review asks first.
- SOC 2
- Type 2 auditedSecurity and availability criteria, independent auditor.
- Data access
- Read-oriented IAM rolesNo change to your infrastructure without your approval.
- Encryption
- TLS 1.2+ and AES-256In transit and at rest.
- Uptime SLA
- 99.5% per quarterFor the CloudFix dashboard and API.
- AWS Partner
- ISV Accelerate and Cloud Operations CompetencyAvailable in AWS Marketplace.
- Coverage
- 110+ finders · 53 automated fixersAcross 30+ AWS services.
Audited, partnered and listed
How CloudFix works
Four steps, and one of them is yours.
CloudFix connects through a CloudFormation StackSet that creates carefully scoped IAM roles. Discovery is read-oriented. Fixes run inside your own account, after you approve them.
Connect
A CloudFormation StackSet you deploy creates scoped IAM roles in your accounts. No agents, no stored credentials.
Discover
Finders read Cost and Usage Reports, CloudWatch metrics and resource metadata, overwhelmingly with Describe, List and Get calls.
Approve
Each recommendation shows its savings, effort and risk. Nothing changes in your account until you approve it.
Run
The approved fix runs as an AWS Systems Manager Automation runbook in your account, under cloudfix-ssm-update-role, and every execution is logged.
Approval is the control boundary, and it stays with you. CloudFix can find an opportunity and prepare the fix, but nothing runs until you approve it. The approved fix runs as an AWS Systems Manager Automation runbook in your account under cloudfix-ssm-update-role, which the CloudFix platform can assume only with an external ID unique to your tenant. Every call lands in your CloudTrail, and deleting the stack revokes all access.
The platform
Fully automated AWS cost optimization.
110+ purpose-built finders spanning more than 30 AWS services identify savings. 53 automated fixers implement the ones you approve, through AWS Systems Manager Automation.
- $2B+
- AWS spend analyzed
- 500+
- companies
- 110+
- finders · 53 automated fixers · 30+ AWS services
Trust Center documents
Everything a reviewer needs, in one place.
Security
The finder and fixer roles, encryption, network, API authentication and incident response.
OpenArchitecture
Data flow diagrams for CloudFix, ITSM integration and RightSpend.
OpenCompliance
SOC 2 Type 2, AWS partner status, standards alignment and documents on request.
OpenData processing
Data residency, the DPA summary, sub-processors and integration data flows.
OpenPrivacy
What CloudFix collects, what it never collects, retention and sub-processors.
OpenSupport and SLA
Company overview, severity levels, escalation path and vulnerability disclosure.
OpenRightSpend
How RightSpend manages Convertible Reserved Instances, and the three roles it needs.
OpenStatus
Service components, recent incidents and the uptime commitment.
Open
Need security documentation?
Request the SOC 2 Type 2 report, the DPA, the penetration test summary or anything else your review needs. We respond within 2 business days.

