Skip to content
Back to cloudfix.com
Menu

Menu expanded. The navigation follows.

Trust Center

Security, compliance and privacy for CloudFix and RightSpend.

How CloudFix connects to your AWS accounts, what it can read and change, who approves each change, and where the record of it lives.

Request security documentsRead the security model

At a glance

  • SOC 2 Type 2 audited, security and availability
  • Least-privilege IAM roles deployed by CloudFormation you can read first
  • Nothing runs without your approval, and every run is logged
  • All activity in your CloudTrail, independent of CloudFix logs
  • One region: AWS us-east-1

Quick facts

What a security review asks first.

SOC 2
Type 2 auditedSecurity and availability criteria, independent auditor.
Data access
Read-oriented IAM rolesNo change to your infrastructure without your approval.
Encryption
TLS 1.2+ and AES-256In transit and at rest.
Uptime SLA
99.5% per quarterFor the CloudFix dashboard and API.
AWS Partner
ISV Accelerate and Cloud Operations CompetencyAvailable in AWS Marketplace.
Coverage
110+ finders · 53 automated fixersAcross 30+ AWS services.

Audited, partnered and listed

  • AWS Partner, ISV Accelerate Program
  • AWS Qualified Software
  • SOC 2 Type 2 audited
  • AWS Partner with the Cloud Operations Competency
  • FinOps Foundation Member
  • Available in AWS Marketplace

How CloudFix works

Four steps, and one of them is yours.

CloudFix connects through a CloudFormation StackSet that creates carefully scoped IAM roles. Discovery is read-oriented. Fixes run inside your own account, after you approve them.

  1. Connect

    A CloudFormation StackSet you deploy creates scoped IAM roles in your accounts. No agents, no stored credentials.

  2. Discover

    Finders read Cost and Usage Reports, CloudWatch metrics and resource metadata, overwhelmingly with Describe, List and Get calls.

  3. Approve

    Each recommendation shows its savings, effort and risk. Nothing changes in your account until you approve it.

  4. Run

    The approved fix runs as an AWS Systems Manager Automation runbook in your account, under cloudfix-ssm-update-role, and every execution is logged.

Approval is the control boundary, and it stays with you. CloudFix can find an opportunity and prepare the fix, but nothing runs until you approve it. The approved fix runs as an AWS Systems Manager Automation runbook in your account under cloudfix-ssm-update-role, which the CloudFix platform can assume only with an external ID unique to your tenant. Every call lands in your CloudTrail, and deleting the stack revokes all access.

The platform

Fully automated AWS cost optimization.

110+ purpose-built finders spanning more than 30 AWS services identify savings. 53 automated fixers implement the ones you approve, through AWS Systems Manager Automation.

$2B+
AWS spend analyzed
500+
companies
110+
finders · 53 automated fixers · 30+ AWS services

Need security documentation?

Request the SOC 2 Type 2 report, the DPA, the penetration test summary or anything else your review needs. We respond within 2 business days.