A fixed-price, five-business-day audit of your Terraform against your live cloud. It runs on your infrastructure, under your credentials, with us alongside you. You keep the install and the report.
One Helm command, in your own cluster, with us on the call. We never take custody of your cloud credentials — you hold them the whole way. When the five days end, the install stays. helm uninstall removes it whenever you want.
Not “something changed.” The exact field, the old value, the new value. Severity you define, per resource type and environment.
source_ranges[0]: 10.30.0.0/16 → 0.0.0.0/0
Live resources that no Terraform state claims. This is the category terraform plan structurally cannot see, and it is usually where the uncomfortable findings are.
The first scan’s undeclared list is noisy — service-created resources surface too. Tuning that down with you is part of the five days, not homework we leave behind.
Which resource types were compared field by field, which were listed as inventory, and anything excluded. Most audits tell you what they found. This one also tells you where the looking stopped.
It is a paid engagement with a deliverable, and you keep the install and the report either way.
We never take custody of your credentials. If a vendor asks you to hand over cloud access to audit you, that is the thing this product exists to make unnecessary.
If you'd rather do it yourself, do it yourself. The install is public and needs no call and no account. It scans for 30 days, then stops starting new scans — your findings and connected sources stay put, and we'll extend it if you ask.Start with the quickstart →
In five days, on your own infrastructure, we'll show you the difference — and tell you exactly where we stopped looking.
Scans are point-in-time, on a schedule you set — never continuous. Ownership is assigned manually. Actor attribution is best-effort within a lookback window. Field-level comparison depth differs by cloud and is published, generated from the code. We are pre-launch: no customers yet, and no SOC 2. There are no Cloudkeel-DD-operated endpoints — the only outbound traffic is the read calls to your own cloud APIs, plus any webhook or Git host you configure.