Trust posture

Read-only by architecture. Audited by design.

CloudPulse surfaces multi-cloud cost, AI spend, SaaS spend, carbon, and unit economics without writing a single byte into your cloud. The IAM policy your security team approves contains only read actions. The platform itself cannot deviate. It has no write permissions to deviate with.

The FinOps platform your CISO will approve and your CFO will read.

Three pillars

Read-only is not a stance we describe in a sales deck. It is a property enforced at the IAM layer, the application layer, and the audit layer.

Read-only IAM, every cloud

The role you trust to CloudPulse contains only describe / list / get actions across AWS, Azure, OCI, and GCP (in development). The published policy is the policy. No hidden write paths.

Separation of duties at the platform

Even our own identity surface (user enable / disable / password reset) runs through a dedicated mediator with its own narrow permissions. The main application has no admin identity-mutation rights. The blast radius of a platform compromise is bounded by IAM, not by trust.

Audit on every privileged action

Every operator action against customer data writes an audit record with actor, target, reason, and outcome. That includes reads of sensitive recommendations, team-membership changes, and password resets. Customers receive their account’s log on request.

How we compare

The FinOps market splits cleanly along this line. Tools that auto-apply changes require write permissions; tools that only observe do not. CloudPulse sits in the latter camp, explicitly, by design, and without exception.

Platform Cloud-write IAM required? What that means at the IAM-policy level
CloudPulse No Describe / list / get only. The role you grant cannot stop, modify, tag, terminate, or purchase anything. Customer-cloud writes are not a feature we have switched off; they are a capability we have refused to acquire. Verified by the published role policy and the security audit that runs on every release.
Spot (NetApp) Yes Auto-applies rightsizing, instance replacement, and spot-fleet management. The role you grant must hold EC2 modify / terminate scope to deliver the product.
nOps Yes Auto-purchases commitments and applies cost optimisations. Requires write scope on billing-account-level commitment APIs and compute-action APIs.
ProsperOps Yes Actively manages your commitment portfolio: buying, exchanging, and optimising RIs / Savings Plans on your behalf. Requires commitment-write scope.
Harness CCM Yes Auto-applies governance policies and remediation actions across the cloud estate. Write scope is the product.
CloudZero No Read-only on cloud APIs. Complementary on the trust axis. The competitive difference is feature breadth (multi-cloud, AI, SaaS, carbon, repatriation), not trust posture.
Vantage No Read-only. Same trust-posture camp as CloudPulse and CloudZero.
Finout No Read-only on customer-cloud APIs.
CloudHealth (Broadcom) Partial Read by default. Optional remediation modules require write scope, granted per-module, with the security review that implies.
Apptio Cloudability (IBM) Partial Primarily read. Action-oriented capabilities (TruePlan execution, certain governance flows) extend the IAM footprint when enabled.

Vendor scopes reflect public IAM-policy documentation and product positioning as of the most recent competitive review. Trust posture changes over time, so ask your prospective vendor for their published IAM policy in writing before comparison.

Evidence pack

Every security-team question we have ever been asked has a reproducible answer. The pack is available to CloudPulse customers on request, with no NDA required, in the form your team needs.

  • Published IAM policy
    The exact JSON policy each customer attaches to their cross-account role. No wildcards on write actions. Reviewable before any access is granted. Re-issuable on scope change, so you see the diff before we read anything new.
  • Standards conformance
    Built to OWASP ASVS Level 2, the OWASP API Security Top 10, NIST SSDF, and the SOC 2 Common Criteria. ISO 27001 controls mapped where they apply. Working toward UK GDPR / EU GDPR compliance by design.
  • Security review on every release
    A standing security agent reviews every code change against the same ASVS / CCM rule set, on every pull request, before merge. Findings become public commits.
  • Audit log on request
    Customers can request the full audit log for their account in JSON or CSV. Every operator action against customer data is recorded with actor, target, reason, decision, and timestamp.
  • Multi-tenant isolation
    Tenant identity is established server-side from the verified Cognito session and pinned on every request. Cross-tenant access by design is not possible from the customer-facing surface; cross-tenant access by an Embli operator requires a separate sanctioned, audited path with step-up MFA.

Start without a security exception

Spin up a CloudPulse account in minutes. The role you attach is read-only. No firewall changes. No egress paths. No write permissions to review.