Available on AWS Marketplace

Every AWS account. One read-only view of what runs, what it costs, and what’s at risk.

Inventory, cost, security, and compliance from the same source of truth — read-only cross-account access, tenant-isolated from day one.

DashboardIllustrative

Scope: All accounts (6)

Current month spend

$48,212

↓ 7.0% vs. last month

Estimated savings

$3,940/mo

14 open opportunities

Unresolved critical / high

12

3 critical

Compliance score

78%

47 / 60 automated controls

Daily cost, last 30 days

Top open findings

Root account has no MFA
critical · 2 accounts
SSH open to the internet
critical · sg-0a12… Production
CloudTrail not multi-region
high · 1 account
Unencrypted EBS volume
medium · 4 resources

Inventory

Multi-account, multi-region resources, tags, relationships, and history — the source of truth for everything else.

Cost & FinOps

CUR 2.0 ingestion, amortized by default, with budgets, forecasts, and savings ranked by money.

Security

30+ deterministic checks plus Security Hub, GuardDuty, and Inspector findings, grouped by what produced them.

Compliance

CIS, AWS FSBP, ISO 27001, and NIST CSF mappings with evidence-backed, reproducible scores.

Built on trust

You deploy the role. We never hold a key.

Access is a cross-account AssumeRole with a unique external ID per connection, deployed from a versioned CloudFormation template you can read line by line. Every permission is a read.

Read the security model →
drizzle-cloud-read-only-role.yamlv1.6.0
AssumeRolePolicyDocument:
  Statement:
    - Effect: Allow
      Principal:
        AWS: arn:aws:iam::[DRIZZLE ACCOUNT]:root
      Action: sts:AssumeRole
      Condition:
        StringEquals:
          sts:ExternalId: [UNIQUE PER CONNECTION]
ManagedPolicyArns: []   # none — custom read-only policy only
Mapped frameworks
  • CIS AWS Foundations 1.5
  • AWS FSBP
  • ISO/IEC 27001:2022
  • NIST CSF 1.1

See your AWS estate clearly.

Onboarding a first AWS account takes minutes, and access stays read-only.