Platform

Inventory, cost, security, compliance, reporting, and AI-assisted insights for AWS, unified in one platform.

Every surface reads from the same inventory, so a cost, a finding and a control failure all point at the same resource.

Inventory

Every resource, every account, every region.

Drizzle Cloud discovers EC2, EBS, S3, Lambda, RDS, VPC networking, load balancers, IAM, and more across every connected AWS account — with relationships between them, not just a flat list.

  • Multi-account, multi-region discovery on a schedule you control
  • Resource relationships: EC2 → EBS → subnet → VPC → security group
  • Change history with canonicalized metadata hashes
  • Search by ARN, ID, name, tag, account, service, region, type, or owner
web-server-02 · aws.ec2.instanceResource · illustrative
Account
Production · 111122223333
Region
eu-west-1
Type
t3.medium · running
Attached
vol-0a4f (gp3, 40 GiB) · sg-0a12f9
Tags
Environment=production, Owner=platform
Last confirmed
41 min ago

Cost & FinOps

Cost explained, not just reported.

CUR 2.0 cost data is ingested incrementally and correlated back to the resources that generated it, so cost changes have a concrete explanation, not just a number.

  • Current month, previous month, variance, and forecast in one view
  • Group by account, service, region, and activated cost-allocation tags
  • Stopped EC2, unattached EBS, idle load balancers, and more, ranked by money
  • Budget thresholds and alerts, with clear data-freshness disclosure
RecommendationIllustrative
batch-runner
Stopped EC2 instance
Evidence window
16 Jul – 15 Aug
Current cost
$64.80 / month, amortized
Estimated saving
$64.80 / month
Confidence
High

Security

Deterministic checks. No black-box scoring.

30+ checks covering identity, logging, storage, network, and database configuration run on a schedule and produce evidence-backed findings — plus imported Security Hub, GuardDuty, and Inspector results in the same queue.

  • Findings are grouped by the check that produced them, across every account failing it
  • Every finding has machine-readable and human-readable evidence
  • A finding exists while the condition holds, and clears when the next scan proves it gone
  • Severity is never the only signal — labels and evidence always accompany it
aws.ec2.security_group_ssh_rdp_open_to_internetFinding · illustrative
Severity
critical
Resource
sg-0a12f9 · Production
Evidence
0.0.0.0/0 → tcp/22
Mapped to
CIS 5.2 · FSBP EC2.13
Remediation
Restrict the source CIDR or move SSH behind a bastion

Compliance

Scores you can reproduce and defend.

CIS AWS Foundations, AWS Foundational Security Best Practices, ISO/IEC 27001, and NIST CSF mappings show exactly which controls passed, failed, or require manual review — never misrepresented as automated when they aren’t.

  • Every score shows its formula and denominator
  • Critical and high failures stay visible regardless of aggregate score
  • Historical score snapshots for trend reporting
  • Not-assessed and manual controls are excluded from the score, never counted as passes
CIS AWS Foundations Benchmark 1.5Illustrative
Score
78% · 47 of 60 automated
1.10 · MFA for console users
failed
3.1 · CloudTrail in all regions
passed
1.20 · IAM Access Analyzer
manual review

Reports & alerts

The right people find out first.

Executive, inventory, cost, security, and compliance reports generate asynchronously and deliver through short-lived signed links — never an open, guessable URL.

  • Email and in-app alerts for new critical findings, budget thresholds, and scan failures
  • Every report states its period, timezone, data freshness, and included accounts
  • Redaction of secrets and sensitive fields before generation
Executive summary · August 2026Report · illustrative
Format
PDF
Accounts
6 of 6
Data as of
27 Aug 2026, 06:10 UTC
Status
succeeded
Download
Signed link, expires in 5 minutes

AI-assisted insights

Optional. Grounded. Never the final word.

Five AI features explain findings, summarize cost changes, write executive summaries, draft remediation steps, and summarize compliance gaps — using only your tenant’s approved data. Deterministic systems remain authoritative for cost, findings, and compliance status.

  • Every AI response states its purpose, generation time, and source records
  • Disabled by default where data is stale, incomplete, or unauthorized
  • The product works fully without AI enabled

Explain this finding · draft

This security group allows SSH from any address on the internet. Anyone who finds the instance can attempt to log in, so the risk depends entirely on the strength of its credentials. Restricting the source to your office or VPN range removes the exposure without changing how your team connects.

Grounded in finding 2f1a… and check aws.ec2.security_group_ssh_rdp_open_to_internet · generated 27 Aug 2026, 09:41 · not a determination of status · illustrative

See your AWS estate clearly.

Onboarding a first AWS account takes minutes, and access stays read-only.