Platform
Inventory, cost, security, compliance, reporting, and AI-assisted insights for AWS, unified in one platform.
Every surface reads from the same inventory, so a cost, a finding and a control failure all point at the same resource.
Inventory
Every resource, every account, every region.
Drizzle Cloud discovers EC2, EBS, S3, Lambda, RDS, VPC networking, load balancers, IAM, and more across every connected AWS account — with relationships between them, not just a flat list.
- Multi-account, multi-region discovery on a schedule you control
- Resource relationships: EC2 → EBS → subnet → VPC → security group
- Change history with canonicalized metadata hashes
- Search by ARN, ID, name, tag, account, service, region, type, or owner
- Account
- Production · 111122223333
- Region
- eu-west-1
- Type
- t3.medium · running
- Attached
- vol-0a4f (gp3, 40 GiB) · sg-0a12f9
- Tags
- Environment=production, Owner=platform
- Last confirmed
- 41 min ago
Cost & FinOps
Cost explained, not just reported.
CUR 2.0 cost data is ingested incrementally and correlated back to the resources that generated it, so cost changes have a concrete explanation, not just a number.
- Current month, previous month, variance, and forecast in one view
- Group by account, service, region, and activated cost-allocation tags
- Stopped EC2, unattached EBS, idle load balancers, and more, ranked by money
- Budget thresholds and alerts, with clear data-freshness disclosure
- batch-runner
- Stopped EC2 instance
- Evidence window
- 16 Jul – 15 Aug
- Current cost
- $64.80 / month, amortized
- Estimated saving
- $64.80 / month
- Confidence
- High
Security
Deterministic checks. No black-box scoring.
30+ checks covering identity, logging, storage, network, and database configuration run on a schedule and produce evidence-backed findings — plus imported Security Hub, GuardDuty, and Inspector results in the same queue.
- Findings are grouped by the check that produced them, across every account failing it
- Every finding has machine-readable and human-readable evidence
- A finding exists while the condition holds, and clears when the next scan proves it gone
- Severity is never the only signal — labels and evidence always accompany it
- Severity
- critical
- Resource
- sg-0a12f9 · Production
- Evidence
- 0.0.0.0/0 → tcp/22
- Mapped to
- CIS 5.2 · FSBP EC2.13
- Remediation
- Restrict the source CIDR or move SSH behind a bastion
Compliance
Scores you can reproduce and defend.
CIS AWS Foundations, AWS Foundational Security Best Practices, ISO/IEC 27001, and NIST CSF mappings show exactly which controls passed, failed, or require manual review — never misrepresented as automated when they aren’t.
- Every score shows its formula and denominator
- Critical and high failures stay visible regardless of aggregate score
- Historical score snapshots for trend reporting
- Not-assessed and manual controls are excluded from the score, never counted as passes
- Score
- 78% · 47 of 60 automated
- 1.10 · MFA for console users
- failed
- 3.1 · CloudTrail in all regions
- passed
- 1.20 · IAM Access Analyzer
- manual review
Reports & alerts
The right people find out first.
Executive, inventory, cost, security, and compliance reports generate asynchronously and deliver through short-lived signed links — never an open, guessable URL.
- Email and in-app alerts for new critical findings, budget thresholds, and scan failures
- Every report states its period, timezone, data freshness, and included accounts
- Redaction of secrets and sensitive fields before generation
- Format
- Accounts
- 6 of 6
- Data as of
- 27 Aug 2026, 06:10 UTC
- Status
- succeeded
- Download
- Signed link, expires in 5 minutes
AI-assisted insights
Optional. Grounded. Never the final word.
Five AI features explain findings, summarize cost changes, write executive summaries, draft remediation steps, and summarize compliance gaps — using only your tenant’s approved data. Deterministic systems remain authoritative for cost, findings, and compliance status.
- Every AI response states its purpose, generation time, and source records
- Disabled by default where data is stale, incomplete, or unauthorized
- The product works fully without AI enabled
Explain this finding · draft
This security group allows SSH from any address on the internet. Anyone who finds the instance can attempt to log in, so the risk depends entirely on the strength of its credentials. Restricting the source to your office or VPN range removes the exposure without changing how your team connects.
Grounded in finding 2f1a… and check aws.ec2.security_group_ssh_rdp_open_to_internet · generated 27 Aug 2026, 09:41 · not a determination of status · illustrative
See your AWS estate clearly.
Onboarding a first AWS account takes minutes, and access stays read-only.