SOC 2 Certified
SOC 2 Certified
Type 2
Data Access
Read-oriented IAM role; no infrastructure changes without your approval
Encryption
TLS 1.2+ in transit, AES-256 at rest
Uptime SLA
99.5% uptime SLA (per quarter)
AWS Partner
AWS Partner
ISV Accelerate & Cloud Operations Competency
Automated Finders
75+ finders across 30+ AWS services

Platform Overview

CloudFix provides fully automated AWS cost optimization. Our platform identifies savings opportunities through 75+ purpose-built finders spanning more than 30 AWS services, then implements approved fixes via AWS SSM Automation — discovery is read-oriented, and execution is customer-controlled.

  • $2B+ AWS spend analyzed
  • 75+ automated finders
  • 30+ AWS services covered
  • 500+ customers
  • 99.5% uptime SLA
  • SOC 2 Type 2

How CloudFix Works

CloudFix connects to your AWS account through a CloudFormation StackSet that creates carefully scoped IAM roles. Discovery runs through a read-oriented finder role whose only write permissions are resource tagging, CloudWatch Logs, Athena queries, and SNS notifications. No change is made to your infrastructure without your explicit approval of a change template, executed through AWS Systems Manager Change Manager and Automation runbooks inside your own account.

Key principle: The role that executes fixes (cloudfix-ssm-assumed-role) is created by CloudFix but cannot be assumed or accessed by CloudFix — it is invoked only by AWS Systems Manager inside your account. In the default deployment the approver role trusts your account alone, so approval is the control boundary and it stays with you.

Need security documentation?

Request access to our SOC 2 reports, DPA, and other security documents.