SOC 2 Certified
SOC 2 Certified
Type 2
Data Access
Read-oriented IAM role; no infrastructure changes without your approval
Encryption
TLS 1.2+ in transit, AES-256 at rest
Uptime SLA
99.5% uptime SLA (per quarter)
AWS Partner
AWS Partner
ISV Accelerate & Cloud Operations Competency
Automated Finders
75+ finders across 30+ AWS services

Platform Overview

CloudFix provides fully automated AWS cost optimization. Our platform identifies savings opportunities through 75+ purpose-built finders spanning more than 30 AWS services, then implements approved fixes via AWS SSM Automation — discovery is read-oriented, and execution is customer-controlled.

  • $2B+ AWS spend analyzed
  • 75+ automated finders
  • 30+ AWS services covered
  • 500+ customers
  • 99.5% uptime SLA
  • SOC 2 Type 2

How CloudFix Works

CloudFix connects to your AWS account through a CloudFormation StackSet that creates carefully scoped IAM roles. Discovery runs through a read-oriented finder role whose write permissions are limited to resource tagging, query execution, and a small number of finder-specific actions granted only when the finder that needs them is entitled. No change is made to your infrastructure without your explicit approval of a change template, executed as AWS Systems Manager Automation runbooks inside your own account.

Key principle: The role that executes fixes (cloudfix-ssm-assumed-role) is created by CloudFix but cannot be assumed or accessed by CloudFix — it is invoked only by AWS Systems Manager inside your account. In the default deployment the approver role trusts your account alone, so approval is the control boundary and it stays with you.

Need security documentation?

Request access to our SOC 2 reports, DPA, and other security documents.