Company Overview

Legal entity Aurea, Inc.
Product CloudFix — automated AWS cost optimisation platform
Headquarters United States
Platform hosting Amazon Web Services, us-east-1 (N. Virginia)
AWS partner status ISV Accelerate Partner · Cloud Operations Competency (Cost Management)
Certifications SOC 2 Type 2 · FinOps Certified Platform
AWS Marketplace View CloudFix on AWS Marketplace →

Service Description

CloudFix is a SaaS platform that automatically identifies and implements AWS cost optimisation opportunities across your AWS estate. It operates via a secure read-oriented IAM role model deployed into your AWS account via CloudFormation StackSet — no agents, no third-party software, only AWS-native services.

Finders

75+ automated analysers scan your AWS account metadata — Cost & Usage Reports, CloudWatch metrics, resource configuration — to identify cost savings opportunities across 30+ AWS services.

Fixers

For each opportunity you choose to act on, CloudFix generates a change template through AWS Systems Manager. Changes execute only after your explicit approval — never automatically.

RightSpend

An optional module for Reserved Instance and Savings Plan management, providing automated purchase recommendations and RI conversion optimisation.

API & Integrations

A REST API and outbound webhook capability enable integration with ITSM and service desk platforms, allowing recommendations to flow through existing approval workflows.

What CloudFix accesses in your AWS account

  • AWS Cost and Usage Reports (CUR) — billing and usage metadata only
  • CloudWatch metrics — performance and utilisation data for optimisation analysis
  • CloudTrail logs — read access for audit and recommendation context
  • Resource metadata via Describe/List/Get API calls — no access to application data, S3 object contents, or database records
CloudFix deploys no user agents or third-party code into your AWS account. All activity within your account uses AWS-native services only (CUR, CloudWatch, S3, Athena, Glue, Lambda, SSM, CloudFormation).

Support Model

Support Channels

ChannelPurposeAvailability
Support portal Primary channel for all support requests, product questions, and incident reporting. Powered by Kayako. support.cloudfix.com
Trust Center contact form Security concerns, compliance queries, documentation requests, vulnerability reports. trust.cloudfix.com/contact
In-app support Contextual help and ticket submission from within the CloudFix dashboard. Available when logged in

Support Coverage

CloudFix provides support during standard business hours (09:00–18:00 ET, Monday–Friday). Critical incidents (P1) are monitored outside business hours with on-call escalation.

Service Level Commitments

Platform Availability

  • CloudFix Dashboard: 99.9% uptime target (measured monthly, excluding maintenance windows)
  • API: 99.9% uptime target
  • Scheduled maintenance: Communicated at least 72 hours in advance; typically performed 02:00–04:00 UTC
  • Exclusions: AWS infrastructure incidents, force majeure, customer-caused outages

Incident Response SLA

Priority Definition Initial response Resolution target
P1 — Critical Platform completely unavailable or data integrity risk; no workaround 1 hour 4 hours
P2 — High Significant feature impairment; partial workaround available 4 business hours 2 business days
P3 — Medium Non-critical issue; workaround available 1 business day 5 business days
P4 — Low General questions, feature requests, documentation queries 2 business days Best efforts

Business hours: 09:00–18:00 ET, Monday–Friday, excluding US public holidays. P1 incidents are monitored on-call outside business hours.

Escalation Path

LevelContactTrigger
Level 1 CloudFix support team via support.cloudfix.com All initial requests
Level 2 Senior support engineer (auto-escalated for P1/P2 after initial response SLA) P1 unresolved > 2 hours · P2 unresolved > 1 business day
Level 3 Engineering team lead P1 unresolved > 4 hours · complex technical issues requiring engineering involvement
Security escalation Security team via Trust Center contact form Any security incident or vulnerability report

Incident Management

CloudFix follows a structured incident management process aligned with SOC 2 requirements.

Incidents are detected via automated monitoring alerts, customer reports, or internal escalation. On detection, an incident commander is assigned and the incident is classified P1–P4 based on impact and scope.

  • Service incidents (P1/P2): Status page updated within 30 minutes of confirmed incident. Affected customers notified via in-app notification and/or email.
  • Security incidents: Affected customers notified within 24 hours of confirmed security incident, regardless of severity.
  • Data breaches: Notification within 72 hours as required by applicable regulations, with full incident details provided as they become available.

Following resolution of P1/P2 incidents, a post-incident review (PIR) is conducted within 5 business days. The PIR documents root cause, contributing factors, timeline, and corrective actions. Summaries are available to customers on request.

All production changes follow a defined change management process: peer review, staging environment testing, and phased rollout. Emergency changes require post-implementation review. Scheduled maintenance is communicated at least 72 hours in advance via the status page.

Vulnerability Management

Internal Programme

  • Regular third-party penetration testing — results available under NDA (request via Compliance page)
  • Continuous automated dependency scanning for known CVEs
  • Internal security assessments aligned with SOC 2 requirements
  • Patch management policy: critical CVEs remediated within 30 days of disclosure; high within 60 days

Responsible Disclosure

CloudFix operates a responsible disclosure programme. If you believe you have identified a security vulnerability:

  1. Submit details via the Trust Center contact form, selecting Vulnerability Report as the subject.
  2. Include a clear description of the vulnerability, steps to reproduce, and potential impact.
  3. CloudFix will acknowledge receipt within 24 hours and provide an initial assessment within 72 hours.
  4. We request a 90-day disclosure window from initial report to allow for remediation before any public disclosure.
  5. Coordinated disclosure is welcomed — we will keep you informed of remediation progress and notify you when a fix is deployed.
CloudFix does not currently operate a formal bug bounty programme. All responsible disclosure reports are handled directly by the security team.

Questions about our support model?

Contact the CloudFix team for enterprise SLA terms or to discuss specific support requirements.

Contact Us