Connect your cloud
without giving up control.
Read-only by default. Revocable in one click. No agent inside your infrastructure.
Here is why security teams and CTOs trust Thalaxo Cloud before connecting their first account.
Verified by third parties.
Not self-attested.
Certifications take time. Here is what external sources have independently confirmed about Thalaxo Cloud — today.
SaaSHub Approved
Thalaxo Cloud is listed and verified on SaaSHub — an independent software discovery platform. The product exists, ships, and is publicly referenceable before any sales conversation.
Listed on AlternativeTo
Independently listed on AlternativeTo — used by 15 million monthly visitors to find and compare software. Thalaxo Cloud appears as an alternative to Cast AI, CloudZero, AWS Cost Explorer and more.
AWS · Azure · GCP — provider-audited access
Connection uses the native identity federation of each provider. The permission scope is enforced by the provider itself — not declared by Thalaxo Cloud.
What Thalaxo Cloud
cannot do.
By design. These are not missing features — they are deliberate constraints embedded in the access model.
Access your root account or admin credentials
Modify, create, or delete infrastructure in OBSERVER mode
Store long-term provider credentials as a primary path
Act autonomously on your infrastructure without your explicit confirmation
Lock you into proprietary data formats or infrastructure
Discover and inventory all resources across AWS, Azure, GCP
Detect idle, oversized, and orphaned resources with cost estimates
Start, stop, resize instances — after you explicitly grant SCHEDULER or BUILDER level
Export infrastructure as Terraform HCL — the code stays yours
Log every action: who, when, IP address, before/after state
Encryption everywhere
Standardized protection across every layer — in transit and at rest.
You can remove Thalaxo Cloud’s access in one click.
We purge your secrets immediately.
You get step-by-step teardown instructions.
No ticket. No migration project.
Revoke in Thalaxo Cloud console
Single button disconnect.
Secrets purged immediately
Vault wiped. KMS key context invalidated.
Provider teardown instructions
AWS CloudFormation / Azure role / GCP WIF — clean on your side too.
Architecture first.
Audits second.
SOC 2 Type II
AICPA SSAE 18 — Trust Services Categories: Security, Availability, Confidentiality. Kick-off June 2026. Auditor identity available under NDA.
ISO 27001
ISMS engagement initiated with Univate. Gap assessment and control roadmap underway.
GDPR & Data Residency
AWS eu-west-3 (Paris, France). KMS, S3, backups: Paris region. Your cloud workloads remain in your accounts — Thalaxo Cloud is never a data controller of your infrastructure payloads.
Frequently asked questions
What CTOs and security teams ask before connecting their cloud.
Do you store my AWS access keys?
No — as the recommended path. We use AssumeRole (AWS), delegated roles (Azure), or Workload Identity Federation (GCP). No long-lived access keys stored as primary path. Any credential in transit is envelope-encrypted with AWS KMS and purged on revocation.
Are you SOC 2 certified today?
We are under SOC 2 Type II audit since June 2026. We do not claim a completed Type II report until the auditor issues it. The auditor’s identity is available on request under NDA. Controls are documented, evidenced, and under independent review — not self-attested.
Where is data hosted?
Production target: AWS eu-west-3 (Paris, France) — deployment in progress. KMS, S3, and backups are already in eu-west-3. Your cloud workloads stay in the regions you choose — Thalaxo Cloud never becomes data controller of your infrastructure payloads.
Can we stay read-only forever?
Yes. OBSERVER is the default capability level and is sufficient for all FinOps features: full inventory discovery, cost dashboards, rightsizing insights, and PDF audit reports. Write operations require an explicit upgrade you choose per credential.
What happens if we stop using Thalaxo Cloud?
Revoke credentials in the console → secrets purged immediately → you receive provider-specific teardown instructions (AWS CloudFormation stack delete, Azure role removal, GCP WIF unbind). Your cloud account has no remaining Thalaxo Cloud principal. No migration project required.
Still evaluating?
Choose the level of verification you need.
No pressure. Most teams start with the live demo — then connect a non-production account in read-only.
You stay in control.
At every level.
You decide what Thalaxo Cloud can access — and you can revoke it instantly, without opening a ticket.
- Read-only by default — no write access without your explicit upgrade
- Permissions granted level by level, per cloud account
- Revocable in one click — secrets purged immediately
- No agent running inside your VMs or containers
- No autonomous action without your confirmation
Permission levels
