Thalaxo

Book a Demo

30 min · Thalaxo FinOps Platform

Loading calendar...

Why trust Thalaxo Cloud ?

Security Center

Connect your cloud
without giving up control.

Read-only by default. Revocable in one click. No agent inside your infrastructure.

Here is why security teams and CTOs trust Thalaxo Cloud before connecting their first account.

No agent on your VMs SaaSHub Approved EU-hosted · Paris SOC 2 Type II — audit in progress
Independent validation

Verified by third parties.
Not self-attested.

Certifications take time. Here is what external sources have independently confirmed about Thalaxo Cloud — today.

AWS · Azure · GCP — provider-audited access

Connection uses the native identity federation of each provider. The permission scope is enforced by the provider itself — not declared by Thalaxo Cloud.

AWS AssumeRole Azure ARM Delegation GCP Workload Identity
Validation roadmap
SOC 2 Type II — audit in progress (kick-off June 2026) ISO 27001 — gap assessment underway, target Dec 2026 G2 — pending first reviews
Capability boundary

What Thalaxo Cloud
cannot do.

By design. These are not missing features — they are deliberate constraints embedded in the access model.

Cannot

Access your root account or admin credentials

Modify, create, or delete infrastructure in OBSERVER mode

Store long-term provider credentials as a primary path

Act autonomously on your infrastructure without your explicit confirmation

Lock you into proprietary data formats or infrastructure

Can — when you choose to

Discover and inventory all resources across AWS, Azure, GCP

Detect idle, oversized, and orphaned resources with cost estimates

Start, stop, resize instances — after you explicitly grant SCHEDULER or BUILDER level

Export infrastructure as Terraform HCL — the code stays yours

Log every action: who, when, IP address, before/after state

Permission levels — you set the ceiling
OBSERVER
Read-only · default
SCHEDULER
Start / Stop
BUILDER
Resize + Snapshots
AUTOPILOT
Terminate · triple confirm

Encryption everywhere

Standardized protection across every layer — in transit and at rest.

Layer Standard
Data in transit TLS 1.3
Data at rest AES-256-GCM + AWS KMS
Databases LUKS disk encryption (PostgreSQL + TimescaleDB)
Backups AWS S3 SSE — eu-west-3 (Paris)
Sessions & tokens Hash-only — no plaintext in DB

You can remove Thalaxo Cloud’s access in one click.

We purge your secrets immediately.

You get step-by-step teardown instructions.

No ticket. No migration project.

1

Revoke in Thalaxo Cloud console

Single button disconnect.

2

Secrets purged immediately

Vault wiped. KMS key context invalidated.

3

Provider teardown instructions

AWS CloudFormation / Azure role / GCP WIF — clean on your side too.

Compliance roadmap

Architecture first.
Audits second.

We believe trust is earned through technical constraints, not certification claims. The access model, the permission levels, and the revocation mechanism exist independently of any audit. The certifications below make that verifiable by an independent third party.
Audit in progress

SOC 2 Type II

AICPA SSAE 18 — Trust Services Categories: Security, Availability, Confidentiality. Kick-off June 2026. Auditor identity available under NDA.

Target: H1 2027
Gap assessment underway

ISO 27001

ISMS engagement initiated with Univate. Gap assessment and control roadmap underway.

Target: December 2026
EU hosted

GDPR & Data Residency

AWS eu-west-3 (Paris, France). KMS, S3, backups: Paris region. Your cloud workloads remain in your accounts — Thalaxo Cloud is never a data controller of your infrastructure payloads.

Active — deployment in progress

Frequently asked questions

What CTOs and security teams ask before connecting their cloud.

Do you store my AWS access keys?

No — as the recommended path. We use AssumeRole (AWS), delegated roles (Azure), or Workload Identity Federation (GCP). No long-lived access keys stored as primary path. Any credential in transit is envelope-encrypted with AWS KMS and purged on revocation.

Are you SOC 2 certified today?

We are under SOC 2 Type II audit since June 2026. We do not claim a completed Type II report until the auditor issues it. The auditor’s identity is available on request under NDA. Controls are documented, evidenced, and under independent review — not self-attested.

Where is data hosted?

Production target: AWS eu-west-3 (Paris, France) — deployment in progress. KMS, S3, and backups are already in eu-west-3. Your cloud workloads stay in the regions you choose — Thalaxo Cloud never becomes data controller of your infrastructure payloads.

Can we stay read-only forever?

Yes. OBSERVER is the default capability level and is sufficient for all FinOps features: full inventory discovery, cost dashboards, rightsizing insights, and PDF audit reports. Write operations require an explicit upgrade you choose per credential.

What happens if we stop using Thalaxo Cloud?

Revoke credentials in the console → secrets purged immediately → you receive provider-specific teardown instructions (AWS CloudFormation stack delete, Azure role removal, GCP WIF unbind). Your cloud account has no remaining Thalaxo Cloud principal. No migration project required.

Client control

You stay in control.
At every level.

You decide what Thalaxo Cloud can access — and you can revoke it instantly, without opening a ticket.

  • Read-only by default — no write access without your explicit upgrade
  • Permissions granted level by level, per cloud account
  • Revocable in one click — secrets purged immediately
  • No agent running inside your VMs or containers
  • No autonomous action without your confirmation
Access expands only when you explicitly choose it. The default is always the most restrictive level.

Permission levels

OBSERVER
Read-only inventory, dashboards, FinOps insights default
No mutations possible at this level
SCHEDULER
Start / Stop / Restart instances
Explicitly granted per account — never automatic
BUILDER
Resize instances + create snapshots
Explicitly granted per account — never automatic
AUTOPILOT
Terminate instances
Triple confirmation required — always human-initiated
The people behind the product

Built by cloud operators.
For cloud operators.

N
“We built Thalaxo Cloud to solve a problem we faced ourselves: cloud spend nobody owns, waste nobody sees, and tools that act without asking. You shouldn’t need to trust a black box. You should be able to verify every permission, every action, every cost.”
Nabil H. — Founder & CEO, Thalaxo Cloud
Nuvelia SAS · Versailles, France
Multi-cloud practitioner · AWS · Azure · GCP
Talk directly with the founder — 15 min
Open to security questions
You can ask Nabil directly about the IAM model, secret storage, or any technical constraint — before connecting a single account.
EU-based, GDPR by default
Nuvelia SAS — Versailles, France. Infrastructure hosted in AWS eu-west-3 (Paris). Your data never leaves the EU without your consent.
Direct security contact
[email protected] — responded personally. No support queue, no bot, no 72-hour SLA on a security question.