Technical FAQ & knowledge base
Everything you need to know about ArthaOps IAM security, 378 cost detectors, Autopilot remediation, and billing.
ArthaOps connects via agentless read-only protocols: AWS STS AssumeRole with ExternalID, Azure ARM Reader roles, GCP Workload Identity federation, and Kubernetes read-only ClusterRoles. You deploy lightweight least-privilege connectors using Terraform, CloudFormation, Bicep, or Helm. ArthaOps never requests permanent access keys, passwords, or root credentials.
Not by default. ArthaOps IAM policies are bounded strictly to read-only telemetry scans (Describe* and List* APIs only): the scanner's role grants no APIs that can delete, alter, or reboot resources. Write access exists only if you explicitly enable Autopilot remediation with pre-flight snapshots.
All resource metadata and audit logs are stored securely in the AP-SOUTH-1 (Mumbai) sovereign region under DPDPA 2023 and GDPR guidelines. No customer telemetry leaves sovereign jurisdiction.
Preflight telemetry scans run continuously on a configurable schedule: ranging from daily on Control plans to hourly on Operator plans and real-time 15-minute event-driven monitoring on Command plans.
ArthaOps detectors are engineered specifically for federated multi-cloud and Kubernetes environments. Our stateless execution engine evaluates AWS, Azure, GCP, and Kubernetes resources in seconds without exceeding provider API rate limits.
Autopilot allows 1-click execution or fully autonomous remediation of flagged waste (e.g. stopping idle RDS instances, deleting unattached EBS volumes). Every action generates a SHA-256 hash-chained audit record and deterministic rollback state.
ArthaOps is designed for alignment with India DPDPA 2023 and EU GDPR, with an audit trail built for SOC 2 Type II evidence generation. Payment processing is handled securely via Razorpay PCI-DSS Level 1 infrastructure.
If you subscribe to any paid plan and feel it hasn't delivered value, email billing@arthaops.com within 14 days for a 100% full refund.
Our engineering team is ready to assist with custom IAM policy reviews and architecture questions.
Contact Engineering Team →