ArthaOps
PlatformTrustCase StudiesPricingDocs
Sign InStart Free
ZERO-AGENT READ-ONLY DEPLOYMENT // MULTI-CLOUD IAM & RBAC

Evaluate your multi-cloud environment in under 2 minutes.

Deploy the agentless read-only scanner with zero long-lived credentials stored. Real-time deterministic waste detection across 378 active multi-cloud rules.

Start Free ScanBook Demo
$curl -sSL https://arthaops.com/scan | sh
ArthaOps

Zero-Trust Multi-Cloud Cost Governance Platform. Continuous waste detection, deterministic math & automated remediation.

INSTITUTIONAL FINOPS // ZERO-TRUST ENGINE

01 PLATFORM

Platform OverviewControl RoomCloud TopologyDetector EngineAsset InventoryRemediation EngineSavings IntelligenceDetector CatalogPlatform ComparisonPricing

02 TRUST

Trust CenterSecurity ArchitectureCompliance MatrixSovereign Proxy Guarantee

03 RESOURCES

DocumentationChangelogCase StudiesCustomer GuaranteesROI CalculatorGitHub Repository

04 COMPANY

About UsContact UsEnterprise Sales
45.0°W:117.0mmR:14.0mmH:53.0mmCL:298.0GAP:15.045.0°O-DIAM:117.0P-LOOP:38.0S-END:957.0117.0117.0117.0117.0117.0117.0117.0117.03.03.03.03.03.03.03.0P1P2P3P4P5P6P7P8P9⊕ DATUM-A (0,53)⊕ DATUM-B (957,0)OVERALL WIDTH: 957.00 mm53.00 mmDESIGNED BY ARTHAOPSMISSION CONTROL // CLASS-ATECH SINGULARITYSECTION 9 // ISO-128CAD DWG NO: AO-2026-M290 // SCALE 1:1 // TOLS: ±0.005mm // SHADER: WGL-V2 // CERTIFIED MAXIMUM HIGH-DENSITY CAD SCHEMATIC
© 2026 ArthaOps. Inc. All rights reserved.
SOC2 TYPE II READY // READ-ONLY IAM
Privacy PolicyTerms of ServiceCookie PolicyRefund PolicySystem Status
/////TRUST & COMPLIANCE
[SOC2 TYPE II]

ENTERPRISE TRUST CENTER

Trust, Security & Architecture Portal

Designed for technical evaluations & security reviews. Zero stored cloud access keys, read-only IAM connectors across AWS, Azure, GCP, and Kubernetes, and sovereign AP-SOUTH-1 data residency.

Capability & Compliance Status Matrix

Explicitly discriminates current implementation facts from roadmap items.

CapabilityCategoryCurrent StatusTechnical & Compliance Scope
AWS STS AssumeRole Cross-Account IntegrationSecurityOK AvailableRead-only IAM AssumeRole delegation with external ID validation.
AES-256 KMS Envelope EncryptionSecurityOK AvailableAWS KMS customer-managed key envelope encryption at rest.
TLS 1.3 In-Transit EncryptionInfrastructureOK AvailableHTTPS TLS 1.3 enforced across all API routes and websocket streams.
AP-SOUTH-1 Mumbai Infrastructure HostingInfrastructureOK AvailableHosted strictly in AWS AP-SOUTH-1 regional infrastructure.
DPDPA 2023 & GDPR Data Minimization ArchitectureComplianceOK AvailableArchitected for privacy alignment via zero credential storage & minimal metadata ingestion.
Immutable Cryptographic Audit LedgerGovernanceOK AvailableHash-chained append-only event ledger logging all detection and execution steps.
SOC 2 Type II CertificationCompliance PlannedIndependent third-party SOC 2 Type II audit planned for Q4 2026.
ISO 27001 CertificationCompliance PlannedInformation security management system certification roadmap.

Explained Least-Privilege IAM Policy Inspector

Every permission requested is bound strictly to a specific waste detector feature.

sts:AssumeRoleFeature: Cross-Account Integration
Why requested: Generates temporary, short-lived security tokens for agentless scanning.
Impact if omitted: Agentless discovery fails; requires storing static IAM access keys (violates security policy).
ec2:DescribeVolumesFeature: Detector #102 (Unattached EBS Volume)
Why requested: Inspects volume state (available/in-use) and attachment timestamp.
Impact if omitted: Unattached EBS waste detector cannot inspect block storage.
rds:DescribeDBInstancesFeature: Detector #104 (Idle RDS Instance)
Why requested: Inspects database instance status, engine class, and endpoint identifiers.
Impact if omitted: Idle database waste detector cannot inspect RDS instances.
cloudwatch:GetMetricDataFeature: Resource Utilization Telemetry
Why requested: Retrieves 30-day P95 CPU, IOPS, and network throughput CloudWatch metrics.
Impact if omitted: Overprovisioned resource detectors cannot perform P95 utilization math.

Self-Describing Proof Assets Library

Technical evidence artifacts with explicit representation metadata.

Executive Multi-Cloud & AI FinOps Optimization ReportPDF

Demonstrates executive summary layout, spend breakdown, and monthly waste recovery roadmap across AWS, Azure, GCP, and K8s.

Representation: Representative Sample (Executive Audience)
Download PDF Asset →
Cryptographic Audit Ledger ExportJSON

Illustrates JSON structure of hash-chained audit events, actor sign-offs, and state transitions.

Representation: Test Environment Output (Security Audience)
Download JSON Asset →
AWS STS Least-Privilege IAM Policy TemplateJSON

CloudFormation / Terraform template defining exact AssumeRole read-only permissions.

Representation: Test Environment Output (Engineering Audience)
Download JSON Asset →
Azure ARM Reader Least-Privilege Role DefinitionJSON

Bicep / Terraform definition granting read-only inspection across Azure Subscriptions and Management Groups.

Representation: Test Environment Output (Engineering Audience)
Download JSON Asset →
GCP Workload Identity Least-Privilege BindingJSON

Terraform template configuring short-lived credential exchange for GCP Resource Manager and Compute viewer.

Representation: Test Environment Output (Engineering Audience)
Download JSON Asset →
Kubernetes Read-Only ClusterRole ManifestJSON

Standard Kubernetes YAML manifest defining read-only ClusterRole for pods, PVCs, nodes, and daemonsets.

Representation: Test Environment Output (Engineering Audience)
Download JSON Asset →
Multi-Cloud Agentless Architecture & Data Flow DiagramPNG

Visualizes network boundaries, AWS STS, Azure ARM, GCP Workload Identity, K8s RBAC, and AP-SOUTH-1 hosting.

Representation: Representative Sample (Engineering Audience)
Download PNG Asset →

Security & Compliance FAQs

Q: Does ArthaOps store long-lived AWS IAM access keys?
No. ArthaOps uses AWS STS AssumeRole cross-account delegation with External ID validation. Zero long-lived AWS access keys or secrets are stored in our systems.
Q: Where is customer telemetry data stored?
All telemetry metadata is hosted strictly in AWS AP-SOUTH-1 (Mumbai) infrastructure, encrypted at rest using AES-256 KMS keys and in transit via TLS 1.3.
Q: Can ArthaOps modify my production infrastructure during a preflight scan?
No. Preflight scans execute strictly within read-only IAM AssumeRole permissions (List* and Describe*). Zero production changes are made during preflight evaluation.
Schedule Architecture & Security Review