CCCloud Complianceby CloudAudit
Open demoRequest audit

Inside CloudAudit

CloudAudit features

Trace cloud inventory, identity, cost and compliance evidence in one workspace. Missing data stays visible and production changes stay under human control.

Sample data only. The public demo does not yet include the new Governance or Compliance Automation workspaces. These require an updated, authenticated platform deployment.

Cloud estate

Know what is connected, and what is still unknown.

Discovery begins with a validated, read-only cloud identity. Partial scans and permission gaps remain visible instead of becoming assumed coverage.

Connected inventory

Search AWS, Azure and Google Cloud resources, then move into Environment X-Ray for account, network, exposure and service context.

Organisation onboarding

Discover child accounts, subscriptions or projects from a validated parent scope. Administrators select what to prepare; discovery never silently connects every account.

Identity evidence

Review AWS IAM and MFA signals, Azure role assignments and Google Cloud IAM bindings with explicit unknown states when permissions or evidence are missing.

Compliance and assurance

Show the evidence behind each control outcome.

The workbench links observed technical outcomes to selected framework mappings without treating a passing check as certification.

Control coverage

Inspect retained provider evidence across technical controls and selected CIS, SOC 2, ISO 27001, POPIA, HIPAA and NIST mappings. Unknown and uncollected outcomes remain distinct.

Evidence-led findings

Filter by account, framework and outcome; trace captured properties to resources and governed remediation cases. Partial scans never imply a pass.

Verifiable assurance

Generate evidence-bound PDF packs with checksums and verification references. Signing and previous-pack chain links are available when signing is configured.

FinOps and Kubernetes

Explain spend before promising savings.

Cost views use retained billing evidence, not estimates derived from inventory. Currencies stay separate and coverage gaps stay visible.

Billing and reports

Import validated billing data or configure read-only native collection from AWS, Azure and Google Cloud. Explore trends, services and billable items and export scoped PDF reports.

Budgets and planning

Track scoped budgets, forecasts, anomalies and commitment evidence. Planning scenarios are decision support, not guaranteed savings.

Kubernetes context

Join EKS, AKS and GKE inventory to risk signals. Workload allocation appears only when an OpenCost source is configured; unpriced clusters stay unpriced.

Governed response

Move from a finding to accountable work.

Automation can prepare the next step, while ownership, exceptions and final closure remain reviewable human decisions.

Remediation and retesting

Cases retain owners, due dates, evidence, retests and time-bound risk decisions. A passing retest does not close a case without separate approval.

Compliance automation

Scoped rules can respond to new or recurring findings, missing evidence, expiring exceptions and SLA breaches with alerts, cases, retests or assurance packs. No cloud resources are changed.

Client and ticket workflows

Isolate client workspaces by membership and role. Validated Jira, ServiceNow, Azure DevOps, GitHub or GitLab connectors can link external tickets to retained cases.

Governed AI analysis

Optional AI providers analyse bounded retained evidence with provenance and human review. AI cannot approve infrastructure changes, close findings or claim certification.

Evidence boundary

Coverage is explicit, not assumed.

Live results depend on validated connections, provider permissions and configured integrations. Unsupported or failed collectors remain unknown. CloudAudit does not make production changes from these read-only reviews.

Discuss your cloud estate