AI for IT operations · One console across your clouds

One AI console for AWS, Azure and GCP

Your inventory, your security findings and your remediations across every cloud, in one place, with the three providers treated the same way. Self-hosted, and nothing changes without your approval.

AWS, Azure and GCP · Self-hosted · Zero telemetry · Free forever tier

What is AI CloudOps?

AI CloudOps is AI for IT operations across every cloud: an autonomous agent that runs multi-cloud IT operations from one console, with a unified inventory across AWS, Azure and GCP, correlated security and cost findings, and remediation through each cloud's own APIs. NudgeBee runs in your environment and applies every change only after human approval.

One console across every cloud
Three clouds, one modelAWS, Azure and GCP, plus Cloud Foundry, collected through one pipeline into one data model and one recommendation taxonomy.
One graphResources and their real dependencies are linked across accounts and clouds, so a finding in one account can be traced to the workload it affects in another.
In your environmentLeast-privilege onboarding, credentials encrypted at rest, and nothing shipped to a third party.

Every account, every cloud, one inventory

Instead of three consoles and three mental models, you get one list of what exists, where, and in what state.

  • Dozens of AWS service scanners, the deepest coverage of the three clouds.
  • Broad Azure coverage across the estate.
  • GCP, read through the same single collector.
  • Everything normalised into one data model and one recommendation taxonomy.
A unified cloud inventory across AWS, Azure and GCP, showing resource counts per service for each account plus month-to-date and forecast spend, 2,847 resources discovered agentless.
A unified security findings queue across three clouds, with GuardDuty, Azure Defender, Sentinel, Inspector, Security Hub and GCP SCC signals normalised and ranked by severity, account and cloud.

Security findings from every cloud, in one queue

Findings are ranked in the same queue as everything else, so a critical exposure in a rarely-watched account does not sit unseen in a console nobody opens.

Native security signals, normalised into one queue:
  • AWS GuardDuty
  • Inspector
  • Security Hub
  • Azure Defender
  • Sentinel
  • Kubernetes RBAC
  • CIS benchmarks

It connects resources across accounts, not just within them

A knowledge graph links resources and their real dependencies across accounts and clouds, using a set of default cross-account rules.

That means a change or failure in a shared service can be traced to everything downstream of it, even when the downstream sits in a different account or a different cloud. One graph spans AWS, Azure and GCP, so a dependency does not fall out of view just because it lives in another team's account.

A cross-account dependency graph for a shared payments-db, showing four dependents across three accounts and two clouds, with cross-account and cross-cloud READS_FROM edges drawn from network flows and IAM.
A remediation queue with two fixes awaiting approval: an S3 encryption fix that applies via an s3:PutBucketEncryption cloud API call, and a security group fix on a Terraform-managed resource that opens a pull request instead.

Fixes applied through each cloud's own APIs

When you approve a change, NudgeBee applies it the native way. Apply coverage varies by service, so major services are supported directly and everything else lands as a pull request. Every change is approval-gated.

  • A cloud API change for supported services on AWS, Azure and GCP, through the provider API.
  • A Kubernetes patch applied to the deployment in your cluster.
  • A pull request raised against your infrastructure repository, the GitOps way.

The same console surfaces cost optimisation findings and incident investigations, so a cloud team does not switch tools to see spend, security and reliability across every cloud. Go deeper on cost with AI FinOps and on incidents with AI SRE. CloudOps is the breadth layer over both, in one place.

Cost and incidents share the same pane

One console for spend, security and reliability across every cloud, so the team stops switching tools to get the full picture.

It reads freely. It changes nothing without you.

Two modes, drawn at the tool layer, not left to the model's judgement.

Reads

Reads every cloud without asking

Read-only reads run without asking, so building the picture across your clouds is never slowed by a prompt.

Writes

Gated behind your approval

Every create, update and delete is classified at the tool layer and gated behind explicit human approval.

No self-granted access

The agent is forbidden from modifying IAM or RBAC to grant itself access it lacks.

It does the work, not you

It never asks you to go and run commands yourself.

Untrusted by default

All tool output is treated as untrusted input, a deliberate prompt-injection defence.

Approvals arrive where the team already works:
  • Slack
  • Microsoft Teams
  • Google Chat
  • Signed link

Your cloud data does not leave your environment

Self-hosted

Runs in your own environment.

Zero telemetry

Nothing shipped to a third party.

Outbound only

The in-cluster agent dials out only. No inbound ports, no exposed API server, no VPN.

Least-privilege onboarding

AWS onboarding via STS AssumeRole with an External ID. Credentials encrypted at rest with AES-256-GCM.

Bring your own model

Nine provider routes across AWS Bedrock, OpenAI, Azure OpenAI, Google AI, Vertex AI, SageMaker, HuggingFace and Anthropic.

Readable source

Read the implementation, with a free Community edition.

CloudOps FAQ

Frequently asked questions

For the lead who has to answer for every cloud at once.

Book a Demo
AI CloudOps is the use of an autonomous agent to run multi-cloud operations from one console: a unified inventory across AWS, Azure and GCP, correlated security and cost findings, and remediation applied through each cloud's own APIs. It runs in your environment, reads freely, and applies every change only after human approval.
A CSPM shows posture and a cloud management tool shows inventory, and both usually leave the fix to you, per cloud. NudgeBee unifies inventory, security and cost across AWS, Azure and GCP in one queue, correlates findings across accounts, and applies the remediation on approval through each cloud's native API.
AWS, Azure and GCP, plus Cloud Foundry, collected through one pipeline into one data model and one recommendation taxonomy. Instead of three consoles and three mental models, you get one. AWS has the deepest service coverage of the three, which the collector reflects honestly.
Same platform, different job. AI SRE goes deep on incidents and AI FinOps goes deep on cost. CloudOps is the breadth layer: one console across every cloud for inventory, security and remediation, with the depth of the other two assistants available in the same place when you need it.
Only with your approval. Read-only reads run freely, but every create, update or delete is classified at the tool layer and gated behind explicit human approval, delivered in Slack, Teams, Google Chat or a signed link. The agent cannot grant itself permissions it does not already have.
Native signals from each cloud, normalised into one queue: AWS GuardDuty, Inspector and Security Hub; Azure Defender and Sentinel; plus Kubernetes RBAC analysis and CIS benchmark scans. A critical exposure in a rarely-watched account is ranked alongside everything else, not left in a console nobody opens.
Yes. A knowledge graph links resources and their real dependencies across accounts and clouds, using a set of default cross-account rules. A change or failure in a shared service can be traced to everything downstream of it, even when the downstream sits in a different account or a different cloud.
No. NudgeBee is self-hosted in your own environment with zero telemetry, and your inventory, security and cost data is read in place. AWS onboarding uses least-privilege STS AssumeRole with an External ID, so you are not handing over long-lived credentials.
Yes. The full implementation is readable: the agent architecture, the prompts and the quality gates. You can self-host it in your own cluster and run it in production internally for free, on a free Community edition covering up to two clusters or cloud accounts.
There is a free forever tier covering up to two cloud accounts, with no credit card required. CloudOps is part of the platform every paid plan includes, alongside the other assistants, and paid plans are detailed on the pricing page. You can validate it against your own accounts first.
Free forever · No credit card

Put every cloud in one console.

Free forever on up to 2 cloud accounts. No credit card. Self-hosted, so nothing leaves your environment.

Read the source on GitHub