RESOURCES · CLOUD MAP
See your cloud as it really is.
Cloud Map reads your AWS and Google Cloud accounts and draws their resources, the connections their settings prove, internet exposure and known cost. Azure and DigitalOcean are coming next.
What Zaysa readeu-west-2
thumbs: Not priced. · no price available for this resource
- 01Reading your AWS account
- 02Every resource becomes a box
- 03Lines only where a setting proves them
- 04What is open to the internet
- 05The proof behind a line
- 06Cost on every box
- 07Honest about gaps
Example data. From an AWS account.
How it works
From read-only scan to map
Connect your clouds
Connect AWS or Google Cloud through keyless federation. Azure and DigitalOcean Cloud Map support is coming next.
Example data.
Zaysa reads, read-only
See every service and region read, including denied and unavailable reads.
Example data.
Search and explore
Find a resource by name, id, IP or tag, then inspect its settings and proven connections.
Example data.
Proven connections
Two kinds of lines, never guessed
Configured: A setting points here. Allowed: Network rules allow this. It does not prove that traffic actually flows.
Allowed appears only when network rules permit a path. It shows the port. If only some placements are reachable, the map says “Only some placements are reachable.” You can switch each line kind on and off.
sg-db ingress 5432 from sg-web
network ACL rule 100 allow 5432
route local 10.0.0.0/16
Example data.
Exposure
Open to the internet, with the ports
See which resources are open to the internet and the ports involved. Private resources stay distinct from internet exposure.
shop-alb · 443 · from 0.0.0.0/0
web · not reachable from the internet
orders-db · not reachable from the internet
sessions · not reachable from the internet
Example data.
Evidence
Every line has its proof
Click a box to see where it lives, its cost, proven connections and settings. Click a line for the exact settings and values that prove it. Search by name, id, IP or tag.
Allowed · port 5432
Network rules allow this. It does not prove that traffic actually flows.
sg-web egress all → sg-db
sg-db ingress 5432 from sg-web
network ACL rule 100 allow 5432
route local 10.0.0.0/16
Example data.
Permissions
Read-only by design
Cloud Map reads your connected accounts through provider-specific read-only paths. Choose a cloud to see the connection and request limits.
A keyless (federated) connection is required because stored keys cannot be restricted to read-only.
Explicit deny
tag values that look like secrets → [redacted]
The session has an explicit deny on reading data and secrets: log events, queue messages, stream records, secret values, function code, container images and templates. Only display-safe metadata is kept; tag values that look like secrets are redacted.
Example data.
Coverage
Honest about what it could not read
Every service and region read has a count and a status: read, denied, error, timeout or not enabled. Unreadable is not empty. Anything that could not be proven is listed with a reason, never drawn as a line or shown as clean.
Not proven
thumbs → outbound: VPC endpoint policy could not be read (denied)
Example data.
INCLUDED IN FREE
See your cloud on every plan
Cloud Map
See resources, exposure and proven connections.
Cloud History
Review changes and compare scans.
Autopilot
Find issues in the infrastructure you run.
Connectors
Reach private systems through an outbound connection.
Questions
Frequently asked questions
AWS and Google Cloud. Azure and DigitalOcean are coming next.
More in Resources
See what you run, and what it costs.
Free plan, no card needed.