
CloudOps
CloudOps is Trinetri's Cloud Security Posture Management module, detecting misconfigurations, identity risk and exposed resources across AWS, Azure and Google Cloud the moment they appear, then letting GAS ai prioritise what matters and remediate it, on one agentless control plane. This datasheet covers the five core disciplines, how it works in three steps, resource coverage across 192 resource types, and compliance frameworks and industries served.
- 100% asset visibility with normalised inventory across every account, region and provider
- 70% faster remediation through prioritised, automated fixes
- 99% continuous compliance, audit ready against CIS, SOC 2, ISO 27001, PCI DSS and HIPAA
- 30% lower cloud spend by finding and retiring idle, orphaned resources
Cloud Security Posture, Continuously Hardened
Detect misconfigurations, identity risk and exposed resources across AWS, Azure and Google Cloud the moment they appear, then let GAS ai prioritise what matters and remediate it, on one agentless control plane.
- Asset Visibility: 100%, normalised inventory across every account, region and provider
- Faster Remediation: 70%, prioritised, automated fixes replace manual triage queues
- Continuous Compliance: 99%, audit ready against CIS, SOC 2, ISO 27001, PCI DSS and HIPAA
- Lower Cloud Spend: 30%, idle, orphaned and oversized resources found and retired
Live console example: 18,406 resources across 3 providers (AWS 9,842, Azure 5,120, GCP 3,444), a B+ posture score with top findings like a public S3 bucket with no encryption, an IAM role with wildcard policy, and a security group open on port 22, plus $186K/mo FinOps spend with $41K reclaimable that month.
One Control Plane, Five Disciplines
The same normalised inventory feeds posture, compliance and FinOps, so a finding, a control and a cost line all resolve to the same asset, with the same owner.
- Cloud Security Posture Management (Detect, Prioritise, Fix): Continuously assess configuration against best practice benchmarks. Score posture per account and team, rank exposures by real exploitability, and get guided or automated remediation.
- Cloud Asset Inventory (Discover, Normalise, Govern): Auto discover compute, storage, network, identity, container and serverless resources, mapped into one consistent, searchable schema across every account and region.
- Continuous Compliance Assessment (Assess, Evidence, Report): Controls evaluated on every sync, so drift is caught immediately, with audit ready evidence gathered and mapped to each control automatically.
- Cloud Cost Management (Attribute, Reclaim, Forecast): FinOps context on the same inventory you already secure. Idle, orphaned and oversized resources are surfaced continuously with savings quantified by rightsizing.
- GAS AI, Autonomous Cloud Operations (Gather, Analyse, Settle): GAS AI turns the cloud into a system you can talk to: a virtual cloud operations engineer, security analyst and FinOps specialist working 24x7 across posture, compliance and cost, without leaving the console. Capabilities include natural language queries, autonomous remediation, anomaly detection and guided investigation. Ask about assets, risks or spend in plain English, trace any finding to root cause, catch unusual changes before they become incidents, and let approved workflows settle them end to end.
How It Works
From cloud account to settled finding, in three steps.
- 01, Connect, Onboard In Minutes: Add AWS, Azure and Google Cloud accounts through read only roles, no agents, no network changes. (Agentless, Multi account)
- 02, Assess, Unified Control Plane: Every sync rebuilds the normalised asset graph and reevaluates benchmarks, controls and cost, settled by GAS AI. (Asset graph, Continuous rescoring)
- 03, Settle, Resolve Autonomously: Remediation, tickets, evidence and dashboards land via REST API, webhooks or the console, approval gated end to end. (REST API, SSO & SCIM)
Deploy Your Way
- SaaS Control Plane: Fully managed by Trinetri, live in minutes, no infrastructure to run
- Self hosted / on prem: Host the control plane in your own environment for data residency needs
- MSP & MSSP: Client estates isolated per tenant, automated once and published to all
Runs across: AWS, Microsoft Azure, Google Cloud
Every resource, mapped to one schema
Each resource is a registered, continuously synced type, normalised into one searchable schema regardless of provider. 192 resource types synced (AWS 79, Azure 50, GCP 63).
-
Compute: EC2, VM and Compute Engine instances, autoscaling groups, batch compute environments, and PaaS runtimes like Elastic Beanstalk, App Service and App Engine
-
Storage & Backup: S3, Blob and Cloud Storage buckets, block volumes and managed disks, snapshots, file shares, and backup vaults and plans
-
Database: RDS, Azure SQL and Cloud SQL, DynamoDB, Cosmos DB and Firestore, Redshift, Synapse and BigQuery, plus Spanner, DocumentDB and Neptune
-
Networking: VPCs and virtual networks, subnets, security groups, load balancers, NAT and internet gateways, DNS zones, CDN and Direct Connect / ExpressRoute links
-
Containers & Serverless: EKS, AKS and GKE clusters and node pools, container registries, Lambda, Azure Functions and Cloud Functions, plus Cloud Run and App Engine services
-
Identity & Security: IAM users, roles and policies, KMS keys and Key Vault secrets, WAF rules, and threat detection from GuardDuty, Defender for Cloud and Security Command Center
-
Analytics & Integration: Glue, Dataflow and Dataproc pipelines, Kinesis, Event Hubs and Pub/Sub streams, SNS/SQS, Service Bus and EventBridge queues and buses
-
Governance & Monitoring: Config and Policy rules, CloudTrail and Activity Logs, CloudWatch and Monitor alarms, and CI/CD pipelines across CodePipeline, Logic Apps and Workflows
-
Full Fidelity: Every resource carries account, region, tags and its full native payload, synced continuously
-
Safe Deletes: Deletes are soft and swept only after a clean sync, so a failed collection never produces a false delete
-
Growing Coverage: Adding a new resource type requires no core change, so coverage keeps growing release to release
What CloudOps Covers, In Detail
Compliance Frameworks
CIS, SOC 2, ISO 27001, PCI DSS, HIPAA, NIST
Controls are assessed continuously, with evidence gathered and mapped to each control automatically, so posture is always audit ready.
Finding Severity Model
- Critical: Exploitable now, remediate immediately
- High: Viable attack path to sensitive assets
- Medium: Deviation with limited exposure
- Low: Hygiene, scheduled cleanup
Platform
- Providers: AWS, Azure, Google Cloud
- Collection: Agentless, read only API roles
- Cadence: Continuous, every sync
Enterprise Readiness
- Access: SSO, SCIM, role based scoping
- Integration: REST API, webhooks, real time sync
- Certification: ISO certified vendor
Built For Regulated, Multi Cloud Estates
Banking & FS, Retail, Manufacturing, Government, Technology & SaaS, Healthcare, Energy & Utilities, MSP & MSSP
Get Started: See Your Posture In Your Own Cloud
Connect with a read only role and get a scored posture baseline, a normalised inventory and a prioritised remediation plan.
