Multi-cloud, multi-IaC — the audit trail is the product.
Tallywyrm runs inventory across AWS, GCP and Azure and ships rightsizing PRs into the Terraform, Pulumi or Crossplane repo you already maintain. Bring your own cloud credential, pay a percentage of verified savings, and read the same audit trail the finance and security teams already reconcile against.
Early-access teams get pricing tiers and the weekly-report digest before the public launch.
Six connectors, one audit trail.
AWS, GCP and Azure for inventory and rightsizing; Terraform, Pulumi and Crossplane as the PR targets the agent opens against your existing repo. Every card on this page links to a procurement summary your security and finance teams reconcile against.
Merge loop & OIDC trust on /faq.
EC2, RDS, ECS, Lambda, S3 & EFS inventory on a daily cadence.
- Read-only scope against Cost Explorer, the AWS Price List API and the granted accounts.
- Instance-family rightsizing for EC2 (graviton + x86), Lambda memory/concurrency and RDS instance classes.
- Idle and underused coverage for S3 buckets, EFS file systems and ECS services running below a configurable floor.
Compute Engine, GKE, Cloud SQL, Cloud Run and BigQuery inventory.
- Read-only scope against BigQuery billing export, Cloud Billing API and the granted projects.
- Rightsizing families for Compute Engine machine types, GKE node pools and Cloud SQL tiers.
- Idle coverage for idle Cloud Run services, unused BigQuery slots and disk snapshots older than 90 days.
Virtual Machines, AKS, SQL DB, App Service and Storage inventory.
- Read-only scope against the Azure Cost Management API, the Advisor API and the granted subscriptions.
- Rightsizing families for VM SKUs, AKS node pools, SQL DB tiers and App Service plans.
- Idle coverage for unattached disks, deallocated VMs and storage accounts below the access-floor reading.
Rightsizing PRs as scoped `.tf` diffs.
- Format is a real HCL diff against the resource(s) the audit pass identified, ready for `terraform plan` in CI.
- The agent opens the PR in your repo using the GitHub / GitLab credential your platform team already grants.
- Merge loop is PR → human approver → merge → post-deploy measurement → weekly report.
- No state changes, no apply against your account — only the diff lands in your repo, you control the apply step.
Rightsizing PRs as scoped `.ts` programs.
- Format is a typed Pulumi program against the same resource family Terraform covers, importable from any language.
- The agent opens the PR in your repo using the same GitHub / GitLab credential as the Terraform flow.
- Same merge loop as Terraform: PR → human approver → `pulumi up` from your CI → post-deploy measurement.
- No stack mutations, no out-of-band `pulumi destroy` — the recommending agent never touches your state backend.
Rightsizing PRs as scoped `Composition` patches.
- Format is a K8s manifest patch against the ManagedResource(s) the audit pass identified, ready for `kubectl diff`.
- The agent opens the PR in your repo using the same credential flow as Terraform and Pulumi.
- Same merge loop: PR → human approver → your GitOps controller reconciles → post-deploy measurement.
- No provider credentials — the agent only edits the manifest in your repo; the controller you run does the apply.
Reporting, credential model, pricing & compliance.
The six integrations above describe what the agent connects to. The supporting surfaces — weekly report, signed review links, exportable audit trail, bring-your-own credential model, percentage-of-savings pricing and the compliance frameworks the audit trail satisfies — are what finance, security and procurement teams reconcile against.
- Saved-search digest lands in finance inboxes at the same time every Monday morning.
- Each line carries the PR, the deploy timestamp and the percentage-of-savings math.
- Recipient list is editable from the dashboard; the agent never adds a finance address without sign-off.
- Same report-artifact surfaced through a signed, expiring review URL.
- Reviewers see the saving, the diff and the audit trail without a Tallywyrm account; revoking the link closes access.
- Read-only access: nobody signing in through the link can open a PR, edit a policy or rotate a credential.
- Every row ties the saving to a PR, a deploy and a post-deploy measurement.
- Same export format the SOC 2 Type II auditor and the EU CSRD disclosure pack already accept.
- Available from the dashboard and from each weekly email — finance reconcile never blocks on a login.
- Read-only IAM scope against the granted accounts — same wording on /privacy and /security.
- Cost Explorer / Cost Management / BigQuery billing-export read access; no write surface anywhere.
- Brokered through your existing OIDC trust, never a long-lived static key committed to the repository.
- No org-admin or account break-glass role, no role escalation, no cross-account assume into resources you have not already federated.
Full contract and retention windows on /privacy.
8%, 12% or 18% of verified savings. Same integrations across all tiers; the percentage is the only differentiator and the saving is the same formula on /pricing.
Same frameworks the audit trail already satisfies.
SOC 2 Type II, ISO 27001, FedRAMP Moderate and the EU CSRD disclosure pack all accept the same signed CSV export finance teams already reconcile against.
- SOC 2 Type II
- ISO 27001
- FedRAMP Moderate
- EU CSRD
- SEC climate disclosure
- GDPR