Multi-cloud, multi-IaC — the audit trail is the product.
Tallywyrm runs inventory across AWS, GCP and Azure and ships rightsizing PRs into the Terraform, Pulumi or Crossplane repo you already maintain. Bring your own cloud credential, pay a percentage of verified savings, and read the same audit trail the finance and security teams already reconcile against.
Early-access teams get pricing tiers and the weekly-report digest before the public launch.
Six connectors, one audit trail.
AWS, GCP and Azure for inventory and rightsizing; Terraform, Pulumi and Crossplane as the PR targets the agent opens against your existing repo. Every card on this page links to a procurement summary your security and finance teams reconcile against.
Merge loop & OIDC trust on /faq.
EC2, RDS, ECS, Lambda, S3 & EFS inventory on a daily cadence.
- Read-only scope against Cost Explorer, the AWS Price List API and the granted accounts.
- Instance-family rightsizing for EC2 (graviton + x86), Lambda memory/concurrency and RDS instance classes.
- Idle and underused coverage for S3 buckets, EFS file systems and ECS services running below a configurable floor.
Compute Engine, GKE, Cloud SQL, Cloud Run and BigQuery inventory.
- Read-only scope against BigQuery billing export, Cloud Billing API and the granted projects.
- Rightsizing families for Compute Engine machine types, GKE node pools and Cloud SQL tiers.
- Idle coverage for idle Cloud Run services, unused BigQuery slots and disk snapshots older than 90 days.
Virtual Machines, AKS, SQL DB, App Service and Storage inventory.
- Read-only scope against the Azure Cost Management API, the Advisor API and the granted subscriptions.
- Rightsizing families for VM SKUs, AKS node pools, SQL DB tiers and App Service plans.
- Idle coverage for unattached disks, deallocated VMs and storage accounts below the access-floor reading.
Rightsizing PRs as scoped `.tf` diffs.
- Format is a real HCL diff against the resource(s) the audit pass identified, ready for `terraform plan` in CI.
- The agent opens the PR in your repo using the GitHub / GitLab credential your platform team already grants.
- Merge loop is PR → human approver → merge → post-deploy measurement → weekly report.
- No state changes, no apply against your account — only the diff lands in your repo, you control the apply step.
Rightsizing PRs as scoped `.ts` programs.
- Format is a typed Pulumi program against the same resource family Terraform covers, importable from any language.
- The agent opens the PR in your repo using the same GitHub / GitLab credential as the Terraform flow.
- Same merge loop as Terraform: PR → human approver → `pulumi up` from your CI → post-deploy measurement.
- No stack mutations, no out-of-band `pulumi destroy` — the recommending agent never touches your state backend.
Rightsizing PRs as scoped `Composition` patches.
- Format is a K8s manifest patch against the ManagedResource(s) the audit pass identified, ready for `kubectl diff`.
- The agent opens the PR in your repo using the same credential flow as Terraform and Pulumi.
- Same merge loop: PR → human approver → your GitOps controller reconciles → post-deploy measurement.
- No provider credentials — the agent only edits the manifest in your repo; the controller you run does the apply.
Rightsizing PRs land directly in each IaC runner.
The audit pass identifies a resource family. The agent opens a small, reversible PR in the repo you already own. Reviewer signs; your CI reconciles; the audit trail feeds the weekly report.
Full merge loop and credential model on /faq and /security-and-compliance.
- 01Hourly audit pass ranks the resource family
AWS, GCP and Azure inventory sees the oversize, the idle and the underused. Only resource families with a verified saving score above the fleet land in the queue.
- 02Agent opens a scoped PR in the repo you already own
The agent opens a small, reversible PR against your Terraform, Pulumi or Crossplane repo using the GitHub / GitLab credential your platform team already grants — brokered through your OIDC trust, never a long-lived static key.
- 03PR → human approver → merge → your CI reconciles
A reviewer signs off; Terraform, Pulumi or your GitOps controller applies the change. The agent never touches state, never assumes an admin role, never escalates across accounts.
- 04Post-deploy measurement feeds the weekly report
Realized dollars write themselves into the audit trail: PR, deploy timestamp, delta and verified saving. The same export finance, security and procurement already reconcile against.
One signup. Six connectors. Verified savings.
Create an account, broker the OIDC trust for the cloud accounts you want covered, and the first scoped PR lands the same day. Pay a percentage of verified savings; finance reconciles against the same audit trail the SOC 2 and CSRD evidence exports already accept.
Early-access teams get pricing tiers and the weekly digest before launch.
No account needed. The same list finance and platform leads get pulled from at the start of a workspace.