A single percentage of verified savings, paid out of the cloud bill first.
Three tiers — Starter, Growth and Enterprise. Three numbers — 8 %, 12 % and 18 %. The share is the only thing that varies. Same audit gate, same artifact, same audit trail. The service is paid only out of savings that survived the post-deploy measurement window.
How we calculate savings
The 8 % / 12 % / 18 % tier reads from the verified pool only — one PR, one deploy timestamp, one measurement window per saving. Full methodology.
- One PR per saving · one deploy timestamp · one measurement window.
- Forecast and realized are surfaced separately — a forecast cannot pass for a saving.
- The audit row is sha256-sealed; the weekly CSV is the byte-for-byte projection.
- What does NOT count as verified, and why — read the boundary in one glance.
tier % × verified savings. Nothing else.
Three sentences that name the model, the gate and the guardrail. The verified pool is the first column; the tier is the second. /methodology names the gate.
The invoice is a single percentage of one number: the verified pool. The verified pool is the sum of cents that survived the post-deploy measurement window on the audit row — the same row finance signs off on and the same row the Scope 3 category 1 carbon report reads from.
Pick the tier that matches the size of your verified-savings programme. Share is the only variable that lands on the invoice — same audit gate, same artifact, same audit trail across Starter, Growth and Enterprise. The dollar, the carbon and the PR travel as one.
No verified savings = no charge. Month-to-month, no auto-renewal, no claw-back on a previously sent invoice. If a workload stops producing savings, the share on your next invoice drops to zero the same week.
- diff → IaC PR opens
A rightsizing recommendation becomes a scoped pull request against your Terraform, Pulumi or Crossplane repo. The PR description carries the diff, the rollback command and the forecasted saving.
- PR merges and deploy ships
Your existing review, policy and merge gates own the change — Tallywyrm never holds a merge token and never merges on your behalf. A deploy timestamp attaches to the audit row.
- Tallywyrm re-reads the same workload, same account, same time window
The week after deploy, the agent reads the same workload in the same account over the same time window and compares the post-change bill against the baseline.
- The audit tuple is the invoice
verified_cents = re_read_bill_baseline − re_read_bill_post_change. Only the delta that survived the re-read enters the verified pool for that period; that pool is what the invoice is computed against.
8 % / 12 % / 18 % — share is the only thing that varies.
Same audit gate, same artifact, same audit trail. Pick the tier that matches the size of your verified-savings programme; the share is the only variable that lands on your invoice.
- Single AWS / GCP / Azure account · OIDC-trusted credential
- Scoped IaC PRs to your Terraform / Pulumi / Crossplane repo
- Weekly exec-ready savings report
- SOC 2-aligned audit trail
- AWS + GCP + Azure in one workspace
- Scoped IaC PRs + native-API schedules for non-prod + prod sandboxes
- Weekly + daily-digest savings report with audit-row bundle sha256
- SOC 2-aligned audit trail + signed CSV export
- AWS + GCP + Azure + dedicated roles per business unit
- Scoped IaC PRs + native-API schedules for every environment
- Weekly + daily-digest + on-demand reports
- SOC 2 / ISO 27001 evidence export with attestation manifest + CSRD / SEC kgCO₂e evidence
The six things every Tallywyrm workspace ships.
The percentage of savings buys you the same playbook across AWS, GCP and Azure — every tier ships these six mission capabilities, with the depth of each scaling to the tier your workspace lives in.
- 24/7 inventory
- StarterSingle cloud · OIDC-trusted
- GrowthAWS + GCP + Azure
- EnterpriseAWS + GCP + Azure + dedicated roles
- IaC-anchored PRs
- StarterScoped PRs to your Terraform / Pulumi / Crossplane repo
- GrowthScoped PRs to your Terraform / Pulumi / Crossplane repo
- EnterpriseScoped PRs to your Terraform / Pulumi / Crossplane repo
- native-API schedules
- StarterStop / start schedules for non-prod environments
- GrowthStop / start schedules for non-prod + prod sandboxes
- EnterpriseStop / start schedules for every environment
- Weekly exec report
- StarterWeekly exec-ready savings report
- GrowthWeekly + daily-digest savings report
- EnterpriseWeekly + daily-digest + on-demand reports
- Audit trail
- StarterSOC 2-aligned audit trail
- GrowthSOC 2-aligned + signed CSV export
- EnterpriseSOC 2 / ISO 27001 evidence export with attestation manifest
- CO2e evidence
- StarterAvailable on Enterprise
- GrowthAvailable on Enterprise
- EnterpriseCSRD / ISO 27001 evidence export
| Mission feature | Starter | Growth | Enterprise |
|---|---|---|---|
24/7 inventory | Single cloud · OIDC-trusted | AWS + GCP + Azure | AWS + GCP + Azure + dedicated roles |
IaC-anchored PRs | Scoped PRs to your Terraform / Pulumi / Crossplane repo | Scoped PRs to your Terraform / Pulumi / Crossplane repo | Scoped PRs to your Terraform / Pulumi / Crossplane repo |
native-API schedules | Stop / start schedules for non-prod environments | Stop / start schedules for non-prod + prod sandboxes | Stop / start schedules for every environment |
Weekly exec report | Weekly exec-ready savings report | Weekly + daily-digest savings report | Weekly + daily-digest + on-demand reports |
Audit trail | SOC 2-aligned audit trail | SOC 2-aligned + signed CSV export | SOC 2 / ISO 27001 evidence export with attestation manifest |
CO2e evidence | Available on Enterprise | Available on Enterprise | CSRD / ISO 27001 evidence export |
What does NOT make the invoice.
The boundary a procurement reviewer or auditor will test against the contract. Four exclusions, lifted from the methodology FAQ so the page and the canonical documentation cannot drift.
- An unrealised forecast — anything the audit regresses is not certified and is not added to the verified pool for that period.
- A saving that regresses below the baseline — the credit is removed from the next invoice; there is no claw-back on a previously sent invoice.
- Savings that fail the re-read entirely — the invoice line for that period drops to zero for those savings.
- Forecast-only savings surfaced by a native tool — those recommendations have no PR, no deploy and no post-deploy measurement, so they cannot enter the verified pool.
Calibrate the math, then read the explainer prose again.
Everything below sits one scroll under the static marketing surface — same widgets, same anchors, same inbound links as before. Use them to read off your own numbers, then come back up to the model explainer.
3% – 10% verified band on annual spend.
12% applied to whatever the re-read certifies.
Single share of the verified pool.
Tallywyrm is only paid on verified savings — no verified savings = no charge.
On the verified-savings pool for that spend tier.
5% verified baseline minus the 12% share.
Every $1 paid to Tallywyrm, this much kept.
Illustrative — assumes 5% verified savings (the home ROI strip baseline). Your audit may return more or less; the share applies to whatever the re-read certifies.
Midpoint $30,000 / mo — $360,000 / yr
2 of 3 selected
Higher headcount = slightly higher verified band.
9.0% of $360,000annual cloud spend (per the 3%–10% verified band on /pricing).
Applied to whatever the re-read certifies — no verified savings = no charge.
What the customer keeps after Tallywyrm’s share — paid out of savings, before the cloud bill.
Illustrative — the projected figures use the same 3%–10% verified band /pricing explains. Your audit may return more or less; the share applies to whatever the re-read certifies.
Midpoint $150,000 / mo — $1,800,000 / yr
Headline is the cloud that drives the bulk of the bill.
Higher non-prod share widens the verified band.
3.4%–10.0% verified band × $1,800,000 annual spend, non-prod-adjusted.
Illustrative — actual savings require the post-deploy re-read of the same workload. Pre- and post-baselines are computed per the methodology.
18–30% illustrative band on $50,000 / mo · AWS
Illustrative pre-verification range — actual savings require how the math is anchored on /methodology, along with what does not enter the verified pool.
Tallywyrm vs the alternatives.
The same five buyer concerns, three columns. The Tallywyrm column links out to the methodology and the compliance posture that back each row up — the other two columns describe what you get without an autonomous, verified-savings loop.
- Pricing model
- Tallywyrm
- tier% × verified savings How the verified pool is computed→
- Traditional FinOps
- Platform license per seat or % of cloud spend — no verified pool
- In-house + spreadsheets
- Eng time + spreadsheet debt — the savings figure is someone’s notion
- Scoping action
- Tallywyrm
- Autonomous PRs into Terraform / Pulumi / Crossplane Read the IaC PR pipeline→
- Traditional FinOps
- Dashboards & reports only — humans still write the change
- In-house + spreadsheets
- Ad-hoc scripts owned by one engineer — gone when they leave
- Schedules
- Tallywyrm
- Native API stop / start on the workloads the audit certifies Audit-ready schedule logs→
- Traditional FinOps
- Manual playbooks — weekend Slack ping, next-day ticket
- In-house + spreadsheets
- Manual runbooks — whoever is on call that week
- Audit posture
- Tallywyrm
- Framework-aligned change log on every save See the compliance posture→
- Traditional FinOps
- None — no PR, no diff row, nothing an auditor can read
- In-house + spreadsheets
- Email + tickets — not the artifact a CSRD or SOC 2 review wants
- Reporting
- Tallywyrm
- Weekly exec-ready verified savings report See a sample weekly report→
- Traditional FinOps
- Raw bill exports / dashboards — finance still builds the slide
- In-house + spreadsheets
- Spreadsheet of CSV exports — last quarter’s format, by hand
| Concern | Tallywyrm | Traditional FinOps CloudHealth · Vantage · Spot | In-house + spreadsheets |
|---|---|---|---|
| Pricing model | tier% × verified savings How the verified pool is computed→ | Platform license per seat or % of cloud spend — no verified pool | Eng time + spreadsheet debt — the savings figure is someone’s notion |
| Scoping action | Autonomous PRs into Terraform / Pulumi / Crossplane Read the IaC PR pipeline→ | Dashboards & reports only — humans still write the change | Ad-hoc scripts owned by one engineer — gone when they leave |
| Schedules | Native API stop / start on the workloads the audit certifies Audit-ready schedule logs→ | Manual playbooks — weekend Slack ping, next-day ticket | Manual runbooks — whoever is on call that week |
| Audit posture | Framework-aligned change log on every save See the compliance posture→ | None — no PR, no diff row, nothing an auditor can read | Email + tickets — not the artifact a CSRD or SOC 2 review wants |
| Reporting | Weekly exec-ready verified savings report See a sample weekly report→ | Raw bill exports / dashboards — finance still builds the slide | Spreadsheet of CSV exports — last quarter’s format, by hand |
What the percentage buys you.
Every plan ships the same inventory and PR pipeline. Here's where the percentage of savings buys you more.
- Cloud connectorsAWS, GCP and Azure account connectors (read-only, OIDC trust where available)
- Starter
- Growth
- Enterprise
- Connected cloud accountsCloud accounts, projects and subscriptions per workspace
- Starter
- Growth
- Enterprise
- Recommendation slotsConcurrent active rightsizing PRs in flight per workspace
- Starter
- Growth
- Enterprise
- Schedule slotsStop / start schedule rules per workspace
- Starter
- Growth
- Enterprise
- Report cadenceWeekly exec-ready savings report, daily digest, and on-demand runs
- Starter
- Growth
- Enterprise
- Support SLAChannel and first-response target for support requests
- Starter
- Growth
- Enterprise
- Security featuresAudit trail, signed CSV export and ISO / CSRD evidence export
- Starter
- Growth
- Enterprise
- SSO (SAML / OIDC)Single sign-on with SAML 2.0 or OIDC identity providers — Okta, Entra ID, Google Workspace.
- Starter
- Growth
- Enterprise
| Feature | Starter | Growth | Enterprise |
|---|---|---|---|
Cloud connectors AWS, GCP and Azure account connectors (read-only, OIDC trust where available) | |||
Connected cloud accounts Cloud accounts, projects and subscriptions per workspace | |||
Recommendation slots Concurrent active rightsizing PRs in flight per workspace | |||
Schedule slots Stop / start schedule rules per workspace | |||
Report cadence Weekly exec-ready savings report, daily digest, and on-demand runs | |||
Support SLA Channel and first-response target for support requests | |||
Security features Audit trail, signed CSV export and ISO / CSRD evidence export | |||
SSO (SAML / OIDC) Single sign-on with SAML 2.0 or OIDC identity providers — Okta, Entra ID, Google Workspace. |
How the share, the credit, and tier changes work.
Four short answers — what “verified savings” actually means, why the percentage beats a flat fee, what happens when a recommendation under-delivers, and how to move between tiers mid-cycle.
See the audit row run on your account.
Request a demo and walk through a real audit row on your own AWS / GCP / Azure account — the same artifact finance signs off on and the same artifact every reconciliation framework already asks for.