Multi-cloud discovery

Find what live cloud is hiding.

ops0 scans AWS, GCP, Azure, and Oracle Cloud for exposure, drift, unmanaged resources, and cost risk, before they become incident work.

AWS, GCP, Azure, and OCI
Correlated risk, graded A to F
Drift and shadow-resource alerting
Idle and orphaned spend detection

ops0 is preventive cloud security. Multi-cloud discovery scans live cloud read-only to find exposure, drift, unmanaged resources, and cost risk before they become incidents.

ops0.ai/features/discovery/snapshot
ops0 discovery snapshot: security grade C, 312 findings by severity, regional footprint, 6 compliance frameworks, and recoverable spend
4
Clouds
AWS · GCP · Azure · OCI
230+
Resource types
across providers
3
Scan engines
correlated
A-F
Risk grade
per account
Read-only
Access
no write path
How it works

From connected cloud to reviewed code.

01
Connect read-only

Attach AWS, GCP, Azure, or OCI with least-privilege access. ops0 never holds a write path.

02
Scan live state

Inventory every resource, enrich metadata, and map dependencies across accounts and regions.

03
Correlate and grade

Three engines cross-check findings, suppress known-safe noise, and grade the account A to F.

04
Hand off to code

Turn findings into reviewed Terraform, OpenTofu, or Oxid, in dependency-safe import order.

Accounts
8
scanned
Regions
4
scanned
Resource types
27
discovered
Total resources
3,800
live
Monthly spend
$155,000 /mo
Recoverable
$12,400 /mo
Findings
312
Live cloud inventory

See what is actually running.

Find real cloud state across accounts and regions.
Surface unmanaged resources, exposure, and drift.
Spot recoverable spend before it compounds.
Account riskGradeC
Exposure & network118 findings
Compliance posture141 findings
Policy-as-code53 findings
Confirmed by 2+ engines
74
Known-safe noise suppressed
39
Frameworks mapped
6
Correlated risk

Correlated risk, graded A to F.

Three scan engines cross-check exposure, compliance, and policy.
Agreement across engines raises a finding to confirmed.
Context rules suppress known-safe noise, so the grade reflects real risk.
Finding detailCritical
Public ingress and excessive IAM permissions
Resource
Security Group sg-0af1b2c3d4e5f67890
Account
prod-security
Region
us-east-1
Affected resources12
Monthly spend impact$1,280
First seen2 days ago
Last seen3 hours ago
Blast radius
High
Compliance
2 frameworks
Recommendation
Restrict ingress, least privilege
Recoverable
$1,280 /mo
Risk with context

Every finding carries context.

Severity, blast radius, spend, and ownership in one view.
Not just what changed, but what it affects.
Enough context to move the right review.
Changes over time
TOTAL FINDINGS
312 12%
NEW
28 7%
RESOLVED
16 11%
ACTIVE
42 3%
Apr 16Apr 23Apr 30May 7May 14
Continuous by design

Discovery is not a one-time import.

Track quiet changes over time.
Watch live cloud evolve between deploys.
Keep visibility current as infrastructure shifts.
Under the hood

Built to be trusted with production.

Read-only by default

Scans run with least-privilege credentials. No write path to your cloud.

230+ resource types

Compute, storage, network, IAM, and data across four providers.

Scheduled and on-demand

Run discovery continuously on a schedule, or the moment you need it.

Diffs and timelines

Compare two scans and trace how any resource changed over time.

Dependency-safe import

Relationships are resolved so generated code imports without breakage.

Per-resource cost

Every resource carries an estimated monthly cost and recoverable spend.

Common questions

Multi-cloud discovery is the process of scanning cloud environments across AWS, GCP, Azure, OCI, and Kubernetes to build a current inventory of live resources, their dependencies, and the risk attached to them: drift, unmanaged resources, public exposure, idle cost, and policy gaps. In ops0 it runs read-only first, so teams see what is actually running before any change is made.

Turn live findings
into reviewed fixes.

Discovery is the first move. The reviewed fix path is what turns visibility into control.

Explore IaC