CloudAgent logo
Devops Mlops · Observability Monitoring

CloudAgent

CloudAgent is an open-source harness that gives AI agents structured context on your cloud estate, covering architecture, cost, security and health, then keeps them inside read-only defaults, policy checks and human approvals across AWS and Azure.

Active Free plan Freemium API available Verified by Guidaio
Overview

What is CloudAgent?

CloudAgent describes itself as the open-source harness for AI-powered cloud operations. Its starting point is a familiar frustration: every agent session starts cold. Architecture gets pasted in by hand, resources are rediscovered from scratch, and cost or security signals sit somewhere the agent cannot reach. CloudAgent discovers and organises that material once, then keeps it available to any supported AI agent. The product rests on three pillars. Context means automatic cataloguing of accounts, applications and workloads, architecture diagrams attached to real resources, and cost, health and threat data mapped workload by workload. Guardrails means read-only access by default, write permissions granted per session rather than assumed, infrastructure-as-code checked against policy before it applies, human sign-off, and an end-to-end run log. Repeatability turns a session that worked into a reusable skill, chains skills into multi-step workflows, and keeps every input, decision and result. It ships in two forms. CloudAgent Console is a desktop application, open-sourced in July 2026 and published on GitHub, that you run yourself with Codex, Cursor or Claude agents. CloudAgent Hub is the hosted platform, with shared team context, managed agents, approvals, SSO and central control. Coverage is deepest on AWS, where access uses IAM roles with External IDs and temporary STS credentials rather than stored static keys, across three permission levels from Read-Only to Full Admin. The platform enforces 192 security rules spanning 42 AWS services in 11 categories, validated through AWS CloudFormation Guard on both CloudFormation and Terraform templates. Azure and Google Workspace are available on Hub; GCP, Entra ID and GitHub are announced. A public library offers 42 reports, 15 workflows and 3 packages, with Security and Governance the largest category. The vendor claims more than 1,000 cloud environments onboarded and cost reductions of 15 to 40 percent within 90 days. Behind it is CloudAgent Technology Inc., founded by Abdul Kittana, a former senior security architect at AWS, and Osman Rachid, a cloud architect based in Ottawa.

What it does

  • Discover, catalogue and document cloud workloads automatically, with living architecture diagrams
  • Audit an estate against SOC 2, HIPAA, PCI DSS, ISO 27001, NIST, FedRAMP, CIS and CMMC, then export the report
  • Find and remove cloud waste: idle instances, unattached volumes, orphaned snapshots, oversized resources
  • Validate CloudFormation and Terraform templates against 192 security rules before anything is deployed
  • Run scheduled or on-demand workflows that chain several steps behind human approval gates
  • Monitor cost, health and threat signals per workload from a single set of dashboards
  • Drive infrastructure from Cursor, VS Code, Claude Desktop, ChatGPT or JetBrains through an MCP server
Audience

When to use CloudAgent / When not to

A quick filter to help you decide if CloudAgent is the right fit.

When to use CloudAgent

  • Platform and DevOps teams that want governed self-service infrastructure rather than ticket queues
  • Security engineers and CISOs who need continuous posture management and audit-ready compliance evidence
  • FinOps leads and technical founders watching a cloud bill they cannot yet justify hiring for
  • Managed service providers and cloud consultancies juggling several client environments at once
  • Small engineering teams with no dedicated cloud operations headcount, using the permanent free plan to start

When not to use CloudAgent

  • Teams running mainly on Google Cloud, Entra ID or GitHub, all still announced as coming soon
  • Organisations that require a contractual commitment on data residency, since no hosting country or region is published
  • Buyers who need a signed DPA, a named subprocessor list or a completed SOC 2 attestation today
  • Anyone expecting fully autonomous remediation, as the terms make human oversight a contractual obligation
  • Non-English-speaking teams and mobile-first users, since the product ships in English only and has no mobile app
Get started

How to use CloudAgent

A typical end-to-end flow, from setup to results.

  1. Create an account on the CloudAgent Hub sign-up page, or download the open-source desktop console from GitHub if you would rather run it yourself
  2. Connect a cloud account: for AWS, enter the account ID and pick a permission level, starting with Read-Only as the documentation recommends
  3. Deploy the IAM role through one-click CloudFormation, a downloaded template or Terraform, then let the wizard validate the credentials
  4. For Azure, supply the tenant details, choose subscription scope and create a service principal with Terraform, PowerShell or the Azure portal
  5. Let workload discovery run in the background; it catalogues resources and produces diagrams and documentation on its own
  6. Review the cost, health and threat dashboards, then use Command Center to ask questions about the environment in plain English
  7. Run a report from the library, which costs 20 credits, or a workflow, which costs 1 credit, either on demand or on a schedule
  8. Handle the Waiting on User states: read the proposed action and its supporting context before it touches production
  9. Connect an IDE by copying the MCP configuration from the dashboard into Cursor, VS Code, Claude Desktop, ChatGPT, JetBrains or Windsurf, then authenticate with OAuth
  10. Raise the permission level from Read-Only to Limited Write or Full Admin only once you trust what the agents propose
Quick read

Pros & Cons

Pros

  • Read-only by default, temporary STS credentials and no stored static keys, with write access granted per action
  • Human approval and a complete audit trail on every change, which is exactly what makes agentic operations defensible internally
  • Infrastructure-as-code checked against policy before it is applied, not flagged afterwards
  • The desktop console is open source, so the harness can be inspected rather than trusted on faith
  • A permanent free plan with one workload and one compliance report, and a self-hosted option for constrained environments
  • Broad compliance coverage with auditor-ready PDF exports, unusual at this price point
  • Agent-agnostic: it works with any MCP-compatible tool rather than locking you to one assistant

Cons

  • Multi-cloud coverage is uneven: AWS is deep, Azure and Google Workspace are recent, and GCP, Entra ID and GitHub are still announcements
  • No data residency commitment at all, since neither hosting country nor region is published anywhere on the site
  • No published DPA, no subprocessor list, and the third-party AI providers processing your data are never named
  • SOC 2 Type II is described as in the audit process, with a target date that has already passed
  • Public documents are only partly kept up to date, including roadmap milestones and structured data that disagrees with the pricing table
  • The credit model deserves attention: one report costs 20 credits, a fifth of the monthly Individual allowance
  • No postal address is published anywhere, and the jump from 25 to 500 US dollars a month leaves no middle tier
Pricing

Pricing & Plans

A permanent free plan is available at no cost, covering one workload, chat, MCP integration, cost, health and threat monitoring, and one compliance report. The cheapest paid entry point is the Individual plan at 25 US dollars per month, which adds unlimited workloads, 25 monthly credits and priority email support. All prices are quoted in US dollars. Operational tasks are metered in credits, with one credit per workflow run and twenty per generated report, and additional credits may be purchased separately. The CloudAgent Console desktop application is open source and free to run yourself.

Plan 1
Free
  • 0 USD forever - build and manage 1 workload
  • chat
  • MCP integration
  • monitoring
  • 1 compliance report
Plan 3
Teams
  • 500 USD/month - unlimited users
  • SSO and SAML authentication
  • 500 credits per month
Plan 4
Enterprise
  • custom pricing - dedicated deployment
  • custom limits and billing
  • dedicated account manager
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how CloudAgent handles your data.

GDPR overview

There is no GDPR claim for the vendor itself. The privacy policy and terms, both effective 8 January 2026, are written under Canadian law: they refer to Canadian statutes and to transfers of personal information to jurisdictions outside Canada, including the United States. The word GDPR appears on the site only in the product sense, describing the compliance reports CloudAgent generates on a customer's AWS estate. No Article 27 representative is designated, no data protection officer is named, and no lawful basis is cited. The rights that are offered follow Canadian privacy principles: access, correction, withdrawal of consent, and unsubscribe. Questions go to a Privacy Officer reachable at the general support address. European buyers should therefore treat GDPR alignment as unverified rather than absent.

Who owns the data?

The terms split ownership three ways. You keep ownership of original content you create with the AI features, but outputs that are generic, commonly known or not original to you are explicitly not yours. CloudAgent keeps all rights in its models, algorithms and underlying technology, and grants you only a revocable, non-transferable licence to use its materials. Separately, the vendor reserves the right to use and share Aggregated Data, defined as data stripped of personal information and private configuration data. Under the privacy policy you may access and correct your personal information, withdraw consent, delete what you saved to your profile, and close the account at any time.

Reuse rights

You may reuse the reports, diagrams, templates and documentation the platform produces for you without asking permission, and export them, for example as PDF for auditors. What you may not do is reuse the vendor's own materials: copying, reselling, redistributing, modifying, reverse engineering or building a competing product from them is prohibited, as is removing proprietary notices. Generic AI outputs are not yours to claim. On the vendor's side, cloud resource metadata, logs, metrics, events, your chat prompts and workflow definitions may be processed by unnamed third-party AI providers, and using the service is treated as consent to that. Aggregated, anonymised or de-identified data derived from your usage may be used to improve their models; proprietary configuration, credentials and personal data require your explicit consent first.

Data retention & training

Retention summary
The privacy policy commits only to keeping personal information as long as necessary for the purposes it was collected for, or to meet legal requirements, and to destroying it once it is no longer needed. No figure is given: no retention period, no deletion deadline after account closure. You can delete or remove anything you saved to your user profile, and close the account at any time through the interface or the support address. Cloud environment data and the parameters used to generate configuration templates are not collected at all unless you explicitly save them to your profile. The FAQ mentions that retention policies can be set to match your own compliance requirements, but does not document how. Anonymisation appears only in the sense that aggregated data may be reused.
Trains on customer data
Yes
GDPR contact

Hosting summary

No hosting country or region is declared anywhere on the site, and that absence is itself the finding. The privacy policy states only that some or all personal information may be stored or processed in jurisdictions outside Canada, including the United States, and that governments, courts and law enforcement in those jurisdictions may be able to obtain access under local law. The company is governed by Canadian law throughout its terms and privacy policy. Technically, the website is served by Amazon CloudFront and the resolved IP geolocates to Zurich, but that identifies a content delivery node, not where customer data is stored, and should not be read as a hosting location. The one concrete alternative is self-hosting: in a dedicated deployment the entire stack runs inside your own AWS account or data centre, and the vendor states that all data, including agent logs and AI interactions, stays in your infrastructure. Isolated AI endpoints are also offered on that tier to prevent data co-mingling.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting CloudAgent.

  • The terms push every consequence of an approved action or configured workflow onto you, including data loss and higher cloud bills
  • Liability is capped at the greater of the last two months paid or 100 US dollars, which is negligible against a production incident
  • Granting Limited Write or Full Admin hands an agent the power to modify or delete real resources, so approval fatigue becomes a genuine operational risk
  • Unnamed third-party AI providers process your cloud metadata, logs and prompts, and simply using the service counts as consent
  • Aggregated, anonymised or de-identified data may feed model improvement with no documented opt-out setting
  • No hosting country is declared and processing may occur outside Canada, including in the United States, which weakens any residency assumption
  • Terms and privacy policy can change without notice, and outdated roadmap claims on the site mean availability should be checked before you commit
Setup

Setup & Integrations

Technical difficulty

Moderate, and mostly front-loaded. The shortest path is signing up and connecting an AWS account with the one-click CloudFormation stack; downloading the template or using Terraform are the alternatives. Azure asks more: tenant details, subscription scope, then a service principal created through Terraform, PowerShell or the portal. The real prerequisite is knowing how to deploy an IAM role and choose a permission level. IDE integration is quoted at two to five minutes depending on the editor. Running the open-source desktop console is on you. Day-to-day use needs no programming: the platform is driven in plain English.

Deployment

Web appDesktop appAPIPlugin

Integrations

AWS Microsoft Azure Google Workspace Cursor VS Code Claude Desktop ChatGPT JetBrains Windsurf Terraform OpenTofu AWS CloudFormation GitHub Okta Azure AD

Supported languages

English
Company

Behind CloudAgent

Company name
CloudAgent Technology Inc.
Founded
28/05/2014
Country of origin
🇨🇦 Canada
UBO
Abdul Kittana
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does CloudAgent actually do?
It gives AI agents structured context on your cloud estate, covering architecture, cost, security and health, and lets them act on it. Agents show their plan, wait for your approval, then execute. The vendor positions it as a cloud operations team that runs continuously without hiring one.
Which cloud platforms are supported today?
AWS has the deepest coverage. Azure and Google Workspace are available on CloudAgent Hub, with the Azure support pass completed in May 2026. GCP, Entra ID and GitHub are announced as coming soon, so check availability before committing if they matter to you.
How does CloudAgent access my cloud account?
Through IAM roles with External IDs and temporary AWS STS credentials, never stored static keys. Three permission levels exist: Read-Only, Limited Write and Full Admin. The documentation recommends starting with Read-Only, which already covers dashboards, reports, recommendations, health checks and cost analysis.
What does it cost?
There is a permanent free plan with one workload. Individual costs 25 US dollars a month, Teams 500 US dollars a month with SSO and SAML, and Enterprise is quoted on request. Workflows consume one credit and reports twenty, with extra credits available for purchase.
Is there a free trial?
No time-limited trial is advertised. What the site offers instead is a free plan that lasts indefinitely, covering one workload, chat, MCP integration, monitoring and a single compliance report. That is the intended way to evaluate the product without paying.
Can I run CloudAgent on my own infrastructure?
Yes. The CloudAgent Console desktop application was open-sourced in July 2026 and is published on GitHub. For regulated environments, a dedicated hosting option runs the entire stack inside your own AWS account or data centre, keeping data, agent logs and AI interactions in your infrastructure.
Is my data used to train AI models?
Partly. The terms allow aggregated, anonymised or de-identified data derived from your usage to be used to improve their models. Proprietary cloud configuration, credentials and personal data are excluded unless you give explicit consent. No opt-out toggle is documented, so the protection rests on that consent clause.
Where is my data hosted?
The site does not say. No hosting country or region is published, and the privacy policy states that personal information may be stored or processed outside Canada, including in the United States. If residency matters to you, the self-hosted option is the only published answer.
Which compliance frameworks can it report on?
More than twenty, including SOC 2, HIPAA, PCI DSS, GDPR, ISO 27001, NIST 800-53, 800-171 and CSF, FedRAMP Low and Moderate, CIS AWS Foundations v3.0, Canada GC, CMMC 2.0 and the RBI Cyber Security Framework. Reports export to PDF for auditors.
Is CloudAgent itself SOC 2 certified?
Not according to the site. The FAQ describes SOC 2 Type II as currently in the audit process, with a target date that has since passed. Treat it as work in progress rather than an obtained attestation, and ask for the current status before signing.
Conclusion

Should you pick CloudAgent?

CloudAgent is a young product that already covers a lot of ground. The domain was registered in 2024, the desktop console was open-sourced only in July 2026, and yet the platform ships workload discovery, compliance reporting on more than twenty frameworks, cost optimisation, governed workflows and an MCP server for half a dozen IDEs. Its real strength is not the automation but the restraint around it: read-only by default, write access granted per action, infrastructure-as-code validated before it applies, human sign-off and a complete audit trail. That is the part most agentic operations tools skip, and it is what makes this one defensible to a security team. The reservation runs the other way. For a vendor whose entire pitch is governed access to production infrastructure, the legal and hosting transparency lags well behind the security narrative. There is no postal address anywhere on the site, no published DPA, no subprocessor list, no named AI provider, no declared hosting country, and a SOC 2 Type II attestation still described as in progress against a date that has passed. Several public documents have not been reread: roadmap milestones and structured data contradict the current pricing table. None of that makes the product unsound, but it does shift work onto the buyer. Verify actual coverage outside AWS, ask for the current SOC 2 status, and ask in writing where customer data is stored before granting anything beyond read-only. The permanent free plan makes that evaluation cheap: one workload, one compliance report and a read-only IAM role are enough to judge whether the guardrails hold before any money or write permission changes hands.