Integrations

Multi-cloud, multi-IaC — the audit trail is the product.

Tallywyrm runs inventory across AWS, GCP and Azure and ships rightsizing PRs into the Terraform, Pulumi or Crossplane repo you already maintain. Bring your own cloud credential, pay a percentage of verified savings, and read the same audit trail the finance and security teams already reconcile against.

AWS
GCP
Azure
Terraform
Pulumi
Crossplane
The short version
AWS, GCP and Azure inventory; Terraform, Pulumi and Crossplane PR targets; read-only credential; verified savings.
Same wording as /pricing, /security and /faq — this page just names the integrations and the percentages the audit trail backs.
Get on the list

Early-access teams get pricing tiers and the weekly-report digest before the public launch.

The integrations

Six connectors, one audit trail.

AWS, GCP and Azure for inventory and rightsizing; Terraform, Pulumi and Crossplane as the PR targets the agent opens against your existing repo. Every card on this page links to a procurement summary your security and finance teams reconcile against.

Merge loop & OIDC trust on /faq.

AWS
Inventory · Hourly
Hourly inventory across EC2, RDS, ECS, Lambda, S3 and EFS, with rightsizing families per service.

EC2, RDS, ECS, Lambda, S3 & EFS inventory on a daily cadence.

  • Read-only scope against Cost Explorer, the AWS Price List API and the granted accounts.
  • Instance-family rightsizing for EC2 (graviton + x86), Lambda memory/concurrency and RDS instance classes.
  • Idle and underused coverage for S3 buckets, EFS file systems and ECS services running below a configurable floor.
GCP
Inventory · Hourly
Hourly inventory across Compute Engine, GKE, Cloud SQL, Cloud Run and BigQuery, with rightsizing families per service.

Compute Engine, GKE, Cloud SQL, Cloud Run and BigQuery inventory.

  • Read-only scope against BigQuery billing export, Cloud Billing API and the granted projects.
  • Rightsizing families for Compute Engine machine types, GKE node pools and Cloud SQL tiers.
  • Idle coverage for idle Cloud Run services, unused BigQuery slots and disk snapshots older than 90 days.
Pillar guide coming — see /blog
Procurement & compliance →
Azure
Inventory · Hourly
Hourly inventory across Virtual Machines, AKS, SQL DB, App Service and Storage, with rightsizing families per service.

Virtual Machines, AKS, SQL DB, App Service and Storage inventory.

  • Read-only scope against the Azure Cost Management API, the Advisor API and the granted subscriptions.
  • Rightsizing families for VM SKUs, AKS node pools, SQL DB tiers and App Service plans.
  • Idle coverage for unattached disks, deallocated VMs and storage accounts below the access-floor reading.
Terraform
Rightsizing · PR target
Rightsizing landed as a scoped Terraform PR against the repo your platform team already owns.

Rightsizing PRs as scoped `.tf` diffs.

  • Format is a real HCL diff against the resource(s) the audit pass identified, ready for `terraform plan` in CI.
  • The agent opens the PR in your repo using the GitHub / GitLab credential your platform team already grants.
  • Merge loop is PR → human approver → merge → post-deploy measurement → weekly report.
  • No state changes, no apply against your account — only the diff lands in your repo, you control the apply step.
Pulumi
Rightsizing · PR target
Rightsizing landed as a scoped Pulumi program against the same repo, importable from any language.

Rightsizing PRs as scoped `.ts` programs.

  • Format is a typed Pulumi program against the same resource family Terraform covers, importable from any language.
  • The agent opens the PR in your repo using the same GitHub / GitLab credential as the Terraform flow.
  • Same merge loop as Terraform: PR → human approver → `pulumi up` from your CI → post-deploy measurement.
  • No stack mutations, no out-of-band `pulumi destroy` — the recommending agent never touches your state backend.
Pillar guide coming — see /blog
Procurement & compliance →
Crossplane
Rightsizing · PR target
Rightsizing landed as a Composition patch against the ManagedResource(s) the audit pass identified.

Rightsizing PRs as scoped `Composition` patches.

  • Format is a K8s manifest patch against the ManagedResource(s) the audit pass identified, ready for `kubectl diff`.
  • The agent opens the PR in your repo using the same credential flow as Terraform and Pulumi.
  • Same merge loop: PR → human approver → your GitOps controller reconciles → post-deploy measurement.
  • No provider credentials — the agent only edits the manifest in your repo; the controller you run does the apply.
Pillar guide coming — see /blog
Procurement & compliance →
Beyond the grid

Reporting, credential model, pricing & compliance.

The six integrations above describe what the agent connects to. The supporting surfaces — weekly report, signed review links, exportable audit trail, bring-your-own credential model, percentage-of-savings pricing and the compliance frameworks the audit trail satisfies — are what finance, security and procurement teams reconcile against.

Weekly report email
Every Monday, finance-ready.
  • Saved-search digest lands in finance inboxes at the same time every Monday morning.
  • Each line carries the PR, the deploy timestamp and the percentage-of-savings math.
  • Recipient list is editable from the dashboard; the agent never adds a finance address without sign-off.
Shareable links
A signed URL you can hand to a reviewer.
  • Same report-artifact surfaced through a signed, expiring review URL.
  • Reviewers see the saving, the diff and the audit trail without a Tallywyrm account; revoking the link closes access.
  • Read-only access: nobody signing in through the link can open a PR, edit a policy or rotate a credential.
Exportable audit trail
CSV by default; finance already reconciles against it.
  • Every row ties the saving to a PR, a deploy and a post-deploy measurement.
  • Same export format the SOC 2 Type II auditor and the EU CSRD disclosure pack already accept.
  • Available from the dashboard and from each weekly email — finance reconcile never blocks on a login.
Bring-your-own credential
You issue the credential. The agent never accepts a long-lived key.
Every integration above is reached through a read-only credential your platform team brokers through your existing OIDC trust. The contract on /privacy is the same one /security summarises.
  • Read-only IAM scope against the granted accounts — same wording on /privacy and /security.
  • Cost Explorer / Cost Management / BigQuery billing-export read access; no write surface anywhere.
  • Brokered through your existing OIDC trust, never a long-lived static key committed to the repository.
  • No org-admin or account break-glass role, no role escalation, no cross-account assume into resources you have not already federated.

Full contract and retention windows on /privacy.

Verified-savings pricing

8%, 12% or 18% of verified savings. Same integrations across all tiers; the percentage is the only differentiator and the saving is the same formula on /pricing.

8% of verified savings
Starter
For teams getting their first continuous FinOps signal.
12% of verified savings
Growth
For platform teams that want every PR reviewed and accounted for.
18% of verified savings
Enterprise
For finance-led programmes that need SLAs and bespoke reporting.
Compliance frameworks

Same frameworks the audit trail already satisfies.

SOC 2 Type II, ISO 27001, FedRAMP Moderate and the EU CSRD disclosure pack all accept the same signed CSV export finance teams already reconcile against.

  • SOC 2 Type II
  • ISO 27001
  • FedRAMP Moderate
  • EU CSRD
  • SEC climate disclosure
  • GDPR