# Security & Cost: Cut Cloud Cost

> How ZopNight handles security & cost across AWS, GCP, and Azure. Read-only setup, production excluded by default.

Source: https://zop.dev/solutions/security-and-cost
Published: 2026-07-01 · Author: avinash-gaurav · Tags: zopnight, hub

---

Security and compliance recommendations live next to cost and reliability recommendations. Privileged containers, missing TLS, public buckets, exposed databases, and IAM users without MFA all surface in the same dashboard with the same severity, owner, and audit log. ZopNight applies security & cost to non-production across AWS, GCP, and Azure, measured against real usage. See it by cloud or by service below, and the discipline in [FinOps](https://zop.dev/learn/finops).

## By cloud

- [AWS Security & Cost](https://zop.dev/aws-security-and-cost)
- [GCP Security & Cost](https://zop.dev/gcp-security-and-cost)
- [Azure Security & Cost](https://zop.dev/azure-security-and-cost)

## By service

- [Security & Cost for EC2](https://zop.dev/solutions/aws-ec2/security-and-cost)
- [Security & Cost for RDS](https://zop.dev/solutions/aws-rds/security-and-cost)
- [Security & Cost for EKS](https://zop.dev/solutions/aws-eks/security-and-cost)
- [Security & Cost for ECS](https://zop.dev/solutions/aws-ecs/security-and-cost)
- [Security & Cost for Lambda](https://zop.dev/solutions/aws-lambda/security-and-cost)
- [Security & Cost for ElastiCache](https://zop.dev/solutions/aws-elasticache/security-and-cost)
- [Security & Cost for Redshift](https://zop.dev/solutions/aws-redshift/security-and-cost)
- [Security & Cost for SageMaker](https://zop.dev/solutions/aws-sagemaker/security-and-cost)
- [Security & Cost for EMR](https://zop.dev/solutions/aws-emr/security-and-cost)
- [Security & Cost for ASG](https://zop.dev/solutions/aws-auto-scaling/security-and-cost)
- [Security & Cost for S3](https://zop.dev/solutions/aws-s3/security-and-cost)
- [Security & Cost for EBS](https://zop.dev/solutions/aws-ebs/security-and-cost)
- [Security & Cost for CloudFront](https://zop.dev/solutions/aws-cloudfront/security-and-cost)
- [Security & Cost for DynamoDB](https://zop.dev/solutions/aws-dynamodb/security-and-cost)
- [Security & Cost for App Runner](https://zop.dev/solutions/aws-app-runner/security-and-cost)
- [Security & Cost for Compute Engine](https://zop.dev/solutions/gcp-compute-engine/security-and-cost)
- [Security & Cost for Cloud SQL](https://zop.dev/solutions/gcp-cloud-sql/security-and-cost)
- [Security & Cost for GKE](https://zop.dev/solutions/gcp-gke/security-and-cost)
- [Security & Cost for Cloud Run](https://zop.dev/solutions/gcp-cloud-run/security-and-cost)
- [Security & Cost for Memorystore](https://zop.dev/solutions/gcp-memorystore/security-and-cost)
- [Security & Cost for BigQuery](https://zop.dev/solutions/gcp-bigquery/security-and-cost)
- [Security & Cost for Cloud Functions](https://zop.dev/solutions/gcp-cloud-functions/security-and-cost)
- [Security & Cost for Artifact Registry](https://zop.dev/solutions/gcp-artifact-registry/security-and-cost)
- [Security & Cost for Azure VMs](https://zop.dev/solutions/azure-virtual-machines/security-and-cost)
- [Security & Cost for AKS](https://zop.dev/solutions/azure-aks/security-and-cost)
- [Security & Cost for Azure SQL](https://zop.dev/solutions/azure-sql-database/security-and-cost)
- [Security & Cost for Azure Functions](https://zop.dev/solutions/azure-functions/security-and-cost)
- [Security & Cost for VMSS](https://zop.dev/solutions/azure-vm-scale-sets/security-and-cost)
- [Security & Cost for Databricks](https://zop.dev/solutions/azure-databricks/security-and-cost)
- [Security & Cost for ML Compute](https://zop.dev/solutions/azure-ml-compute/security-and-cost)

## Frequently asked questions

### Where should I start?

Start with the FinOps overview for the discipline that ties it together, then use the specific guide, cloud, or location page for the task you are on.

### Is production at risk?

No. Production is excluded by default; ZopNight acts only on the non-production resources you choose.

### What access does ZopNight need?

A read-only role to start. Discovery, cost reporting, and recommendations all run read-only, and you enable actions when you are ready.
