Your cloud advisor showed you 14%. The other 86% is where the savings live.
450+ rules across AWS, GCP, Azure, and your data platforms. Read-only in five minutes. Every finding is reconciled against your actual bill before it reaches your dashboard.
The architecture canvas.
Every resource, every dependency, mapped.
Architecture canvas view. Filter by provider and region. Click any resource to drill into its config + cost. (Live product includes Globe view, account / category filters, and the full inventory grid.)
Cloud spend grew.
Cloud governance didn’t.
Three clouds. Eight dashboards. Thirty-plus engineering hours a week on manual start-stop and tag work nobody trusts. The waste isn’t dramatic, it’s quiet, distributed, and continuous.
- Non-prod running 24/7 Used 50 hours. Billed for 168.
- Orphan resources Detached disks, stale snapshots, unattached IPs.
- Over-provisioned production t3.xlarge at 8% CPU. The team that picked it left.
- Unclaimed rate optimisation Hybrid Benefit, RIs, Savings Plans untouched.
- Compliance drift IAM, encryption, public-access misconfigs.
Detect. Decide. Act. — Every dollar your cloud advisor missed.
Continuous detection across AWS, GCP, and Azure. Every finding reconciled against your live bill. Auto-fix where it’s safe; guided remediation for everything else. Customer databases excluded by default.
Three engines.
One workspace.
Lens reads your bill and finds the waste. Smart Scheduling captures non-prod cycles. Tide sizes production to actual demand. CDCR keeps it all fixed.
Recommendations
Finds the waste.
450+ rules across AWS, GCP, Azure. Eight categories, idle, right-sizing, schedule, orphan, compliance, discount, security, reliability. Every finding ships with the metric, the threshold, the action, and the dollar. No black-box ML.
Smart Scheduling
Captures non-prod cycles.
Cron-based, dependency-aware, per-timezone. 30+ resource types, VMs, K8s, SQL, Databricks, Snowflake. Storage wakes before compute. Production-safe overrides.
Smart Autoscaling by Tide
Sizes for the moment, not the peak.
ASGs, scale sets, AKS pools. 30–40% compute reduction on eligible workloads. Three modes, monitor → recommend → autopilot. You decide where it gets the keys. Never silently overwrites scaling policies you already run: adopt them as-is, or replace them with the original config captured for byte-accurate restore. You decide where it gets the keys.
A number you can take to finance.
A recommendation either carries a dollar figure backed by live rates and measured telemetry, or it doesn’t ship. No fabricated percentages, no $0 filler. Mutually exclusive levers never stack: savings on one resource never sum past what that resource costs. Stopped and part-time resources are priced at measured uptime, and a production tag is an absolute veto on Spot, on HA removal, and on multi-year lock-in.
The depth behind
the three engines.
Eighteen more features you’d otherwise build internally, reports, showback, smart tags, inventory, budgets, ownership, AI-native access, audited remediation, the cross-cloud map, data platforms, Kubernetes workload rules, commitments, blast radius, AI infrastructure, AI spend, Jira/ITSM, cloud IAM import, unit economics. All ship inside the same workspace, on the same audit trail.
Boardroom-ready cost reports.
Three Reports tabs, Organisation, Teams, Tags. Cost Flow Sankey, four columns deep. Cost anomaly detection across seven dimensions, root cause named. Four dashboard presets, Executive, Engineering, FinOps, All Widgets. Exports ship as CSV or a two-sheet Excel workbook with an executive summary, savings de-duplicated per resource so leadership never sees stacked levers.
ORG · TEAMS · TAGS
Every dollar, attributed.
Two attribution dimensions — team and tag. Shared resources split equally across owning teams. Reconciled to actual billing (Cost Explorer, Cost Management, BigQuery), not rack rate.
TEAM · TAG · RECONCILED
Tag every dollar, without the ticket.
Policy-driven tags for cost attribution. Write the policy once; the tag value derives from what the resource already is: provider, region, type, name. Accept or revoke per key; every refresh re-checks that an accepted tag still holds. Applied inside zopnight. Your cloud tags are never modified.
POLICY · ACCEPT · RECONCILED
Search, filter, act on every resource — three levels deep.
395+ resource types across AWS, GCP, Azure, Databricks, and Snowflake. Grouped account dropdown, cascade filters, nine type categories. Parent-child nesting (cluster → nodepool → VM). Bulk start / stop with a sticky selection banner.
395+ TYPES · 5 PLATFORMS · 3 LEVELS
Budgets that compute themselves.
Budget per team, per resource group, or per resource. Spend computed live from your actual cost records. Status colour-coded: green, yellow, red. Threshold-crossing alerts fire to the team’s channel.
GREEN · YELLOW · RED
Who created this? Already answered.
Daily identity-sync derives the IAM principal that originally created each resource — from CloudTrail, GCP Audit Logs, Azure Activity Logs. Human callers separated from service accounts. The “who owns this orphan disk?” question, finally answered.
CREATOR · LAST WRITE · HUMAN VS SERVICE
Your cloud, in your AI editor. Now with governed writes.
A Model Context Protocol server with 119 tools: 85 read, 34 write. Connect Claude Desktop, Cursor, Codex, or Claude Code with one PAT. Read-only by default; writes are opt-in per org, tiered from metadata-only to irreversible, enforced at the gateway, and audit-logged like every other action.
AI-NATIVE · 119 TOOLS · GOVERNED WRITES
Certified rules. One click. Zero database touches.
One click applies certified recommendations. A four-step check runs every time — precondition → approval → cloud action → validate. Customer databases stay with your DBA team: RDS, Aurora, Cloud SQL, ElastiCache, Azure SQL, Postgres, MySQL — never touched.
CERTIFIED · DBS UNTOUCHED
Map every cloud. Trace every dependency. Automatically.
Atlas, searchable inventory of 395+ resource types across AWS, GCP, Azure, Databricks, and Snowflake. Canvas, interactive dependency graph, live edges auto-derived from cloud metadata. Subnet swimlanes, security-group hubs, VPC peering, attached storage. The map maintains itself.
ATLAS · CANVAS · LIVE
Databricks and Snowflake, governed like the rest.
Databricks on all three clouds: clusters, pools, SQL warehouses, jobs, serving endpoints, with 15 rules per cloud for auto-termination, warehouse auto-stop, Photon, spot workers, orphan jobs, and missing cost tags. Snowflake warehouses suspend and resume on the same scheduler as your VMs, with 20 cost signals reconciled against your own ACCOUNT_USAGE.
DATABRICKS · SNOWFLAKE · SCHEDULED
Inside the cluster, not just around it.
43 rules per provider on EKS, GKE, and AKS: missing requests and limits, single-replica production, privileged containers, root users, unbound volumes, HPAs pinned at max, CPU and memory over-provisioned against live autoscaler signals. Every check is time-gated, so a mid-deploy blip never pages anyone.
RELIABILITY · SECURITY · RIGHTSIZING
Reservations, priced honestly.
1-year and 3-year Reserved Instance and Committed Use recommendations, priced from live public rates, never a flat discount. Gated on 60 days of history, measured uptime, and a break-even test: if the commitment doesn’t beat what you actually pay, it isn’t recommended. Every figure carries the evidence that produced it.
REAL RATES · BREAK-EVEN GATED · AUDITABLE
See what a fix touches, before you apply it.
One click maps the resources connected to any recommendation, on the architecture canvas: what breaks, what blips, what’s safe. A 0-100 risk score from impact, environment, and ownership. Applies to resources, autoscaling policies, and schedules.
TARGET · AFFECTED · SAFE
The AI stack is billable too.
SageMaker endpoints, notebooks, training jobs, and HyperPod clusters. Bedrock provisioned throughput, agents, guardrails, and knowledge bases. Vertex AI endpoints and notebooks. Azure OpenAI provisioned throughput. Idle detection, off-hours scheduling, and rightsizing, with the same discipline as everything else: a real dollar figure or no recommendation.
SAGEMAKER · BEDROCK · VERTEX · AZURE OPENAI
Your LLM bill, governed like your cloud bill.
Connect OpenAI, Anthropic, OpenRouter, or AWS Bedrock. Per-team virtual keys with hard budgets and model allow-lists; rotation without downtime. Spend by provider, model, and team in Cost Reports. A complexity router sends cheap prompts to cheap models and reports the share served cheap.
KEYS · BUDGETS · ROUTING
From finding to ticket, automatically.
One-click Jira tickets carrying the resource, the savings, and the fix. Policy-driven auto-ticketing for the findings you choose, with a live count of what a policy would ticket before you save it. Status and assignee sync both ways; one problem never becomes two tickets.
TWO-WAY SYNC · POLICY-DRIVEN
Your cloud IAM, imported, not re-typed.
Pull users, groups, and roles from AWS, GCP, or Azure into zopnight teams and roles, with a curated translation of cloud permissions to platform policies. Review before apply. Admin rights are never auto-granted, whatever the source policy says.
AWS · GCP · AZURE · REVIEW-FIRST
A bigger bill isn’t the problem. A bigger bill per customer is.
Define the denominator that matters to your business: orders, monthly active users, API requests, signups. Push the values from your pipeline, upload a CSV, or register an endpoint we poll daily. Cost per unit reads off the same trend chart as spend, forecast included, and scopes to a team or a tag.
PUSH · CSV · PULL
The fix that stays fixed.
CI/CD made code continuous. CDCR makes your cloud continuous. So the fix stays fixed.
Drift, cost anomalies, expired overrides, compliance gaps continuously, across every cluster, account, and region.
450+ rules across AWS, GCP, Azure. Every finding scored by severity and dollar impact production drift ranks above an idle dev box.
Every action in the audit trail actor, timestamp, dollar delta. Reviews read measured outcomes, never forecasts.
Auto-fix where it’s safe guided remediation for the rest. Production writes admin-gated, customer databases never touched.
$14,820/month recovered in 4 weeks.
Production untouched.
Anonymised Fortune 1000 estate. 2,140 resources across 3 Azure subscriptions. Read-only connect, then four weeks, line-by-line, reconciled against actual billing.
We find. We execute. We prove.
| Azure Advisor | CloudHealth | Flexera | Spot.io | zopnight | |
|---|---|---|---|---|---|
| Azure rules | 15 | ~50 | ~90 | - | 147 |
| Multi-cloud (AWS + GCP + Azure) | - | ✓ | ✓ | ✓ | ✓ |
| Cron scheduler | - | - | partial | - | ✓ |
| Dependency sequencing | - | - | - | - | ✓ |
| Autoscale on prod | - | - | - | partial | ✓ |
| Continuous remediation (CDCR) | - | - | - | partial | ✓ |
| Automated execution | - | - | - | partial | ✓ |
| Kubernetes + Databricks + Snowflake | - | partial | partial | partial | ✓ |
| India residency | - | - | - | - | ✓ |
* AWS Trusted Advisor and GCP Recommender exhibit the same 14%-only pattern as Azure Advisor.
Outcome-aligned pricing.
Pay when the bill drops.
| Plan | Free | Team | Growth | Enterprise |
|---|---|---|---|---|
| Best for | Audit your cloud, read-only | Up to $50K/mo cloud spend | Up to $500K/mo cloud spend | Custom + outcome share |
| Tailored Recommendations | ✓ all 450+ rules | ✓ | ✓ | ✓ |
| Sequenced Scheduling | - | ✓ | ✓ | ✓ |
| Autoscaling engine | - | - | ✓ | ✓ |
| CDCR auto-remediation (safe) | - | - | ✓ | ✓ |
| CDCR guided remediation + audit forwarding | - | - | - | ✓ |
| MCP server (Claude / Cursor) | ✓ | ✓ | ✓ | ✓ |
| Multi-cloud (AWS + GCP + Azure) | 1 cloud | ✓ | ✓ | ✓ |
| India residency / VPC deploy | - | - | - | ✓ |
| SAML SSO, RBAC, SOC 2 pack | - | - | ✓ | ✓ |
| Pricing | $0 | $199/mo* | $799/mo* | Platform fee + % of realised outcomes |
| Connect a cloud → | Start trial → | Start trial → | Talk to platform sales → |
No outcomes, no charge on the variable. Verified against your actual AWS / GCP / Azure billing.
Built for every seat in the room.
Predictable variance. Verified against your bill.
One platform. Three clouds. Four lifecycle stages.
Ship product, not platform overhead.
Cross-cloud inventory. CDCR auto-fix.
Read-only by default. Append-only audit.
How much is your cloud wasting right now?
Most teams overspend by 30–60%. Find out your number in 30 seconds.
Enter your details to receive your savings estimate by email.
We’ll always send your savings estimate. Marketing emails are sent only with your consent.
Things teams ask before they sign.
Will zopnight ever touch production?
Not until you say so. zopnight runs read-only by default, every write operation rejected at the credential layer. To enable writes, you opt in per environment, scope the IAM policy, and tag the resources eligible. The audit trail captures every approval. Most customers run six to twelve weeks read-only before flipping the first scope.
What permissions does zopnight need?
Read-only roles on AWS, GCP, or Azure, full IAM policy published in the docs. No service accounts created in your tenant; no agents installed; no proxy in the data path. For optional auto-remediation, a scoped write policy (also published) covers only the resource types enabled in the override settings. Every granted and denied permission is listed per resource category, per account, so you can see exactly what we can and cannot read. Credentials rotate in place: swap keys or switch auth methods without losing resources, schedules, or history, and new credentials are verified against the same cloud identity before anything changes.
What happens during an incident?
All scheduled actions pause. zopnight stops issuing writes the moment a registered incident channel signals an open incident, Slack, Teams, GChat, webhook. Resume is one click; the audit trail records the pause and the resume.
How is this different from native AWS / GCP / Azure scheduling?
Native schedulers are single-cloud, single-resource-type, and operator-defined. zopnight is multi-cloud, dependency-aware, and rule-derived. The cron syntax is the surface; underneath, the engine knows storage wakes before compute, knows that an EKS scale-down waits for the StatefulSet quiesce, knows the override expires Friday.
How long until the bill drops?
First findings in five minutes. First safe auto-fix windows in week one. Measurable bill movement by end of week four, the Fortune 1000 case study above ($14,820/mo recovered in 4 weeks) is the documented pattern, not the ceiling.
Is there a free tier?
Yes. The Free plan covers all 450+ recommendation rules on one cloud, read-only, with the MCP server included. No credit card. The pilot runs 30 days; after that, you stay on Free or upgrade, no auto-bill, no surprise charge.