Security and compliance

CloudFix Compliance and Security Assurance

CloudFix is SOC 2 Type 2 audited. This page explains the access model a security reviewer will ask about: what CloudFix can read, what it can change, who approves each change, and where the record of it lives.

Open the Trust CenterTalk to our team

Source of record

trust.cloudfix.com

CloudFix’s security and compliance documents, including the SOC 2 Type 2 audit report, policies and security questionnaire answers, are published in the Trust Center. This page is a summary; the Trust Center is authoritative.

  • SOC 2 Type 2 audited
  • Least-privilege IAM
  • No agents
  • Logged in your account
Visit the Trust Center

Audited, certified and listed

  • AWS Partner, ISV Accelerate Program
  • AWS Qualified Software
  • SOC 2 Type 2 audited
  • AWS Partner with the Cloud Operations Competency
  • FinOps Foundation Member
  • Available in AWS Marketplace

The access model

Four steps, and one of them is yours.

  1. 01Connect

    A CloudFormation stack in your account

    It creates the IAM roles CloudFix uses, scoped to least privilege. No long-term credentials, passwords or access keys to hand over.

  2. 02Read

    Finders are read-only

    They read your Cost and Usage Report, resource configurations and CloudWatch metrics. They never read customer data in any data store, and they change nothing.

  3. 03Approve

    You approve every change

    You choose who can approve, and whether a fix runs now, runs on a schedule, or never runs.

  4. 04Run

    AWS Systems Manager Automation

    Approved fixes run as Automation runbooks in your own account, under a dedicated CloudFix role. Every execution has its own ID and log.

In detail

What a security review will ask.

How CloudFix connects

During onboarding you deploy a CloudFormation stack in your own account. It creates the IAM roles CloudFix uses, scoped to least privilege.

  • Scoped IAM roles: the templates define tightly scoped roles that allow only the actions CloudFix needs, such as reading Cost and Usage Reports and resource configurations, and applying the specific fixes you approve.
  • Cross-account access control: access uses AWS’s recommended cross-account pattern, so account boundaries stay intact and every call is attributable.
  • Audit and monitoring: actions CloudFix takes are recorded in AWS CloudTrail in your account, where your own tooling can monitor them.

What happens when a fix runs

Approved fixes run as AWS Systems Manager Automation runbooks in your own account, under a dedicated CloudFix role.

  • Snapshots first: where the fix supports it, CloudFix takes a snapshot before making the change, so you can restore the previous state.
  • Every execution is logged: each Automation execution carries a full record of what ran, where and when, which supports your own audit requirements.
  • Based on AWS’s own guidance: each fixer implements a documented AWS best practice or advisory.

Your compliance obligations

Inside the controls you already operate.

CloudFix works within the AWS shared responsibility model. Because changes run in your account, through your approval workflow and your logging, they stay inside the controls you already operate for frameworks such as GDPR or HIPAA. Whether a given change fits your obligations is your call, which is why nothing runs without your approval.

Walk through the access model with your security team.

The SOC 2 Type 2 report, policies and security questionnaire answers are at trust.cloudfix.com.