MarshalCloud
How it worksBill scanPricingTrustSign inStart free

AWS integration

Connect AWS with one read-only CloudFormation role. MarshalCloud reads your bill, your inventory and your security settings, drafts a fix, and waits for you to approve it.

What MarshalCloud does with it

  • Your bill, from a cost and usage export delivered to a bucket in your own account, so the dollar figures come from your own data and not an estimate.
  • What you are running: servers, storage, databases, load balancers, containers and clusters, certificates and DNS health checks.
  • Security settings: public buckets, sign-in and access-key hygiene, encryption defaults, audit logging, and the findings of AWS's own scanners where you already pay for them.
  • AWS's own cost advice: Compute Optimizer, Cost Optimization Hub, Trusted Advisor and Savings Plans data.

What it never does

  • The read role can only describe, list and get. It cannot create, change or delete anything in your account.
  • It is never granted permission to read a secret's value, your log contents, or the prompts and responses of an AI model.
  • Fixes need a second, separate role you choose to install. Never installing it is a supported way to use MarshalCloud, and every fix still waits for a person to approve it.
  • Your credentials are not held: the default connection is a role you own plus a secret External ID, not keys we store.

Read-only is the default everywhere. A fix is drafted, priced and explained, and then waits for a person to approve it. The whole access path is on Security and access.

Which plan includes it

Every plan, including Free. What changes is how many AWS accounts: 1 on Free, 2 on Startup, 10 on Growth, 50 on Scaled. See every plan limit.

How to connect it

  1. Start a connection in MarshalCloud. It gives you a CloudFormation link and an External ID unique to your organisation, so a leaked role name is not access.
  2. Run the stack in your own AWS account. You can read every permission it grants line by line first. It creates the read-only role and a billing export bucket that stays yours.
  3. Paste the role's ARN back into MarshalCloud. To revoke, delete the stack: our access ends immediately.

Questions

Is the AWS connection read-only?
Yes. The role the CloudFormation template creates can only describe, list and get. It cannot create, change or delete anything, it is never given permission to read a secret's value or your log contents, and it can only be assumed with an External ID unique to your organisation.
Can MarshalCloud change something in my AWS account?
Only if you install a second, separate role for fixes, and only after a person approves that specific fix. The fix role's permissions mirror the reviewed action list exactly, nothing wider. Never installing it is a supported way to use MarshalCloud.
Which plan includes AWS?
Every plan, including Free. Free covers one AWS account, Startup two, Growth ten and Scaled fifty.

Other integrations

  • Google Cloud
  • Kubernetes
  • Slack
  • Datadog
  • Email and webhooks

MarshalCloud

MarshalCloud is your agentic friend for the cloud. Four named agents read AWS, Google Cloud and Kubernetes, name what changed in spend, security and uptime, and draft the fix. A person approves every change.

[email protected]

Product

  • How it works
  • Free bill scan
  • Sample brief
  • How a build works
  • Integrations
  • Compare
  • Pricing

Trust

  • About
  • Security and access
  • Report a security issue

Legal

  • Terms
  • Privacy
  • Data processing
  • Subprocessors

Follow

  • LinkedIn
  • Facebook

© 2026 MarshalCloud

Read-only to connect. Nothing changes without your approval.