Marshal watches spend, security exposure and customer uptime across AWS, Google Cloud and Kubernetes, explains what changed, and drafts the fix for you to approve.
Observe
Reads billing, resources, security settings and uptime, read-only.
Understand
Names what changed, what it costs, and who owns it.
Draft the fix
An allowlisted change, priced from your own bill, undo stated plainly.
You approve
Nothing runs until a person presses the button.
Waiting for youAct
Rechecks live conditions, then makes the one change approved.
Verify
Confirms the result and writes the audit trail.
Deepest on AWS, with Google Cloud and Kubernetes alongside it.
What you get back
Not four dashboards to check. One investigation that says what changed, what it costs, and what to do next.
The change that caused it, the resource behind it, and the team that owns it, priced from your own billing data.
Data transfer is up week over week
The increase traces to one service that started reading from a bucket in another region after a deployment. Marshal shows the billing rows it used and the change that preceded them.
Dollar figures come from your own billing data. When Marshal cannot price something confidently it says so instead of guessing.
Public access, drift and stale keys, checked continuously. A check that did not finish reads as unknown, never as a pass.
Storage bucket readable by anyone
Public read on a bucket holding customer uploads.
Admin key not rotated
A long-lived access key with broad permissions.
Backup coverage unknown
The last scan did not complete, so this is not a pass.
Findings map to common frameworks as readiness guidance. Marshal is not a certification and does not claim one.
Uptime and certificate checks from outside your cloud. A failure opens an incident and pages whoever is on call.
Checkout stopped answering
Two checks from different regions failed in a row. Marshal opened an incident, paged the rotation on duty, and started the timeline before anyone had to notice. Paging needs an on-call rotation set up first.
A status page can share the same incident with your customers while it is still open.
The gap
Directional, from each product's public positioning. Marshal does not replace a deep security scanner or paging system. It connects cost, risk and reliability to one safe next action.
| Product | Cost intelligence | Security posture | SRE / SLA | Approval-gated action | Cross-domain loop |
|---|---|---|---|---|---|
Marshal One operating loop for lean teams | |||||
Vantage / Pump FinOps-first | · | · | |||
Datadog Observability-first | · | · | · | ||
PagerDuty Incident-response-first | |||||
Wiz / Prowler Security-first |
Who it is for
A team under thirty people cannot staff an SRE, a security lead and an SLA owner separately. Pick the seat you sit in.
Checks run from outside your cloud, a failure is confirmed before anyone is woken, and the incident writes most of its own record.
Paging needs a rotation set up first. Until you configure one, Marshal alerts rather than pages.
Checkout stopped answering
The failure was confirmed from a second location before anyone was paged. With only one location configured, the check is labelled single-location rather than confirmed.
Paging needs an on-call rotation set up first. The timeline you build during the incident becomes the postmortem draft.
Answers you have already approved come back on the next questionnaire, each one carrying the evidence it was drafted from.
This is the questionnaire and evidence half of compliance work. It is not continuous control monitoring across your HR, device and vendor systems, and readiness evidence is not certification.
Is data encrypted at rest?
Drafted from an answer you already approved, with a citation to what it came from. Signed once, reused on the next questionnaire.
Do you run background checks on staff?
Nothing in Marshal supports an answer, so it is left for a person instead of drafted.
Framework mapping is readiness evidence, not a certification, and Marshal does not claim one.
The same checks that page your team produce the report you send out, measured from outside the cloud they are grading.
Marshal reports the uptime it measured for you. It does not promise a number, and a period with missing checks says so rather than counting as up.
Ninety days of checks, taken from outside
Uptime and certificate checks run outside your cloud, so the report is not your own infrastructure grading itself. Marshal reports what it measured and nothing more.
No target percentage is promised here. The report shows the checks that ran and the ones that did not.
Your exposure
84% of cloud teams name spend as their hardest problem, and the money is not the worst of it: the outage you hear about from a customer, and the bucket that was public for a month, both start the same way. Nobody was looking.
$6,000
$1,740/month
is probably buying nothing
The industry puts wasted cloud spend at 29%. Idle servers, disks nobody attached, oversized databases. The hard part is not the number, it is which line it is.
Flexera 2026 State of the Cloud Report · 753 cloud decision-makers$1,020/month
past what you planned
Cloud budgets run 17% over. The overrun does not arrive as an alert, it arrives as an invoice you already owe.
Flexera 2025 State of the Cloud Report · 750+ technical professionals and executives$600max credit
is all an outage gets back
AWS pays 10% of the bill when uptime lands in the 99.0% to 99.99% band. It is not automatic: you claim it by the end of the second billing cycle after the incident, and you attach request logs documenting the errors, with resource IDs and times. No monitoring, no evidence, no credit.
Amazon Compute Service Level AgreementThese are benchmarks against a number you typed, not a reading of your account. Marshal will not guess at your bill. Connect one AWS account read-only and every figure here is replaced by your own billing data, priced at the rate you actually pay, with the rows it came from attached.
Marshal is $0 to start and read-only to connect. The cheapest way to find out whether any of this is true of your account is to look.
The gate
Other tools tell you what is wrong and stop. Marshal drafts the exact fix, shows the dollar impact, and waits for you.
Stop staging-worker-03
No application connection or customer dependency was observed. The disks survive and the instance can be started again. The open security group remains a separate finding.
Build
A network, a container platform, a database, a Kubernetes cluster: Marshal plans it, prices it, backs up first, and waits for a person to approve it. The same gate as every other change here.
Brief
Say what you need in plain words.
Plan and price
The exact changes, their cost, and what could go wrong.
Back up
A restore point first, or the change stops.
You approve
Production needs a second approver.
Waiting for youBuild
Applied on AWS today. Other clouds plan only.
Getting started
Same loop every time, and it stops in the same place every time: on you.
Step one
One AWS role that can look but not touch. Two minutes, and you can delete it from your own account whenever you like. Google Cloud and Kubernetes have their own documented connection paths.
Step two
Cost, security, resource health and customer uptime examined as one problem. You see which data has arrived and which is still catching up.
Step three
An allowlisted change with the dollar impact priced from your own bill, a plain-language plan, and one sentence on whether it can be undone.
Step four
Nothing runs until a person presses the button. The executor rechecks live conditions, acts, and logs every step for the audit.
Start free for visibility. Every paid plan includes 15 days free, with limits that are clear before you connect a cloud account.
See one AWS account clearly.
Free forever
See risk and waste before they compound.
15-day free trial
Investigate the cause. Approve the fix.
15-day free trial
Operate a multi-cloud estate with room to grow.
15-day free trial
Read-only, free, and reversible from your own account. You will see what Marshal found before you decide anything.