Your whole cloud on one map, with its cost and its risks.
Skyline draws your infrastructure on AWS, Google Cloud, Azure and Oracle Cloud on a world map, region by region, and tells you what it costs and where it is exposed. It is the tool we use in every assessment, and you can use it yourself for free with read-only access.
Four views of the same estate.
Inventory, Terraform, security and cost share one data model, so a finding in the security report points at the same resource you see on the map and in the cost table.
Map and inventory
Every region with resources appears on the map, sized by how much lives there. Click one and you get its resources grouped by service, plus a dependency graph between them.
Terraform files and plans
Upload your .tf files or a whole project folder and see it before it exists. Load a terraform plan and Skyline shows what will be created, changed, replaced or destroyed.
Security report
Public buckets, open security groups, wildcard policies, unencrypted storage, stale access keys. Findings are ranked by severity with the resource and the fix for each one.
Cost estimate
Monthly estimate per region and per service from public price lists, and real spend from your billing export where it is available. Idle resources and oversized instances are flagged.
From sign-up to report in minutes.
Create an account
1 minuteEmail and password, or sign in with Google or LinkedIn. No card, no commitment, no sales call.
Load your infrastructure
2 minutesUpload .tf files, a project folder or a terraform plan in JSON. Or connect a cloud account with a read-only role. Skyline first checks the credentials cannot write and refuses them if they can.
Explore and download
As long as you likeBrowse the map, open the dependency graph, read the findings and export the security and cost reports to share with your team.
Four clouds, one scope model.
Live scans read the whole scope you point them at. Terraform files and plans work for any provider Skyline supports, with or without cloud access.
| Provider | Live scan scope | Access needed | Cost data |
|---|---|---|---|
| AWS | One account, all regions | IAM role or keys with ReadOnlyAccess | Public price list; Cost Explorer where allowed |
| Google Cloud | Project, folder or entire organisation | Service account or ADC with viewer roles | Public price list; billing export where available |
| Azure | Subscription or management group | Service principal or CLI login with Reader | Public price list; Cost Management where allowed |
| Oracle Cloud | Whole tenancy | API key with read-only policies | Public price list |
| Terraform | .tf files, folders and plan JSON | None | Estimate from the plan |
What the security report looks for.
- Publicly readable or writable storage buckets
- Security groups and firewall rules open to the internet on sensitive ports
- IAM policies with wildcard actions or resources, and users without MFA
- Access keys older than ninety days or unused
- Unencrypted disks, databases and storage
- Databases and Kubernetes control planes with public endpoints
- Functions on deprecated runtimes
- Missing audit logging or detection services
Each finding carries a severity, the resource it points at and the change that closes it, ready to paste into a ticket.
What the cost estimate flags.
- Monthly estimate per region, per service and per resource
- Instances and databases stopped or idle for weeks
- Oversized instances relative to their observed use
- Unattached disks and addresses, old snapshots
- Data transfer between regions that could stay local
- Resources without owner or environment tags
- Real spend from your billing export next to the estimate, where available
Estimates come from the providers' public price lists. They are meant for prioritising, not for replacing your bill.
Before you connect an account.
Is Skyline really free?
Yes. The account, the scans and the reports are free. We build it for our own assessments and we would rather you see your estate clearly, even if you never hire us.
Do you store my cloud credentials?
No. Credentials are used in memory for the scan you request and discarded when it finishes. Before scanning, Skyline checks that they cannot write and refuses them if they can. The scan results are stored with your account so you can revisit them, and you can delete them at any time.
Can I use it without giving access to any cloud?
Yes. Upload your Terraform files or a plan and Skyline builds the map, the security findings and the cost estimate from the code alone.
Does it change anything in my account?
No. Skyline only reads. It never creates, modifies or deletes resources, and it refuses credentials with write permissions.
Where does the data live?
On Amazon Web Services in the European Union. See the privacy policy for the details.
See your cloud on the map today.
Create a free account and load a Terraform plan or connect a read-only role. If you would rather we do it with you, ask for an assessment.