How many SaaS tools does it take to change a light bulb?
At most startups, eleven. With SaneOS, one app.
SaneOS is a single app that maps your AWS and shows your engineers what is exposed, what is wasting money and what would stop you recovering. Rules decide what matters. AI explains it in plain words.
5 minutes to connect · one read-only role · no access keys · never writes to your cloud · no credit card · read the role
- Architecture diagrams$59
- Cost reports$199
- Drift detection$0 +1 login
- Cron monitoring$24
- SSL expiry alerts$12
- Uptime checks$34
- Attack-surface scans$99
- Status page$29
- Postmortems 8 seats$120
- Audit evidence$104
- IAM access review$99
Illustrative. Typical entry prices for single-purpose tools, Sep 2026.
Micro-SaaS tools, each seeing one slice of your cloud. None of them knows who owns the thing it just flagged.
Vendors holding a role in your production account. Each one is a questionnaire for your regulator and a door for an attacker.
People whose full-time job is security. The engineers who ship features also answer the auditor and the AWS bill.
Every app reads the same map of your cloud
Small tools each rebuild their own inventory. SaneOS builds one graph of resources, owners, changes, cost and access, and every app is a view on it. A cost spike, the change behind it and the team that owns it show up in the same place.
Every finding comes from a written rule and carries its path, owner, ticket and evidence hash. The AI writes the explanation and answers questions. It never scores risk or closes a finding.
One SaneMapReadOnly role per account, or one StackSet for the whole Organization. Metadata only. Secrets are dropped before anything is stored.
One question that used to take four tools
The bill, the change log, the network and the owner live in one graph, so the answer can cross them.
- Cost saw the spike.
- Change history found the route edit behind it.
- The map knows which VPC and service it belongs to.
- Ownership knows who to tell.
NAT Gateway data processing in payments-prod went from $38 to $451 a day, starting Tue 14:02 UTC. Four minutes earlier, the CI deploy role changed route table rtb-0a17 so the ledger service reaches S3 through the NAT gateway instead of the S3 endpoint.
- Owner
- payments-platform (tag team)
- Change
- ReplaceRoute · ci-deploy · 13:58 UTC
- Ticket
- PAY-1284
- Evidence
- sha256:9f2c…41ab · capture 14:30
Three jobs your engineers already have
See what the internet can reach, and who owns it
"Is anything open that shouldn't be?"
SaneMap draws every account, VPC and path from the internet. SaneSurface finds each public endpoint on its own, with no list to maintain, and flags open admin ports, new exposure and DNS records pointing at released addresses.
- Owner
- platform-team
- Ticket
- SEC-212 · opened in Jira
- Evidence
- DescribeSecurityGroups · sha256:c41d…e09a
Mock-up with example data. Every finding carries the path, the owner, a ticket and an evidence hash.
A morning cost digest that names the cause and the owner
"What did we spend yesterday, and why?"
SaneCost posts yesterday's spend to Slack or email, explains each jump with the change that caused it, and lists waste with a monthly price and an owner. Nothing is deleted for you. Your team decides.
| Waste | Owner | Per month |
|---|---|---|
| NAT traffic to S3 without an endpoint | payments-platform | $12,390 |
| 6 unattached EBS volumes | data-eng | $418 |
| 3 idle load balancers | no owner tag | $66 |
| 2 unused Elastic IPs | platform-team | $7 |
Mock-up with example data. AWS charges about $0.01 per Cost Explorer request; SaneCost reads once a day.
If an attacker gets in, can the business come back?
"Backups are on" is a different question.
SaneResilience checks each database, volume and bucket for a copy the intruder cannot delete or make unreadable, recent enough to use. SaneIncident builds the timeline of what changed when something breaks, and drafts the postmortem.
Mock-up with example data. States are decided by rules from captured evidence.
Start with the free map. Add apps when you need them.
Each app replaces a tool you may be paying for today. They all share one connection, one login and one bill.
Live diagram of every account, region and VPC, with exposure paths and what changed since last week.
Instead of diagram tools and hand-drawn architecture docsEvery public endpoint found from AWS itself, checked for uptime, open ports and dangling DNS.
Instead of uptime monitors and attack-surface scannersWhether each data store has a copy an attacker cannot delete, and how old it is.
Instead of spreadsheet backup auditsDaily digest, spikes tied to the change that caused them, and waste with owners.
Instead of cost report toolsExpiring certificates, failing schedules, root MFA, old keys and ownerless resources. No agent, no ping URL.
Instead of cron monitors and SSL expiry alertsInventory, diagrams and control evidence for SOC 2, ISO 27001 and PCI DSS audits, each item hashed and timestamped.
Instead of screenshot evidence and infra doc generatorsUnused roles, keys and permissions with owners, and review campaigns exported as evidence.
Instead of IAM review toolsTimeline of changes, deploys and alarms around an outage, with a drafted postmortem. Works with your pager.
Instead of postmortem toolsPublic status page driven by your endpoint checks and alarms, with approve-before-publish.
Instead of status page toolsManaged, hand-made and drifted resources compared with Terraform, and who changed them.
Instead of drift scripts nobody maintainsFintechs and startups where engineering owns everything
You have 20 to 200 engineers, a regulator or enterprise customers asking security questions, and no security team. SaneOS gives the people you already have one place to look.
"The auditor wants evidence and I'm the security team."
Weekly posture, cost and recovery summary. Evidence packs you can hand over with hashes and capture times.
"I pay for nine tools and still grep CloudTrail at 2am."
One connection, one inbox of findings with owners, and a timeline when something breaks.
"Why is AWS up 18% this month?"
A plain-language digest that names the change and the team behind every jump.
It only needs to look, so it can only look
Your security reviewer can read the whole role in five minutes. We publish it.
- One role, no keysYou create SaneMapReadOnly with CloudFormation. We assume it with an external ID only we generate. We never ask for access keys.
- Metadata, never dataAn explicit deny blocks S3 objects, database reads, secrets, parameters, logs, Lambda code and EC2 user data.
- Secrets dropped before storageEnvironment variable values are removed at capture, before anything is hashed or saved.
- Every call visible in your CloudTrailOur sessions are tagged sanemap-<workspace>. Delete the stack and access ends.
- Unknown is never safeA denied API or skipped region shows up as a coverage gap, never as a clean result.
# sanemap-readonly-role.yaml (excerpt) SaneMapReadOnly: Type: AWS::IAM::Role AssumeRolePolicyDocument: Principal: { AWS: arn:aws:iam::…:role/sanemap-collector } Condition: StringEquals: sts:ExternalId: !Ref ExternalId # generated by SaneMap Policies: - Allow: ec2:Describe* elasticloadbalancing:Describe* rds:Describe* route53:List* acm:Describe* backup:List* cloudtrail:LookupEvents … - Deny: s3:GetObject dynamodb:GetItem dynamodb:Query secretsmanager:GetSecretValue ssm:GetParameter* logs:GetLogEvents lambda:GetFunction ec2:GetConsoleOutput kms:Decrypt …
One bill instead of eleven
Beta prices. Design partners get the first months free.
Map
- SaneMap for your AWS accounts
- Exposure, network and change views
- Free outside-in attack-surface report
Apps
- Add Surface, Cost, Resilience and more as they ship
- Findings in Slack, email and Jira
- Plans at $99, $399 and $1,499 a month by estate size
Suite
- Every app, every account
- SSO, audit evidence packs
- A named engineer for onboarding and reviews
Change the light bulb once.
Connect one AWS account and see your map today. Add the apps you need when you need them.