SaneOS · Fewer tools. Saner cloud.

How many SaaS tools does it take to change a light bulb?

At most startups, eleven. With SaneOS, one app.

SaneOS is a single app that maps your AWS and shows your engineers what is exposed, what is wasting money and what would stop you recovering. Rules decide what matters. AI explains it in plain words.

5 minutes to connect · one read-only role · no access keys · never writes to your cloud · no credit card · read the role

Your cloud tool billSep 2026
  1. Architecture diagrams$59
  2. Cost reports$199
  3. Drift detection$0 +1 login
  4. Cron monitoring$24
  5. SSL expiry alerts$12
  6. Uptime checks$34
  7. Attack-surface scans$99
  8. Status page$29
  9. Postmortems 8 seats$120
  10. Audit evidence$104
  11. IAM access review$99
Total$779 / mo
Vendors to security-review11
Vendors with a role in your AWS6
Places a finding can hide11

Illustrative. Typical entry prices for single-purpose tools, Sep 2026.

Replacedby a single app
11

Micro-SaaS tools, each seeing one slice of your cloud. None of them knows who owns the thing it just flagged.

6

Vendors holding a role in your production account. Each one is a questionnaire for your regulator and a door for an attacker.

0

People whose full-time job is security. The engineers who ship features also answer the auditor and the AWS bill.

One stack

Every app reads the same map of your cloud

Small tools each rebuild their own inventory. SaneOS builds one graph of resources, owners, changes, cost and access, and every app is a view on it. A cost spike, the change behind it and the team that owns it show up in the same place.

asks
Rules decide · AI explains

Every finding comes from a written rule and carries its path, owner, ticket and evidence hash. The AI writes the explanation and answers questions. It never scores risk or closes a finding.

reads
One context graph
resourcesnetwork pathsownerschangescostpublic endpointsidentitiesbackupsevidence
collects every 6 hours
Your AWS accounts

One SaneMapReadOnly role per account, or one StackSet for the whole Organization. Metadata only. Secrets are dropped before anything is stored.

Ask across everything

One question that used to take four tools

The bill, the change log, the network and the owner live in one graph, so the answer can cross them.

  • Cost saw the spike.
  • Change history found the route edit behind it.
  • The map knows which VPC and service it belongs to.
  • Ownership knows who to tell.
Why did AWS cost jump 18% on Tuesday?

NAT Gateway data processing in payments-prod went from $38 to $451 a day, starting Tue 14:02 UTC. Four minutes earlier, the CI deploy role changed route table rtb-0a17 so the ledger service reaches S3 through the NAT gateway instead of the S3 endpoint.

Owner
payments-platform (tag team)
Change
ReplaceRoute · ci-deploy · 13:58 UTC
Ticket
PAY-1284
Evidence
sha256:9f2c…41ab · capture 14:30
Rule COST-SPIKE-03 decidedAI wrote the explanationExample data
Security · Cost · Resilience

Three jobs your engineers already have

Secure

See what the internet can reach, and who owns it

"Is anything open that shouldn't be?"

SaneMap draws every account, VPC and path from the internet. SaneSurface finds each public endpoint on its own, with no list to maintain, and flags open admin ports, new exposure and DNS records pointing at released addresses.

SaneMap · payments-prod · Exposure view
VPC payments-prod · ap-south-1 public subnet private subnet 0.0.0.0/0 → 22 Internet api-alb :443 bastion-old SSH open ledger-1 ledger-2 ledger-db
SSH open to the internet on bastion-oldHigh
Internet→igw-3c1→sg-legacy-admin :22→i-0b7e bastion-old
Owner
platform-team
Ticket
SEC-212 · opened in Jira
Evidence
DescribeSecurityGroups · sha256:c41d…e09a

Mock-up with example data. Every finding carries the path, the owner, a ticket and an evidence hash.

Save

A morning cost digest that names the cause and the owner

"What did we spend yesterday, and why?"

SaneCost posts yesterday's spend to Slack or email, explains each jump with the change that caused it, and lists waste with a monthly price and an owner. Nothing is deleted for you. Your team decides.

SaneCost · #eng-aws · Wed 08:00
$1,284+18%
Yesterday
$27.9k
Month to date
$36.1k
Forecast · Sep
16 Sep29 Sep
WasteOwnerPer month
NAT traffic to S3 without an endpointpayments-platform$12,390
6 unattached EBS volumesdata-eng$418
3 idle load balancersno owner tag$66
2 unused Elastic IPsplatform-team$7

Mock-up with example data. AWS charges about $0.01 per Cost Explorer request; SaneCost reads once a day.

Recover

If an attacker gets in, can the business come back?

"Backups are on" is a different question.

SaneResilience checks each database, volume and bucket for a copy the intruder cannot delete or make unreadable, recent enough to use. SaneIncident builds the timeline of what changed when something breaks, and drafts the postmortem.

SaneResilience · attacker with admin in payments-prod
ledger-db (Aurora)RecoverableCopy in backup account under compliance lock, 3 h old
kyc-documents (S3)DeletableVersioning on, but the same account can delete old versions
sessions (DynamoDB)StaleOnly safe copy is 9 days old; target is 24 h
reports-efsNo copyNo backup plan selects it
eu-west-1UnknownRegion not scanned. Unknown is never shown as safe.
13:58ci-deploy replaced a route in rtb-0a17
14:025xx alarm on api-alb · suspected change ranked #1 by time and graph distance

Mock-up with example data. States are decided by rules from captured evidence.

All products

Start with the free map. Add apps when you need them.

Each app replaces a tool you may be paying for today. They all share one connection, one login and one bill.

SaneMapLive · free

Live diagram of every account, region and VPC, with exposure paths and what changed since last week.

Instead of diagram tools and hand-drawn architecture docs
SaneSurfaceEarly access

Every public endpoint found from AWS itself, checked for uptime, open ports and dangling DNS.

Instead of uptime monitors and attack-surface scanners
SaneResilienceEarly access

Whether each data store has a copy an attacker cannot delete, and how old it is.

Instead of spreadsheet backup audits
SaneCostComing

Daily digest, spikes tied to the change that caused them, and waste with owners.

Instead of cost report tools
SaneChecksComing

Expiring certificates, failing schedules, root MFA, old keys and ownerless resources. No agent, no ping URL.

Instead of cron monitors and SSL expiry alerts
SaneAuditComing

Inventory, diagrams and control evidence for SOC 2, ISO 27001 and PCI DSS audits, each item hashed and timestamped.

Instead of screenshot evidence and infra doc generators
SaneAccessComing

Unused roles, keys and permissions with owners, and review campaigns exported as evidence.

Instead of IAM review tools
SaneIncidentComing

Timeline of changes, deploys and alarms around an outage, with a drafted postmortem. Works with your pager.

Instead of postmortem tools
SaneStatusComing

Public status page driven by your endpoint checks and alarms, with approve-before-publish.

Instead of status page tools
SaneDriftComing · free

Managed, hand-made and drifted resources compared with Terraform, and who changed them.

Instead of drift scripts nobody maintains
Built for

Fintechs and startups where engineering owns everything

You have 20 to 200 engineers, a regulator or enterprise customers asking security questions, and no security team. SaneOS gives the people you already have one place to look.

CTO or head of engineering
"The auditor wants evidence and I'm the security team."

Weekly posture, cost and recovery summary. Evidence packs you can hand over with hashes and capture times.

Platform or DevOps lead
"I pay for nine tools and still grep CloudTrail at 2am."

One connection, one inbox of findings with owners, and a timeline when something breaks.

Founder or finance
"Why is AWS up 18% this month?"

A plain-language digest that names the change and the team behind every jump.

Read-only by design

It only needs to look, so it can only look

Your security reviewer can read the whole role in five minutes. We publish it.

  • One role, no keysYou create SaneMapReadOnly with CloudFormation. We assume it with an external ID only we generate. We never ask for access keys.
  • Metadata, never dataAn explicit deny blocks S3 objects, database reads, secrets, parameters, logs, Lambda code and EC2 user data.
  • Secrets dropped before storageEnvironment variable values are removed at capture, before anything is hashed or saved.
  • Every call visible in your CloudTrailOur sessions are tagged sanemap-<workspace>. Delete the stack and access ends.
  • Unknown is never safeA denied API or skipped region shows up as a coverage gap, never as a clean result.
# sanemap-readonly-role.yaml (excerpt)
SaneMapReadOnly:
  Type: AWS::IAM::Role
  AssumeRolePolicyDocument:
    Principal: { AWS: arn:aws:iam::…:role/sanemap-collector }
    Condition:
      StringEquals:
        sts:ExternalId: !Ref ExternalId   # generated by SaneMap
  Policies:
    - Allow:  ec2:Describe*  elasticloadbalancing:Describe*
              rds:Describe*  route53:List*  acm:Describe*
              backup:List*  cloudtrail:LookupEvents  …
    - Deny:   s3:GetObject  dynamodb:GetItem  dynamodb:Query
              secretsmanager:GetSecretValue  ssm:GetParameter*
              logs:GetLogEvents  lambda:GetFunction
              ec2:GetConsoleOutput  kms:Decrypt  …
Pricing

One bill instead of eleven

Beta prices. Design partners get the first months free.

Map

Free
  • SaneMap for your AWS accounts
  • Exposure, network and change views
  • Free outside-in attack-surface report
Map my AWS free

Apps

$99 / month and up
  • Add Surface, Cost, Resilience and more as they ship
  • Findings in Slack, email and Jira
  • Plans at $99, $399 and $1,499 a month by estate size
Start with the map

Suite

$10k / year and up
  • Every app, every account
  • SSO, audit evidence packs
  • A named engineer for onboarding and reviews
Talk to usasolia83@gmail.com
Five minutes, one app

Change the light bulb once.

Connect one AWS account and see your map today. Add the apps you need when you need them.