Skip to content
Public overview

Platform Coverage

Continuous detection coverage across your cloud

Varcio continuously watches AWS, Azure, Google Cloud, and Oracle Cloud for wasted spend and risky configuration — across the services you already run in production.

363+ automated checks across 4 clouds
See a free savings preview
Read-only by defaultCredentials encrypted at restNo agents to install

363+

Automated checks

Across compute, storage, network, database & security

4

Major clouds

AWS, Azure, Google Cloud, Oracle Cloud

6

Monitoring disciplines

One consistent model per provider

Continuous

Evaluation cadence

Not a once-a-quarter audit

What we monitor

Every check we run falls into one of these disciplines, regardless of which cloud it runs against.

Compute & Workloads

Right-size virtual machines, containers, and serverless functions, and surface capacity that's sitting idle or oversized for what it actually runs.

Storage & Backups

Catch orphaned disks, aging snapshots, and storage tiers that quietly cost more than the data sitting in them is worth.

Networking & Connectivity

Find unused IP addresses, idle load balancers, and data-transfer paths that are routing spend less efficiently than they should.

Databases & Caching

Flag oversized database and cache instances, unused replicas, and reserved-capacity commitments that aren't being fully used.

Security & Governance

Watch for overly open network access, missing encryption, and identity hygiene gaps — the kind of drift that turns into risk if it goes unnoticed.

Specialized Services

Provider-specific coverage for the services that don't fit a generic bucket — content delivery, managed app platforms, and commitment programs.

Coverage by cloud provider

Coverage depth varies slightly by provider based on the services available in each ecosystem, and it grows continuously as new services and patterns are added.

Amazon Web Services

103 checks
Security & Governance
23
Compute & Workloads
21
Networking & Connectivity
20
Storage & Backups
18
Databases & Caching
17
Specialized Services
4

Microsoft Azure

95 checks
Networking & Connectivity
21
Security & Governance
19
Storage & Backups
18
Compute & Workloads
17
Databases & Caching
16
Specialized Services
4

Google Cloud

90 checks
Storage & Backups
18
Compute & Workloads
17
Networking & Connectivity
17
Security & Governance
17
Databases & Caching
16
Specialized Services
5

Oracle Cloud Infrastructure

75 checks
Compute & Workloads
15
Storage & Backups
15
Networking & Connectivity
15
Databases & Caching
15
Security & Governance
15

Real services, not generic buckets

A sample of the actual resource types checks run against — compute, database, storage, and network services you already run in production.

AWS
EC2RDSS3 & EBSLambdaRedshiftElastiCacheDynamoDBCloudFrontELBEFSECRSecrets Manager
Azure
Virtual MachinesAzure SQLBlob StorageManaged DisksCosmos DBAKSApp ServiceLoad BalancerApp GatewayCache for RedisSynapseKey Vault
Google Cloud
Compute EngineCloud SQLCloud StorageBigQueryGKEMemorystoreCloud RunPersistent DiskCloud CDNSpannerPub/SubCloud Functions
Oracle Cloud
Compute InstancesAutonomous DatabaseBlock VolumeObject StorageMySQL DB SystemLoad BalancerVCN & DRGOKEFile StorageNoSQL Database

Methodology

How detection actually works

Not a single threshold trip — a pipeline built to be accurate, explainable, and safe on production accounts.

1

Secure connection

Scoped, read-only role. No static admin keys.

2

Continuous signal collection

Native telemetry, billing & config data. No agents.

3

Multi-factor analysis

Utilization + configuration + spend, combined.

4

Evidence-backed output

Severity, savings, confidence, and a fix — per finding.

Accuracy

Built for accuracy, not alert fatigue

Cost and governance tooling loses trust the moment it cries wolf. Every part of the pipeline is built around not doing that.

Every finding is scored

Confidence and risk calculated per finding, so your team triages by what's most certain first.

Evidence, not assertion

Every result ships with the metrics and resource context behind it — verify before you act.

Smart suppression

Resolved findings stay quiet for a cooldown window instead of immediately re-firing.

Deduplicated by design

Keyed to the specific resource and condition — the same issue never surfaces twice.

Workflow

From finding to fix

Detection is only useful if it closes the loop. Every finding has a lifecycle, an owner, and an audit-ready trail.

1. Detected

A check fires against live account signal and produces a scored, evidence-backed finding.

2. Triaged

Findings land in a governance queue with ownership, severity, and SLA-breach tracking — a real inbox, not a static report.

3. Resolved

Cost-backed findings route straight to a guided remediation flow; everything else is closed out with an audit-ready evidence trail.

Security-first

Built to be safe to connect on day one

We designed the connection model around the question every security team asks first: what is the blast radius if this integration is compromised?

Least-privilege, read-only access

Detection runs entirely on read-only, scoped roles — no write access needed.

Encrypted credentials, per connection

Identifiers encrypted at rest; every connection validated with a unique external ID.

Write actions are opt-in and gated

Remediation is a separate, permissioned capability behind an approval workflow.

Nothing installed in your environment

No agents or daemons. Everything runs through each provider's own APIs.

Frequently asked questions

Do you need write access to our cloud accounts?

No. Detection runs entirely on read-only, least-privilege roles. Write access is only ever requested for optional remediation actions, which are separately permissioned and require explicit approval.

How often does coverage run?

Continuously. Coverage re-evaluates as your usage and configuration change, rather than on a fixed monthly or quarterly cadence — so findings stay current without anyone kicking off a manual scan.

Do we need to install anything?

No agents, daemons, or sidecars. Everything runs against your cloud provider's own APIs from a secure, scoped connection you control and can revoke at any time.

How do you keep this from becoming another noisy alert feed?

Every finding is confidence-scored, backed by evidence, deduplicated to its underlying resource, and suppressed for a cooldown window once resolved — the same finding won't just reappear the next day.

Is this a replacement for our cloud security tooling?

No — it's a cost and governance layer that also surfaces configuration and access risk. It's designed to complement dedicated security and compliance tooling, not replace it.

How does coverage grow over time?

New checks are added continuously as cloud providers ship new services and as we identify new waste and risk patterns — coverage depth grows without any action needed on your side.

Want to see what this looks like against your own cloud bill?

No account required — upload a billing export and get a savings preview in minutes.