Decisions you can prove, not dashboards you have to trust.
Atlas Dig reads your AWS, Azure, and GCP accounts — read-only — and turns them into a knowledge graph with evidence behind every fact. Ask what depends on something. Decide if it's safe to remove. Get a deterministic answer, with the proof attached.
Your infrastructure record and your infrastructure disagree.
Three tools claim to know what's running. None of them can tell you what happens if you touch it.
A snapshot, not a system of record
It's accurate the day someone updates it, and wrong every day after. Nobody re-syncs a spreadsheet under deadline pressure.
State without consequence
A graph of resources tells you what exists. It doesn't tell you what breaks if you remove one, or who's still relying on it.
Confident, fluent, and sometimes wrong
A plausible-sounding answer with no evidence chain is worse than no answer — you find out which, in the incident review.
From raw cloud APIs to a decision with a paper trail.
Discover
Read-only connectors pull real state from AWS, Azure, and GCP. Every connector declares ReadOnly: true — Atlas Dig refuses to run one that doesn't.
Build the graph
Assets and relationships land in a Universal Knowledge Model. Every fact carries provenance, a freshness window, and a trust score.
Ask, or decide
Query in plain language, or run a real decision — remove, migrate — and get YES, NO, CONDITIONAL, or UNKNOWN. Never a guess dressed up as one.
Prove it
Every answer carries its evidence chain and lands in an append-only audit trail — the record you hand to the reviewer, not the one you reconstruct afterward.
Built for the team that has to answer for the decision.
Multi-cloud, read-only
AWS Organizations, Azure subscriptions, GCP projects — one command scans a whole org via cross-account AssumeRole, never standing credentials.
Provenance on every fact
No node in the graph exists without a source and a timestamp. Stale evidence is labeled stale, not silently trusted.
Deterministic decisions
remove returns YES, NO, CONDITIONAL, or UNKNOWN — the same input always produces the same verdict, with its reasoning attached.
Self-hosted, single-tenant
Runs inside your own infrastructure. Your inventory, evidence, and decisions never leave it — nothing phones home unless you opt in.
RBAC, SSO, and an audit trail
Role-based access, OIDC/SSO for enterprise identity, and an append-only log of every decision — built for the security review, not just the pilot.
Licensing that never breaks a build
A signed, offline license key — no license server. If a renewal lapses, only new discovery pauses; everything you've already found keeps working.
Built to pass the security review, not just the pilot.
Most tools ask for standing access and hope you don't read the IAM policy too closely. Atlas Dig is built the other way around: least privilege first, evidence for every claim, and nothing that leaves your environment unless you explicitly turn it on.
-
Read-only by contractEvery connector declares
ReadOnly: trueat compile time; Atlas Dig refuses to run one that doesn't. -
Cross-account AssumeRole, least privilegeEvery account is discovered through a role you grant, scoped to read-only. No long-lived credentials, ever.
-
Self-hosted, in your VPCYou run the containers. Your data stays on your infrastructure — there's no multi-tenant database to worry about.
-
Signed, offline license verificationNo license server, no outbound call to prove you're entitled to run it. Usage reporting is opt-in and previewable before you turn it on.
Priced by what you actually run, not by seats.
Annual, billed in advance, on the daily average of discovered assets — not the peak. Business-context entities you add yourself are never billed.
- AWS, Azure & GCP discovery
- Knowledge graph & evidence trail
- Deterministic remove decisions
- Self-serve checkout
- Email support
- Everything in Starter
- Multi-account AWS Organizations
- RBAC + OIDC/SSO
- Full audit trail & export
- Priority email support
- Everything in Growth
- Volume-based pricing
- Deployment & onboarding support
- Direct line to the founder
"Discovered asset" means an entity that came from a real discovery run. Teams, applications, capabilities, and runbooks you add to describe your own organization are never counted or billed.
Try it on your own infrastructure.
30 days, no credit card. The trial clock starts on your first successful discovery run — not the day you sign up.