Pular para o conteudo principal
cumulus
Português

AWS cost governance with enforcement in minutes, not hours

Cumulus reads usage metrics from your AWS accounts every ~1 minute via CloudWatch, estimates the cost and climbs a graduated enforcement ladder — from alert to stop — with simulation, an explanation for every decision and an audit trail. Tools that depend on the billing report (CUR) take hours to notice the same spend.

Born from one semester in production at a Brazilian college, with 49 student accounts governed.

  • Data stays in your AWS account
  • Native PT-BR, not machine-translated
  • AWS Marketplace listing in preparation
Account sandbox-dev-07
Policy dev-sandbox
Month-to-date estimateof USD 50.00
USD 39.2078%
Enforcement ladderT3 Throttle active
  1. T0
  2. T1
  3. T2
  4. T3
  5. T4
Decision timeline
  1. Usage detected: 3 t3.large instances started
  2. Estimate updated: +USD 0.25/h, 78% of budget
  3. T3 Throttle applied: creation of new expensive resources blocked
  4. Record sealed in the audit trail (actor: policy dev-sandbox)
Simulation Mode: off for this policy12 i18n
Illustrative example of the enforcement panel
How it works

Three steps, starting read-only

You don't hand over the power to act on day one. First you watch what Cumulus would do; then you enable the ladder one rung at a time.

  1. 01. Connect

    A cross-account role in your account gives Cumulus read access to CloudWatch metrics. In Edu, student accounts are created through AWS Organizations in a dedicated OU with protective SCPs.

  2. 02. Watch in Simulation Mode

    Cumulus computes every full decision — tier, action, targets — and records what would happen, without executing. You see the explanation for each one before giving it the power to act.

  3. 03. Enable the ladder per account, tag or environment

    Choose how high each environment may climb: prod stays at observe/alert, dev may reach throttle, sandbox may reach stop. Actions never skip rungs.

Enforcement

A graduated ladder, not a kill switch

Five rungs, from no-action to stop. Each account's ceiling is configurable, and the effective action is always the lesser of what the tier asks for and what the mode allows.

  1. T0

    Observe

    Visibility and cost estimate. Zero action.

    default in prod

  2. T1

    Alert

    Notifies the owner when the threshold is crossed.

    default in prod

  3. T2

    Require-approval

    New spend above the limit needs approval before it proceeds.

    suggested in staging

  4. T3

    Throttle

    Selectively blocks the creation of expensive resources.

    suggested in dev

  5. T4

    Stop

    Stops non-prod resources and applies DenyAll.

    sandbox, explicit opt-in

effective action = min(requested tier, mode ceiling)

Never-stop-prod

An account or resource tagged prod never receives an automatic throttle or stop: the action is downgraded to require-approval.

Break-glass

A global operator switch that suspends all enforcement. No per-resource override can turn it back on.

Opt-in per tier

Every rung above Alert is enabled explicitly by you, per account, tag or environment.

Signal latency

Hours versus ~1 minute — and why it changes what you can do

Governance that reacts to the bill arrives after the spend. Cumulus reacts to usage.

Bill-based tools

hours
  • The AWS Cost and Usage Report (CUR) is updated up to three times a day.
  • The first report can take up to 24 hours to appear.
  • By the time the spend shows up, the resources have been running for hours.

Cumulus

~1 min
  • Collects usage metrics from CloudWatch (instances, invocations, GB) every ~1 minute.
  • Multiplies usage by the price catalog and estimates the cost on the spot.
  • The enforcement ladder can act minutes after usage starts.
Trust

For a tool that can stop resources, trust is the product

Every decision can be simulated, explained and audited — and raw data never leaves your account.

Simulation Mode

Run any policy as a dry-run: Cumulus computes the whole decision and records what would happen, without executing. For a whole account or a single resource.

An explanation for every decision

Every action ships with its why: which metric crossed which threshold, which tier resulted and which guardrail applied. Rendered in 12 languages.

Audit trail with identity

Each record keeps who configured, who or what triggered and what was decided, hash-chained. Removing or editing a record mid-chain becomes evident — not even the actor can erase their own trace.

Data stays in your account

In the FinOps edition, collection and enforcement run inside your AWS account. Only aggregated metrics reach Outrun's control plane.

Two editions, one core

Built for those who govern student accounts and for those who govern production accounts

Same detection, estimation and enforcement engine. Different stakeholders and defaults.

Cumulus Edu

Universities and bootcamps

For course coordinators, faculty and institutional IT

Each student gets their own AWS account, with a budget set by the institution and hard enforcement in the sandbox. Students learn cloud with the cost trail visible; the college is never surprised by the bill.

  • One account per student via AWS Organizations, in a dedicated OU with SCPs
  • Budget per student and per class, with faculty and coordinator views
  • Hard enforcement in the sandbox: a student cannot take the institution down
  • Native PT-BR; i18n engine aligned with the AWS Console's 12 locales (en and pt-BR catalogs ready)
  • Born from one semester in production, 49 student accounts governed
See a demo for universities
Cumulus FinOps · early access

Companies with existing AWS accounts

For platform, FinOps and security teams

Governance over the accounts you already have, with enforcement tiers per account, tag or environment, production guardrails and an audit trail. The data plane runs in your account.

  • T0–T4 tiers configurable per account, tag or environment
  • Never-stop-prod, break-glass and explicit opt-in per tier
  • Simulation Mode as the recommended onboarding default
  • Collection and enforcement in your account; only aggregates leave
  • AWS Marketplace distribution in preparation
See a demo for companies
FAQ

The objections we hear first

What IAM permissions does Cumulus need in my account?

To observe, a cross-account role with read access to CloudWatch metrics. You start in Observe or Simulation Mode with no action permissions at all. Enforcement permissions come in only for the tiers you explicitly enable, per account, tag or environment.

What if Cumulus stops production?

It doesn't. An account or resource tagged prod never receives an automatic throttle or stop: the action is downgraded to require-approval. There is a global break-glass that suspends all enforcement and that no per-resource override can turn back on. And the effective action is always the lesser of what the tier asks for and the ceiling configured for that environment.

How does Cumulus connect to my accounts?

In Edu, student accounts are created through AWS Organizations in a dedicated OU with protective SCPs, and Cumulus governs them from the institution's account. In FinOps, the data plane (collection and enforcement) is deployed into your account and only aggregated metrics reach the control plane. Onboarding details are agreed with you during early access.

Is it on the AWS Marketplace?

In preparation. Today access is direct with Outrun, as early access.

Which languages?

Twelve languages, aligned with the AWS Console, with native PT-BR. That includes the explanation for each enforcement decision, not just the interface.

How much does it cost?

On request, as early access. Edu and FinOps are priced separately. Talk to us and get a proposal for your scenario.

cumulus

Watch Cumulus decide, with the explanation right beside it

A 30-minute demo with the real panel, in Simulation Mode, on a scenario close to yours.

You are from

The button opens your e-mail client with a message ready for go@outrundata.com. No data is sent through this website.

Or write directly to go@outrundata.com

Cumulus is an Outrun Data Solutions product. AWS and CloudWatch are trademarks of Amazon Web Services, Inc.