Compare cloud services across providers
The same service, cloud by cloud. Each solution page puts the verified module for every provider we cover side by side - every module is statically validated and publish-checked, live-tested where marked. Pick the cloud; the verification comes with it.
Managed Relational Database
Managed relational databases (PostgreSQL, MySQL, and cloud-native engines like Aurora and AlloyDB) across clouds, provisioned by verified modules.
Secrets & Key Management
Secret stores and KMS (Key Vault, Secrets Manager, KMS, Vault) with verified, least-privilege modules.
DNS & Traffic Management
Authoritative DNS zones and traffic steering (Cloud DNS, Edge DNS, Route management) as verified modules.
Messaging & Pub/Sub
Message queues and pub/sub topics (SNS, SQS, Pub/Sub) for decoupled, event-driven systems, as verified modules.
Load Balancer
Application and network load balancers across clouds (ALB, Application Gateway, Cloud Load Balancing and more), as verified modules.
Virtual Machines
Virtual machine and instance modules (EC2, Compute, Droplets, servers) with secure defaults across clouds.
Virtual Private Cloud (VPC)
Private network foundations (VPC, VNet, VCN) with subnets, routing and security baselines, as verified modules.
Cloud Firewall
The free, stateful packet filter every cloud attaches to an instance or a network - AWS, Azure, OCI, IBM, Alibaba, Tencent, Huawei, Scaleway and Exoscale security groups, GCP firewall policies, and the cloud firewalls of DigitalOcean, Hetzner, Linode, Vultr, Civo, UpCloud and OVHcloud - written so it is attached to something and SSH is not open to the world.
Managed Kubernetes
Managed Kubernetes control planes (EKS, AKS, GKE, OKE, LKE, DOKS and more), each as a verified, plug-and-play module.
Object Storage
S3-compatible object storage buckets (AWS S3, GCS, Azure Storage, OCI, IBM COS, Alibaba OSS, Tencent COS, Huawei OBS, Linode, Cloudflare R2, DigitalOcean Spaces, Vultr, Scaleway, Civo, UpCloud, OVHcloud) with verified, secure-by-default modules.
Block Storage
The disk you attach to a virtual machine - EBS, Azure managed disks, GCP persistent disks, ECS, CBS and EVS disks, OCI, IBM and Scaleway block volumes, UpCloud storage, and the volumes of DigitalOcean, Hetzner, Linode, Vultr, Exoscale and Civo - with the question of who takes the snapshot answered rather than assumed.
Golden Images
Machine images built and versioned by the platform - EC2 Image Builder, Azure Compute Gallery, Compute Engine custom images - with a family or version that instances resolve, encryption with your key, and sharing by policy.
Container Registry
Private container image registries (ECR, ACR, Artifact Registry) with verified, access-scoped modules.
Identity & Access
Account-level identity foundations - roles, workload identities and the guardrails each cloud expects you to set once, before anything else lands.
In-Memory Cache
Managed Redis-compatible caches, provisioned with the network placement and failover settings already decided.
Shared File Storage
Managed NFS-style filesystems that many instances can mount at once, for workloads that need a POSIX path rather than an API.
Managed NoSQL Database
Key-value, document and wide-column databases - DynamoDB, Cosmos DB, Firestore, Bigtable, OCI NoSQL, Keyspaces, DocumentDB - with point-in-time recovery on and the endpoint private.
Serverless Functions
Event-driven function platforms (Lambda, Cloud Functions, Azure Functions, Workers) provisioned by verified modules.
CDN & Edge Delivery
Content delivery and edge platforms (CloudFront, Front Door, Akamai) provisioned by verified modules.
WAF & Edge Security
Web application firewalls and edge request filtering - managed rule sets, rate limits and IP controls in front of your origin.
NAT Gateway
Managed egress for private subnets - NAT Gateway on AWS and OCI, Azure NAT Gateway, Cloud NAT - with the routes written and the address stable.
Serverless Containers
Run containers without managing servers (Cloud Run, Container Apps, ECS Fargate, App Platform), as verified modules.
Monitoring & Observability
The native metrics, logs and alerting baseline for each cloud, wired up rather than left at defaults.
Managed Search
Managed search and analytics engines - OpenSearch on AWS and OCI, OpenSearch Serverless, Azure AI Search - configured so the endpoint is private and the index does not grow forever.
Static Site Hosting
Git-connected hosting for static sites and front ends - Amplify Hosting, Azure Static Web Apps, Cloudflare Pages - with preview branches that are not public by accident.
Managed TLS Certificates
Public certificates the platform issues and renews - ACM, Certificate Manager, Akamai CPS - validated by DNS records the module writes.
Network Peering
A private link between two networks - VPC peering, VNet peering, OCI local and remote peering - with the routes on both sides and the flags that make it carry traffic.
Audit Log Retention
The record of every management action - CloudTrail, the Azure Activity Log, Cloud Audit Logs, OCI Audit - kept for longer than the platform keeps it, somewhere it cannot be changed.
Cloud Data Warehouse
The managed analytical database - Redshift, BigQuery, Synapse dedicated SQL - with the endpoint private, access by identity, and the idle cost understood.
API Gateway
Managed API front doors - routing, authentication, throttling and quotas in front of your services, as verified modules.
Site-to-Site VPN
IPsec tunnels between your network and a cloud VPC - gateway, peer definition and connection, with BGP for routes that do not go stale.
Dedicated Interconnect
A private circuit from your network into the cloud - Direct Connect, ExpressRoute, Cloud Interconnect, FastConnect - with BGP, a redundant pair, and the encryption question answered.
Backup Service
The cloud-native backup service - AWS Backup, Azure Backup, Google Backup and DR - with a plan that is assigned to resources and a vault that refuses to lose them.
Managed CI/CD
The cloud-native pipeline services - CodePipeline, CodeBuild and CodeDeploy, Azure DevOps, Cloud Build and Cloud Deploy, OCI DevOps - with build logs kept, artifacts signed or scanned, and deploy approval where it belongs.
Transit Hub
The hub that connects many networks - Transit Gateway, Virtual WAN, DRG, Network Connectivity Center - with route tables that say which spoke may reach which.
Managed Spark
Managed Spark and Hadoop - EMR Serverless, HDInsight, Dataproc, Databricks on Azure - with the cluster in your network, the metastore outside it, and the bill understood before the first job.
Network Flow Logs
The record of every connection through a network - VPC Flow Logs, NSG and VNet flow logs, VCN flow logs - in the format an investigation needs, kept where it can be queried.
Security Posture & Findings
The cloud-native console that scores your estate and raises findings - Security Hub, Defender for Cloud, Security Command Center, Cloud Guard - configured so the findings reach a person.
Database Migration & CDC
Managed change-data-capture and migration services - DMS, Datastream, GoldenGate - that copy a database somewhere else and keep it in step.
Managed Network Firewall
The managed, stateful inspection appliance - AWS Network Firewall, Azure Firewall, OCI Network Firewall - that sits in the path of traffic, can open TLS and inspect what is inside, and bills by the hour whether or not a rule matches.
Private Instance Access
Reaching a private instance without a public SSH port - Session Manager, Azure Bastion, IAP TCP forwarding, the OCI Bastion service - with the session recorded and the port closed.
Organisation Guardrails
The policy layer that refuses a resource outright - service control policies, Azure Policy in deny mode, Organization Policy constraints, OCI Security Zones - as opposed to the posture services that report afterwards.
Private Service Endpoints
Reaching a service over the provider network rather than the internet - PrivateLink, Private Endpoint, Private Service Connect - so a database or an API has an address inside your network and none outside.
Private Certificate Authority
A managed CA for internal TLS - issuing, renewing and revoking certificates for services that never face the public internet.
Managed ML Platform
The managed notebook and training platform - SageMaker, Azure Machine Learning, Vertex AI, OCI Data Science - with the notebook off the internet and the data it reads encrypted with your key.
Transactional Email
The platform email service - SES, Azure Communication Services email, OCI Email Delivery - sending from a domain you own, with SPF, DKIM and DMARC published and bounces handled.
Managed App Platform
Platform-as-a-service for web applications - App Runner, App Service, App Engine - where you bring code or a container and the platform owns the servers, the scaling and the TLS.
Customer Identity
Sign-in for your customers rather than your staff - Cognito, Azure AD B2C, Identity Platform - with the social providers, MFA, sign-up throttling and the redirect allow-list set before the first user arrives.
Uptime Checks
Synthetic probes from outside the cloud - Route 53 health checks, Cloud Monitoring uptime checks, OCI Health Checks - with the alert that turns a failure into a page.
Landing Zone
The scaffolding every account, subscription or project inherits - Control Tower, the Azure management group hierarchy with policy, the GCP project factory - with logging, guardrails and identity set before the first workload.
Budgets & Cost Alerts
Spend thresholds on a billing account, subscription, compartment or project that notify somebody before the invoice does.
Patch Management
The service that patches a fleet on a schedule - Systems Manager Patch Manager, Azure Update Manager, VM Manager OS patch - with a baseline that says what is approved and a window that says when.
Managed ETL Pipelines
Serverless data integration - Glue, Data Factory, Dataflow - with jobs that run as a scoped identity and pipelines that alert when they fail.
Workflow Orchestration
Managed state machines - Step Functions, Logic Apps, Workflows - that call services in order, retry the right steps, and keep a record of every run.
HPC Parallel File Systems
Parallel file systems for HPC and training - FSx for Lustre, Azure Managed Lustre, Parallelstore - fronting an object store, with the durable copy in the bucket and the fast copy sized on the step.
Managed BI
Dashboards and reporting as a managed service - QuickSight, Looker (Google Cloud core), Oracle Analytics Cloud - signed in through your identity provider, reaching private data over a private path.
Data Transfer Service
Managed bulk copy into cloud storage - DataSync, Storage Transfer Service, Azure Storage Mover - from a file share or another bucket, with what happens to deleted files decided in advance.
Managed Active Directory
A domain the cloud runs - AWS Managed Microsoft AD, Entra Domain Services, Managed Microsoft AD on Google Cloud - with the legacy protocols off and the networks that may reach it named.
Zero Trust Application Access
Identity-based access to internal web applications without a VPN - Verified Access, Cloudflare Access, Identity-Aware Proxy - where the proxy checks who you are and what device you are on before the application sees a request.
Sensitive Data Discovery
Finding the sensitive data you did not know you had - Macie, Sensitive Data Protection, Microsoft Purview - scanning storage on a schedule, with findings that do not themselves leak the data.