Compare cloud services across providers

The same service, cloud by cloud. Each solution page puts the verified module for every provider we cover side by side - every module is statically validated and publish-checked, live-tested where marked. Pick the cloud; the verification comes with it.

25 verified modules

Managed Relational Database

Managed relational databases (PostgreSQL, MySQL, and cloud-native engines like Aurora and AlloyDB) across clouds, provisioned by verified modules.

23 verified modules

Secrets & Key Management

Secret stores and KMS (Key Vault, Secrets Manager, KMS, Vault) with verified, least-privilege modules.

23 verified modules

DNS & Traffic Management

Authoritative DNS zones and traffic steering (Cloud DNS, Edge DNS, Route management) as verified modules.

22 verified modules

Messaging & Pub/Sub

Message queues and pub/sub topics (SNS, SQS, Pub/Sub) for decoupled, event-driven systems, as verified modules.

21 verified modules

Load Balancer

Application and network load balancers across clouds (ALB, Application Gateway, Cloud Load Balancing and more), as verified modules.

21 verified modules

Virtual Machines

Virtual machine and instance modules (EC2, Compute, Droplets, servers) with secure defaults across clouds.

19 verified modules

Virtual Private Cloud (VPC)

Private network foundations (VPC, VNet, VCN) with subnets, routing and security baselines, as verified modules.

17 verified modules

Cloud Firewall

The free, stateful packet filter every cloud attaches to an instance or a network - AWS, Azure, OCI, IBM, Alibaba, Tencent, Huawei, Scaleway and Exoscale security groups, GCP firewall policies, and the cloud firewalls of DigitalOcean, Hetzner, Linode, Vultr, Civo, UpCloud and OVHcloud - written so it is attached to something and SSH is not open to the world.

16 verified modules

Managed Kubernetes

Managed Kubernetes control planes (EKS, AKS, GKE, OKE, LKE, DOKS and more), each as a verified, plug-and-play module.

16 verified modules

Object Storage

S3-compatible object storage buckets (AWS S3, GCS, Azure Storage, OCI, IBM COS, Alibaba OSS, Tencent COS, Huawei OBS, Linode, Cloudflare R2, DigitalOcean Spaces, Vultr, Scaleway, Civo, UpCloud, OVHcloud) with verified, secure-by-default modules.

16 verified modules

Block Storage

The disk you attach to a virtual machine - EBS, Azure managed disks, GCP persistent disks, ECS, CBS and EVS disks, OCI, IBM and Scaleway block volumes, UpCloud storage, and the volumes of DigitalOcean, Hetzner, Linode, Vultr, Exoscale and Civo - with the question of who takes the snapshot answered rather than assumed.

14 verified modules

Golden Images

Machine images built and versioned by the platform - EC2 Image Builder, Azure Compute Gallery, Compute Engine custom images - with a family or version that instances resolve, encryption with your key, and sharing by policy.

12 verified modules

Container Registry

Private container image registries (ECR, ACR, Artifact Registry) with verified, access-scoped modules.

12 verified modules

Identity & Access

Account-level identity foundations - roles, workload identities and the guardrails each cloud expects you to set once, before anything else lands.

12 verified modules

In-Memory Cache

Managed Redis-compatible caches, provisioned with the network placement and failover settings already decided.

11 verified modules

Shared File Storage

Managed NFS-style filesystems that many instances can mount at once, for workloads that need a POSIX path rather than an API.

11 verified modules

Managed NoSQL Database

Key-value, document and wide-column databases - DynamoDB, Cosmos DB, Firestore, Bigtable, OCI NoSQL, Keyspaces, DocumentDB - with point-in-time recovery on and the endpoint private.

10 verified modules

Serverless Functions

Event-driven function platforms (Lambda, Cloud Functions, Azure Functions, Workers) provisioned by verified modules.

10 verified modules

CDN & Edge Delivery

Content delivery and edge platforms (CloudFront, Front Door, Akamai) provisioned by verified modules.

10 verified modules

WAF & Edge Security

Web application firewalls and edge request filtering - managed rule sets, rate limits and IP controls in front of your origin.

10 verified modules

NAT Gateway

Managed egress for private subnets - NAT Gateway on AWS and OCI, Azure NAT Gateway, Cloud NAT - with the routes written and the address stable.

9 verified modules

Serverless Containers

Run containers without managing servers (Cloud Run, Container Apps, ECS Fargate, App Platform), as verified modules.

9 verified modules

Monitoring & Observability

The native metrics, logs and alerting baseline for each cloud, wired up rather than left at defaults.

9 verified modules

Managed Search

Managed search and analytics engines - OpenSearch on AWS and OCI, OpenSearch Serverless, Azure AI Search - configured so the endpoint is private and the index does not grow forever.

9 verified modules

Static Site Hosting

Git-connected hosting for static sites and front ends - Amplify Hosting, Azure Static Web Apps, Cloudflare Pages - with preview branches that are not public by accident.

9 verified modules

Managed TLS Certificates

Public certificates the platform issues and renews - ACM, Certificate Manager, Akamai CPS - validated by DNS records the module writes.

9 verified modules

Network Peering

A private link between two networks - VPC peering, VNet peering, OCI local and remote peering - with the routes on both sides and the flags that make it carry traffic.

9 verified modules

Audit Log Retention

The record of every management action - CloudTrail, the Azure Activity Log, Cloud Audit Logs, OCI Audit - kept for longer than the platform keeps it, somewhere it cannot be changed.

9 verified modules

Cloud Data Warehouse

The managed analytical database - Redshift, BigQuery, Synapse dedicated SQL - with the endpoint private, access by identity, and the idle cost understood.

8 verified modules

API Gateway

Managed API front doors - routing, authentication, throttling and quotas in front of your services, as verified modules.

8 verified modules

Site-to-Site VPN

IPsec tunnels between your network and a cloud VPC - gateway, peer definition and connection, with BGP for routes that do not go stale.

8 verified modules

Dedicated Interconnect

A private circuit from your network into the cloud - Direct Connect, ExpressRoute, Cloud Interconnect, FastConnect - with BGP, a redundant pair, and the encryption question answered.

8 verified modules

Backup Service

The cloud-native backup service - AWS Backup, Azure Backup, Google Backup and DR - with a plan that is assigned to resources and a vault that refuses to lose them.

8 verified modules

Managed CI/CD

The cloud-native pipeline services - CodePipeline, CodeBuild and CodeDeploy, Azure DevOps, Cloud Build and Cloud Deploy, OCI DevOps - with build logs kept, artifacts signed or scanned, and deploy approval where it belongs.

8 verified modules

Transit Hub

The hub that connects many networks - Transit Gateway, Virtual WAN, DRG, Network Connectivity Center - with route tables that say which spoke may reach which.

8 verified modules

Managed Spark

Managed Spark and Hadoop - EMR Serverless, HDInsight, Dataproc, Databricks on Azure - with the cluster in your network, the metastore outside it, and the bill understood before the first job.

8 verified modules

Network Flow Logs

The record of every connection through a network - VPC Flow Logs, NSG and VNet flow logs, VCN flow logs - in the format an investigation needs, kept where it can be queried.

7 verified modules

Security Posture & Findings

The cloud-native console that scores your estate and raises findings - Security Hub, Defender for Cloud, Security Command Center, Cloud Guard - configured so the findings reach a person.

7 verified modules

Database Migration & CDC

Managed change-data-capture and migration services - DMS, Datastream, GoldenGate - that copy a database somewhere else and keep it in step.

7 verified modules

Managed Network Firewall

The managed, stateful inspection appliance - AWS Network Firewall, Azure Firewall, OCI Network Firewall - that sits in the path of traffic, can open TLS and inspect what is inside, and bills by the hour whether or not a rule matches.

7 verified modules

Private Instance Access

Reaching a private instance without a public SSH port - Session Manager, Azure Bastion, IAP TCP forwarding, the OCI Bastion service - with the session recorded and the port closed.

7 verified modules

Organisation Guardrails

The policy layer that refuses a resource outright - service control policies, Azure Policy in deny mode, Organization Policy constraints, OCI Security Zones - as opposed to the posture services that report afterwards.

7 verified modules

Private Service Endpoints

Reaching a service over the provider network rather than the internet - PrivateLink, Private Endpoint, Private Service Connect - so a database or an API has an address inside your network and none outside.

6 verified modules

Private Certificate Authority

A managed CA for internal TLS - issuing, renewing and revoking certificates for services that never face the public internet.

6 verified modules

Managed ML Platform

The managed notebook and training platform - SageMaker, Azure Machine Learning, Vertex AI, OCI Data Science - with the notebook off the internet and the data it reads encrypted with your key.

6 verified modules

Transactional Email

The platform email service - SES, Azure Communication Services email, OCI Email Delivery - sending from a domain you own, with SPF, DKIM and DMARC published and bounces handled.

6 verified modules

Managed App Platform

Platform-as-a-service for web applications - App Runner, App Service, App Engine - where you bring code or a container and the platform owns the servers, the scaling and the TLS.

6 verified modules

Customer Identity

Sign-in for your customers rather than your staff - Cognito, Azure AD B2C, Identity Platform - with the social providers, MFA, sign-up throttling and the redirect allow-list set before the first user arrives.

6 verified modules

Uptime Checks

Synthetic probes from outside the cloud - Route 53 health checks, Cloud Monitoring uptime checks, OCI Health Checks - with the alert that turns a failure into a page.

6 verified modules

Landing Zone

The scaffolding every account, subscription or project inherits - Control Tower, the Azure management group hierarchy with policy, the GCP project factory - with logging, guardrails and identity set before the first workload.

5 verified modules

Budgets & Cost Alerts

Spend thresholds on a billing account, subscription, compartment or project that notify somebody before the invoice does.

5 verified modules

Patch Management

The service that patches a fleet on a schedule - Systems Manager Patch Manager, Azure Update Manager, VM Manager OS patch - with a baseline that says what is approved and a window that says when.

4 verified modules

Managed ETL Pipelines

Serverless data integration - Glue, Data Factory, Dataflow - with jobs that run as a scoped identity and pipelines that alert when they fail.

4 verified modules

Workflow Orchestration

Managed state machines - Step Functions, Logic Apps, Workflows - that call services in order, retry the right steps, and keep a record of every run.

4 verified modules

HPC Parallel File Systems

Parallel file systems for HPC and training - FSx for Lustre, Azure Managed Lustre, Parallelstore - fronting an object store, with the durable copy in the bucket and the fast copy sized on the step.

4 verified modules

Managed BI

Dashboards and reporting as a managed service - QuickSight, Looker (Google Cloud core), Oracle Analytics Cloud - signed in through your identity provider, reaching private data over a private path.

3 verified modules

Data Transfer Service

Managed bulk copy into cloud storage - DataSync, Storage Transfer Service, Azure Storage Mover - from a file share or another bucket, with what happens to deleted files decided in advance.

3 verified modules

Managed Active Directory

A domain the cloud runs - AWS Managed Microsoft AD, Entra Domain Services, Managed Microsoft AD on Google Cloud - with the legacy protocols off and the networks that may reach it named.

3 verified modules

Zero Trust Application Access

Identity-based access to internal web applications without a VPN - Verified Access, Cloudflare Access, Identity-Aware Proxy - where the proxy checks who you are and what device you are on before the application sees a request.

3 verified modules

Sensitive Data Discovery

Finding the sensitive data you did not know you had - Macie, Sensitive Data Protection, Microsoft Purview - scanning storage on a schedule, with findings that do not themselves leak the data.