Frequently asked questions
Process
Do I need to give you credentials?
No. You create read-only access in your own account and tell us which role, service account, or app to use. You don't send us passwords or root credentials.
Which clouds do you support?
AWS, Google Cloud, and Azure.
Does the assessment cost me anything?
Nothing from us. Cloud providers can bill per-request fees to your own account for the read calls the assessment makes (the AWS Cost Explorer API is one), so you may see API charges on your own cloud bill.
How do you find the fixes?
We don't publish our methods. The access we need is described on the Security page. Every fix on your list shows its evidence and our confidence, so your team can check it before acting, and the saving is taken from your own bill.
Who runs the assessment?
Senior DevOps and cloud engineers help run the assessments. A person reads every fix list before we send it. Your team still chooses and applies any fixes.
What if you find nothing?
We tell you, and you owe us nothing.
Do I have to apply any of the fixes?
No. You choose which fixes to apply, if any. The list is yours to keep either way.
How is this different from cloud commitment tools?
Commitment tools manage Savings Plans, reserved capacity, and committed-use discounts. CloudLevy sends a dated fix list for savings in your current setup. You apply the fixes. Our fee is 10% of the annual saving confirmed on each fix you apply, and never more than the list stated. No applied fix, no fee.
Reducing cloud costs
How do I reduce cloud costs?
Start with what you pay for but don't use, and what is bigger than it needs to be. Your cloud provider's own cost tools show where the money goes. The harder part is turning that into a short list of specific changes, each with a dollar figure, so your team can decide what is worth doing first. Our free assessment gives you that list, dated and priced from your own bill. You choose what to apply. Our fee is 10% of the annual saving confirmed on each fix you apply, and never more than the list stated. The assessment is free from us. Cloud providers can bill per-request fees to your own account for the read calls the assessment makes.
How do I reduce AWS cloud costs?
AWS's own cost tools show where your spend goes by service and account. To act on it, your team needs to know which specific changes to make and what each one saves. Our free AWS assessment uses read-only access you create, and sends a dated list of fixes with a monthly saving for each, taken from your own bill. You choose what to apply. Our fee is 10% of the annual saving confirmed on each fix you apply, and never more than the list stated. The assessment is free from us. Cloud providers can bill per-request fees to your own account for the read calls the assessment makes.
Fee
How is the fee calculated?
For each fix you apply within the window, the fee is 10% of that fix's confirmed annual saving. That is the monthly saving the check confirms, times 12, and it is never based on more than the monthly saving on your list. The fee is due once, after the check. It isn't a share of your total bill.
What is the check?
One look at your next invoice after you apply a fix. You tell us when you've applied it, and we run the check. It confirms the fix was applied and measures the saving that shows. It sets the fee. It happens once per fix. It isn't ongoing monitoring.
When do I owe nothing?
For any fix you didn't apply, any fix you applied after the window, any fix that wasn't on the list, and any fix where the check shows no saving.
How long is the window?
90 days after the list is delivered. A listed fix carries a fee only if you apply it within that window. If you want a different window, we can agree it with you in writing before we send the list.
What if my usage grows or shrinks?
It doesn't change the fee. We don't use a baseline and we don't adjust for usage. The fee is set by the one check.
What if the saving is smaller than your list said?
The fee is 10% of the smaller, confirmed saving. If the check confirms no saving, there's no fee.
What if the saving goes away later?
The fee doesn't change. The check happens once, and we don't give credits or refunds for a saving that later shrinks or ends. We do correct our own billing errors.
Who makes the changes?
Your team does, in your environment, unless we agree otherwise in writing.
Billing evidence and disagreements
What is the billing evidence request?
For 12 months after you apply a fix, we may ask for billing evidence, such as invoices or cost reports, to confirm which listed fixes you applied and that the fee was right. It is a request, not monitoring, and not a second check. You choose how to share it. We don't ask for access to your account for this.
What does "the fee was right" mean?
Neither too high nor too low. The fee follows the saving the check confirmed for the fixes you applied within the window, and is never based on more than your list stated. A bigger saving than stated doesn't raise it, and the request never adds a fee for a fix that isn't on your list or that you applied after the window. If the evidence shows a fee was wrong, we correct it.
What if I disagree with a fee?
Tell us in writing. We review the evidence with you and reply in writing. The written agreement sets out the steps if we still disagree.
Who decides whether a fix saved?
We run the check, using figures from your own invoice, so you can see the same numbers. If you think the check got it wrong, you can dispute it in writing. We review the evidence with you and reply in writing, and the written agreement sets out the steps if we still disagree.
Results
How much will I save?
We can't know before we look. We don't publish typical-savings figures because we don't have verified data to back them. The saving on your list is our estimate from your current bill, not a guarantee, and the fee follows the saving the check confirms.
Security
Can the assessment change anything?
The access we ask you to create is read-only, and we send you the exact permission list to read before you create it. It cannot change, create, or delete your cloud resources. The Security page has the details.
What access do you need?
In AWS, a read-only role. In Google Cloud, a service account with read-only roles. In Azure, a custom view-only role for the CloudLevy app. We don't ask for passwords, root credentials, or long-lived keys. The Security page says what each cloud's access can and can't read.
Do you keep access to my account?
Not after the check. We use the access for the assessment and for the check of each fix you apply. After the last check we stop using it, and we'll ask you to remove it. You can delete it sooner whenever you want, and share your invoice or cost report for the checks instead.
How do I remove access?
Delete the role in AWS, remove the service account's access in Google Cloud, or remove the role and the CloudLevy app in Azure, and the access stops working.
Do you hold security certifications?
No. CloudLevy holds no third-party security certification or audit report. The Security page explains what you can check yourself.