Early access · limited cohort

Stop finding drift after it costs you.

Join the waitlist for a workspace, or get a live walkthrough with the team — either way, tell us about your stack once.

drift detected · s3-prod-logs-4f2
$ controlinfra plan --resource s3-prod-logs-4f2
~ found outside terraform state
+ generated import block
opened PR #142 · ready to merge
Waitlist

What you get on day one

Early access to a workspace as soon as your cohort opens
First look at new capabilities before general release
A direct line to the team building it
read-only · agentless · your own AI key · no credit card

Join the waitlist

Cloud providers you use
No spam. We'll only email about early access.
Preview the workspace

What the workspace looks like, walked through on a demo environment.

The views below are from a demo environment with sample data, so you can see how it works before connecting your own infrastructure.

Controlinfra
Drift ExplorerBeta
Cloud DiscoveryBeta
Pull Requests
Drift WatchBeta
AI AnalysisBeta
controlinfraAll systems operationalDemo environment · sample data
Drift Explorer
severity in Critical, High · provider = AWS · last 7 days
Drift over time
Severity distribution
Provider breakdown
AWS 132 Azure 63 GCP 25
SeverityResourceCloudStatus
Criticalweb-security-groupAWSUnresolved
35 drifts matched
What's in early access

Capabilities you can put in front of your own infrastructure today.

Cloud Discovery
Orphaned
47
Est. cost
$791/mo
ec2-legacy-batch-worker$340/mo

Discovery & cost visibility

Surfaces resources that exist in your cloud but nowhere in Terraform, with the monthly spend attached to each one — 47 found across 3 accounts in a recent scan.

Drift Explorer · Drift Watch
nat-gateway-us-east — outbound rule changed2m ago

Drift detection & continuous watch

See exactly which resources have moved out of sync with Terraform state, and keep watching between scheduled scans — polling cloud APIs every 5 minutes across 37 resource types.

Import PR · AI Analysis
+ resource "aws_s3_bucket" "prod_logs_4f2" {
+  bucket = "s3-prod-logs-4f2"
+ }

Root cause: manual console change widened the ingress rule outside Terraform.

Automated import PRs, explained by AI

Resolve drift with a pull request that imports the resource into state, not just an alert — with a Claude-powered breakdown of root cause, impact, and blast radius on every critical finding, using your own key.

Who it's for

Built around how infrastructure teams actually work.

C
Cloud engineers

Find resources created outside Terraform before they become someone else's incident.

Orphaned resource alertsOwnership tracingImport-ready PRs
Orphaned resources
ebs-vol-unattached-8a1no owner
eip-unassociated-prodno owner
web-security-groupflagged
What to expect

A short, hands-on early access — not a mailing list.

Apply

Tell us about your stack via the form above.

Onboarding

We set you up with read-only access and walk through the workspace together.

Test against your infra

Run it against real accounts or a sandbox and see what it surfaces.

Feedback shapes it

You work directly with the team building it — what you flag informs what ships next.

We're intentionally onboarding a small number of early testers so we can work closely with each one. Early Access is limited.

Security & privacy

Read-only by default. Your keys stay yours.

Cloud access is read-only and least-privilege — Controlinfra never writes to your infrastructure without an explicit, reviewed pull request.

Agentless: nothing runs inside your cloud accounts or CI. Nothing to install, patch, or babysit.

AI Insights run on your own API key, so your infrastructure data isn't sent through a third-party model you don't control.

FAQ

Common questions

Cloud engineers, DevOps/platform teams, and FinOps teams managing Terraform-provisioned infrastructure who can spare time to test the product and give feedback.

Ready to see it on your own infrastructure?

Early Access is limited to a small cohort so we can work closely with every tester.

Join the waitlistRequest a demo