See how your cloud actually fits together - and what breaks when it changes.

Meshlyr continuously discovers every resource across AWS and GCP, maps how they connect, and turns that graph into answers: blast radius, per-resource cost, drift and business impact. Read-only. Keyless. Always current.

Explore the live demo

What you can answer

The relationship graph is the engine - every feature is a question you ask of it, not another console to check.

Blast radius

Pick any resource and see, instantly, what fails if it goes down and what it depends on - impact as a query, not a war-room investigation.

Per-resource cost - with the gaps

Cost mapped to the actual resource, not just a bill by service. Plus a triage of what you can’t account for: terminated, mis-matched, or not-yet-discovered spend.

Business services that stay current

Group resources into the services they power - Payments, Checkout - with rules resolved live against the real graph. No hand-maintained list to rot.

Drift, since your last snapshot

What changed - resources, config and relationships - severity-tagged, with a full history and a before→after trace on every change.

Security, in context

Findings from Security Hub, GuardDuty, Access Analyzer and GCP Security Command Center land on the exact resource - and roll up per business service.

The whole estate, both clouds

Every region, every account, AWS and GCP - networking, compute, storage, identity, secrets, IaC - on one cloud-neutral canvas.

How it works - and why you can trust it

Connect once, read-only. Meshlyr never touches your resources - it reads their configuration and builds the map off the request path.

Read-only, least-privilege

List/Describe/Get only. The full IAM policy is published - inspect the CloudFormation template before you apply it.

Metadata only - never your secrets

Meshlyr reads resource configuration. It is granted no permission to read secret values, parameter values, or object contents.

Keyless on GCP

Workload Identity Federation - no service-account key is ever created or stored. AWS uses AssumeRole pinned by a per-tenant ExternalId.

Pinned, one-way trust · no agents

The role you create trusts only Meshlyr’s exact control-plane identity, scoped to your account. Discovery runs on a schedule - nothing is installed in your environment.

A console you’ll actually want to open

Explore all of this live, on a full synthetic estate - nothing connected, nothing to sign up for.

Portfolio dashboard

Portfolio dashboard

Resources by region on a live globe, cost, findings and recent drift - across every account.

Relationship map

Relationship map

Click any resource for its dependencies, cost and relationships - filter by focus, region or service.

Cost Management

Per-resource cost

Where spend goes, mapped-vs-gaps coverage, a 3-month forecast, and cost per resource with Δ.

Blast radius

Blast radius

What fails if a resource goes down - impacted resources and the business services affected, most critical first.

Business services

Business services

Risk and cost rolled up per service, a grounded AI assistant, and a per-service deep-dive with report export.

Relationships editor

Relationships editor

Correct or add a relationship - guardrail-checked, swept across the platform, with dependency-aware, restorable rollback.

Drift and Infrastructure as Code

Drift & IaC

Which stacks have drifted, are in sync, or can’t be checked - with a per-change history since your last snapshot.

Architecture diagram

Architecture diagram

A nested Account → Region → VPC → subnet topology of a service - exportable to PNG, SVG or draw.io.

Reports you can hand to finance or an auditor

Self-contained, printable exports - open two real examples (synthetic data, new tab).

Early access - join the pilot

We’re onboarding a small group of design partners and shaping pricing with them.

Questions, answered

The things people ask before connecting a cloud account.

1. What access does Meshlyr need?

A scoped, read-only role (List/Describe/Get). On AWS it’s a CloudFormation stack you can inspect before applying; on GCP it’s keyless Workload Identity Federation. Meshlyr is never granted permission to read secret values or object contents.

2. Which clouds and accounts are supported?

AWS and GCP today, multi-account and multi-region. One cloud-neutral graph means every feature - blast radius, cost, drift, business services - works identically across both.

3. Where does my data go?

Discovery reads resource configuration (metadata) and stores a snapshot in the control plane - the app only reads that snapshot. No agents are installed in your environment. Ask us for the full data-handling details.

4. What does it cost?

It’s free during the early-access pilot. After that, simple per-connected-account pricing - no per-seat games. Explore the demo first; it needs no cloud access.

See your kind of cloud, mapped

Explore the full demo on synthetic data, or talk to us about connecting your accounts.

Live demo

A full, interactive estate - no signup, no cloud access.

Explore the demo

Talk to us

Early access, security questions, or a walkthrough of your estate.

Get in touch