Hosted today, self-hosted next
Hosted today, with a self-hosted package to follow
Use the hosted service at app.getfinops.cloud. A self-hosted package for your own AWS account is in the codebase but not on a marketplace, so contact us before planning on it.
Self-hosting does not keep AI features inside your account: they call Anthropic’s hosted API.
The problem
Some teams want a hosted product they can connect in minutes. Others need the application and its database inside their own cloud account before a security review will sign off.
How it works
Choose
Sign up for the hosted service. The self-hosted AWS package is not on AWS Marketplace yet, so contact us about it.
Connect
On the hosted service, connect AWS with a cross-account role or an in-account collector, and GCP with a service account. A self-hosted AWS install started with a license key reads the account it runs in.
Run
You use the same dashboard either way. What changes is where the application, its database and its secrets run, plus a few hosted-only extras.
Read-only
cross-account role template, unless EnableRemediation is set to true
ECS Fargate
runs the self-hosted AWS package in your own account
Ed25519
signed license key, checked by a self-hosted install
KMS
key with rotation turned on, created by the AWS launch template
Capabilities
Use the hosted service today; the self-hosted package is not on a marketplace yet.
Hosted service
Sign up at app.getfinops.cloud and your workspace gets its own address. We run it on AWS: containers on Amazon ECS behind CloudFront, with one shared PostgreSQL database in which your data is separated by workspace ID.
Two ways to connect AWS
Use a read-only cross-account role that GetFinOps assumes with an External ID, or a collector stack in your account that writes scheduled snapshots to your own S3 bucket for GetFinOps to read.
Self-hosted package (not listed yet)
On AWS, the package runs the platform in your own account on ECS Fargate, with the database, cache and secrets created there; each install is meant for one workspace. The Google Cloud version is incomplete, and neither is on a marketplace yet.
License keys
A self-hosted install checks an Ed25519-signed license key, and its plan comes from that key. Without a key it still starts, on the free plan: scans, findings and reports work, and remediation needs a license.
In depth
The hosted service
The hosted service runs at app.getfinops.cloud, and each workspace gets its own address under it. Requests pass through CloudFront to a private load balancer, then to the backend and dashboard containers on Amazon ECS. Billing is handled through Stripe.
Workspaces share one PostgreSQL database on Amazon RDS, encrypted at rest and not reachable from the internet. Your workspace comes from your signed session, and the application uses it to scope what you can read. The platform can also give a workspace its own backend and dashboard containers; its data still lives in the shared database.
Connecting AWS and GCP to the hosted service
- Cross-account role. A CloudFormation template creates an IAM role that trusts GetFinOps’ AWS account and requires your workspace’s External ID. GetFinOps assumes it for temporary credentials, so no access keys are stored. It is read-only unless you turn on EnableRemediation, which adds a short list of write permissions.
- Deploy in account. A CloudFormation stack runs a collector in your account, daily by default, and writes snapshots to an encrypted S3 bucket there. The bucket policy lets GetFinOps’ AWS account read them. There is no role GetFinOps can use to make changes, so this method is observe-only.
- Google Cloud. You create a service account with viewer roles for Recommender, Compute, Cloud SQL, Storage, Monitoring, GKE and BigQuery data, plus BigQuery Job User so it can run the billing queries, and provide its key, which is stored encrypted.
Self-hosted on AWS
The AWS package is a CloudFormation template that runs the backend, dashboard and background worker in one container, as a single ECS Fargate task in your VPC. It is not listed on AWS Marketplace, and its container image is not published yet. It creates:
- RDS PostgreSQL 16, encrypted, not publicly accessible, with seven days of automated backups;
- ElastiCache Redis for the job queue;
- a customer-managed KMS key with rotation, used for the secrets and the log group;
- Secrets Manager entries for the database password, the JWT secret and, if you supply one, the license key;
- a security group that opens the app ports only to a CIDR range you choose, 10.0.0.0/8 by default.
Self-hosted on GCP, in progress
A GCP Marketplace Kubernetes app is in progress. Its Deployment Manager template describes a GKE Autopilot cluster, Cloud SQL for PostgreSQL 16 with backups, Memorystore Redis with authentication, Secret Manager secrets, and a Pub/Sub subscription for marketplace entitlement events. The templates it imports and the Helm chart that installs the platform are not written yet, so it cannot be deployed today.
Its Helm values set a single replica, a non-root user, a read-only root filesystem and no Linux capabilities.
License keys and marketplace usage
A self-hosted install reads a license key: a JWT signed with Ed25519, checked against a public key that ships with the product. The signing key does not. The key sets the plan. Without one the install still starts, on the free plan: scans, findings and reports work, and approving or running remediation is refused until a license is installed. A license can also be installed later in Settings → License, which keeps it encrypted in the install’s database; a key set at launch, such as the AWS template’s LicenseToken parameter, takes precedence. When a license passes its end date, it enters any grace period it carries, then expires. After that you can still read what is there, the plan drops to free, and starting a scan from the app and all remediation, including approvals, the auto-execute endpoint, manual rollback and automatic execution after a scan, are refused until a valid key is installed. Scheduled scans keep running.
Marketplace usage is measured in connected cloud accounts, completed scans and active users. The current package does not yet send that usage to AWS or Google.
What changes when you self-host
- On an install started with a license key, the install reads the AWS account it runs in with its own task role, so there is no cross-account role or External ID. The template grants that role read access to Cost Explorer, Config, EC2, RDS and CloudWatch.
- Daily scheduled scans are off until you turn them on, in both packages.
- Your plan comes from the license key, and without one the install is on the free plan. An expired or invalid key blocks starting scans from the app and all remediation.
- On an install started with a license key, there is no in-app workspace deletion (you remove the stack), and the in-app “Report a problem” button is not shown.
- Slack approvals ship switched off.
- MFA can use the built-in authenticator-app option, which needs no outside vendor.
What it does not do
- This page does not confirm that a marketplace listing is live.
- A self-hosted AWS install does not read other AWS accounts, and cannot make changes until you add write permissions to its role.
- Deploy in account does not keep your data out of GetFinOps, and it cannot make changes.
- Self-hosting does not keep AI features inside your account: they call Anthropic’s hosted API.
- The current package does not yet send marketplace usage to AWS or Google.
- No option makes changes in GCP; remediation runs in AWS only.
- The hosted service does not promise that your data stays in a particular region.
FAQ
Questions
What is the difference between the two AWS connection methods?
The cross-account role lets GetFinOps call AWS APIs in your account with temporary credentials, read-only by default. The deploy-in-account stack runs a collector in your account on a schedule and writes snapshots to an S3 bucket there, which GetFinOps reads. Only the cross-account role can make changes.
Does deploy-in-account keep our data out of GetFinOps?
No. The collector runs in your account, but the bucket policy lets GetFinOps’ AWS account read the snapshots, and the hosted service stores and analyses what it reads. To keep the application and its database in your own account, use a self-hosted install.
Can a self-hosted install make changes in AWS?
Only once you allow it. The launch template grants the install’s task role read access only. On an install started with a license key, remediations run with that role, so you add the write permissions to it yourself.
Does a self-hosted install send anything outside our account?
It can. AI-written narratives and the assistant call Anthropic’s hosted API, using an API key you configure; the launch templates do not set one. The current package does not yet send marketplace usage to AWS or Google.
Is it listed on AWS or GCP Marketplace today?
No. Neither marketplace lists GetFinOps yet. This page describes the packages; contact us before you plan around one.