Multi-Cloud Cost Intelligence — Self-Hosted
FinOps for AWS, Azure, and Google Cloud — running inside your own account. Read-only, customer-owned data, one prioritized ranking across all three clouds.
FinOps for AWS, Azure, and Google Cloud — running inside your own account. Read-only, customer-owned data, one prioritized ranking across all three clouds.
Refine is a self-hosted cost-intelligence platform that connects read-only to AWS, Azure, and GCP and ranks every cost-optimization opportunity across all three clouds in a single prioritized list — with dollar impact, executable CLI commands, and a Suggested → Accepted → Implemented → Verified audit trail.
It runs as a Docker container inside your own AWS account. Per-cloud collectors write summary data to buckets you own. No data ever leaves your environment.
One product, three clouds, every cost lever.
Compute (EC2, Azure VMs, GCE), databases (RDS, Azure SQL, Cloud SQL), containers (Fargate, AKS, GKE), serverless (Lambda, Functions), caching (ElastiCache, Redis), and the long tail of orphaned disks, idle NAT gateways, oversized log retention, and unused public IPs.
AWS Savings Plans + Reserved Instances, Azure Reservations + Savings Plan for Compute, and GCP Committed Use Discounts — with utilization tracking and guardrails that block recommendations which would underwater an active commitment.
Conservative / Default / Aggressive presets per resource class, plus per-resource policy flags (Permanent, Size-Locked, Exclude-from-Commitments) so a contractual resource never produces an unwanted recommendation.
Tag-based and signal-based cleanup of stale resources across all three clouds, with ready-to-run aws, az, and gcloud scripts your administrators review and execute. Refine never touches your environment.
Runs inside your AWS account. Collectors write to your S3 / Blob / GCS buckets. Air-gap-deployable. Ed25519-signed offline license. No SaaS ingest, no telemetry, no Blacktip-side store.
LDAP / Active Directory / Entra ID SSO with ROOT / ADMIN / USER roles and per-account-group scoping. Every recommendation lifecycle event is logged with the user who took it.
Refine is a contract product on AWS Marketplace. Subscribe to the tier that matches your cloud spend, launch the CloudFormation stack in your own account, and Refine pulls itself from AWS Public ECR and verifies your Marketplace entitlement automatically — no license file, no forms, no manual steps.
Buying direct, for GovCloud/air-gapped, or via Private Offer (BYOL)? Email corporate@blacktip-ops.com, or request your license if you already hold a BYOL subscription.
From subscribe to first dashboard in about 10 minutes.
Pick the tier that matches your Spend Analyzed and accept the annual contract under the Standard Contract for Marketplace (SCMP). AWS bills the tier; your AWS account is also charged for the small EC2/EBS resources the stack provisions.
One-click from the Marketplace listing. The stack provisions an EC2 host and a least-privilege IAM role in your own account, and (optionally) an HTTPS Application Load Balancer. Set an admin email and password — that's your login.
On first boot the EC2 pulls Refine from AWS Public ECR and confirms your AWS Marketplace contract via AWS License Manager — no license file, no form, no manual step. Open the RefineUrl from the stack Outputs and log in. Typically about 10 minutes end-to-end.
AWS — one-click CloudFormation per account. Azure — one-line curl | bash in Cloud Shell. GCP — a Terraform module. First recommendations appear within minutes of the first sync.
Refine never requests or accepts write credentials. Per-cloud collector roles are strictly Describe / List / Get. The host stack creates only S3-read + SSM permissions.
Cost and inventory summaries land in S3 / Blob / GCS buckets you own. Refine reads from those buckets. There is no Blacktip-side store and no network path back to Blacktip.
License is a ~500-byte signed payload bound to your installation ID. Verified offline against a public key baked into the binary. No phone-home, no internet dependency.
Refine inherits the customer's account-level boundary — FedRAMP via GovCloud, HIPAA via AWS BAA, ISO 27001 / SOC 2 via AWS. Blacktip holds no standalone authorizations because there is no Blacktip-side data path to authorize.
Want a pilot, a demo, or to discuss enterprise pricing? Email corporate@blacktip-ops.com — Annette and Blake reply directly.