Multi-Cloud Cost Intelligence — Self-Hosted
FinOps for AWS, Azure, and Google Cloud — running inside your own account. Read-only, customer-owned data, one prioritized ranking across all three clouds.
FinOps for AWS, Azure, and Google Cloud — running inside your own account. Read-only, customer-owned data, one prioritized ranking across all three clouds.
Refine is a self-hosted cost-intelligence platform that connects read-only to AWS, Azure, and GCP and ranks every cost-optimization opportunity across all three clouds in a single prioritized list — with dollar impact, executable CLI commands, and a Suggested → Accepted → Implemented → Verified audit trail.
It runs as a Docker container inside your own AWS account. Per-cloud collectors write summary data to buckets you own. No data ever leaves your environment.
One product, three clouds, every cost lever.
Compute (EC2, Azure VMs, GCE), databases (RDS, Azure SQL, Cloud SQL), containers (Fargate, AKS, GKE), serverless (Lambda, Functions), caching (ElastiCache, Redis), and the long tail of orphaned disks, idle NAT gateways, oversized log retention, and unused public IPs.
AWS Savings Plans + Reserved Instances, Azure Reservations + Savings Plan for Compute, and GCP Committed Use Discounts — with utilization tracking and guardrails that block recommendations which would underwater an active commitment. The Savings Report shows what your AWS Savings Plans and Reserved Instances actually saved, taken from the credits AWS applied to your bill, alongside utilization and coverage.
Conservative / Default / Aggressive presets per resource class, plus per-resource policy flags (Permanent, Size-Locked, Exclude-from-Commitments) so a contractual resource never produces an unwanted recommendation.
Tag-based and signal-based cleanup of stale resources across all three clouds, with ready-to-run aws, az, and gcloud scripts your administrators review and execute. Refine never touches your environment.
Runs inside your AWS account. Collectors write to your S3 / Blob / GCS buckets. Marketplace deployments verify entitlement via AWS License Manager; direct and air-gapped deployments use an Ed25519-signed offline license. No SaaS ingest, no Blacktip-side store; paid tiers are strictly telemetry-free. Running Refine on EC2? Monitored accounts in the same AWS partition can trust its IAM role directly, with no long-lived access keys to store or rotate.
LDAP / Active Directory / Entra ID SSO with ROOT / ADMIN / USER roles and per-account-group scoping. Every recommendation lifecycle event is logged with the user who took it.
Same self-hosted, read-only, customer-owned-data architecture — choose by your cloud spend.
$0 — for up to $1,000/month of analyzed cloud spend.
Annual contract, priced by Spend Analyzed.
The difference: the Free tier is funded by an anonymous, aggregated usage summary and fits up to $1,000/month of analyzed spend; every paid tier sends zero telemetry and scales to enterprise spend. The architecture, security model, and recommendations are identical across both.
Refine is a contract product on AWS Marketplace. Subscribe to the tier that matches your cloud spend, launch the CloudFormation stack in your own account, and Refine pulls itself from AWS Public ECR and verifies your Marketplace entitlement automatically — no license file, no forms, no manual steps.
Need a Private Offer or volume pricing? Email corporate@blacktip-ops.com — Private Offers run through AWS Marketplace. Direct, GovCloud, and air-gapped deployments are purchased directly and delivered as a self-hosted package with an offline Ed25519 license — request a direct engagement or email us.
From subscribe to first dashboard in about 10 minutes.
Pick the tier that matches your Spend Analyzed and accept the annual contract under the Standard Contract for Marketplace (SCMP). AWS bills the tier; your AWS account is also charged for the small EC2/EBS resources the stack provisions.
One-click from the Marketplace listing. The stack provisions an EC2 host and a least-privilege IAM role in your own account, and (optionally) an HTTPS Application Load Balancer. Set an admin email and password — that's your login.
On first boot the EC2 pulls Refine from AWS Public ECR and confirms your AWS Marketplace contract via AWS License Manager — no license file, no form, no manual step. Open the RefineUrl from the stack Outputs and log in. Typically about 10 minutes end-to-end.
AWS — one-click CloudFormation per account. Azure — one-line curl | bash in Cloud Shell. GCP — a Terraform module. First recommendations appear within minutes of the first sync.
Refine never requests or accepts write credentials. Per-cloud collector roles are strictly Describe / List / Get. The host stack creates only S3-read + SSM permissions.
Cost and inventory summaries land in S3 / Blob / GCS buckets you own. Refine reads from those buckets. There is no Blacktip-side store and no network path back to Blacktip.
License is a ~500-byte signed payload bound to your installation ID. Verified offline against a public key baked into the binary. No phone-home, no internet dependency.
Refine inherits the customer's account-level boundary — FedRAMP via GovCloud, HIPAA via AWS BAA, ISO 27001 / SOC 2 via AWS. Blacktip holds no standalone authorizations because there is no Blacktip-side data path to authorize.
Want a pilot, a demo, or to discuss enterprise pricing? Email corporate@blacktip-ops.com — Annette and Blake reply directly.