Cloud Control Contact Explore

How Cloud Control works

No black box. Here are the data sources, pipeline, scoring, and AI ranking that sit behind every recommendation.

From connection to action

The pipeline behind the platform

Four steps, from the first API call to a prioritized action list in the dashboard. Fully automated, no changes to your environment.

1
Connect
Read-only

You create an app registration with read-only access. No agents, no write permissions, no changes to your environment. Setup takes minutes, and we guide you through it.

2
Data collection
Daily refresh

Cloud Control reads structured metrics from the cloud providers' official APIs. Costs, licenses, users, resources, and security signals are collected nightly and stored encrypted in the EU.

3
AI analysis
Auditable

The AI identifies waste, risk, and improvement opportunities in the data, and ranks findings by impact, severity, and effort. The logic is auditable. LLMs are used for plain-language summaries, not to make decisions.

4
Action
Prioritized

The result lands as a single prioritized action list in the dashboard. History and trends show whether actions actually move the numbers. Export to Jira, ServiceNow, or Excel, or have iStep join monthly status reviews.

Data sources

What Cloud Control actually reads

The signals we use come from official APIs. No agents, no side channels. Here are the main categories.

Cost and billing

  • Azure Cost Management
  • AWS Cost Explorer / CUR
  • Reservations and savings plans

Users and identity

  • Microsoft Graph (Entra ID)
  • MFA status and admin roles
  • PIM (Privileged Identity Management)
  • Guest and external accounts

Licenses and usage

  • Microsoft 365 assignments
  • Service usage reports
  • Last sign-in per user
  • Cost and unit price per seat

Security

  • Defender for Cloud Secure Score
  • Azure Advisor (security)
  • App registrations and secrets
  • NSG and access policies

Resources and ops

  • Azure Resource Graph
  • VMs, SKUs and CPU averages
  • Tags and resource groups
  • Uptime and performance metrics

Sustainability and devices

  • Azure Emissions Impact Dashboard
  • CO₂ per service and region
  • Intune / Device compliance
  • Autopilot and device models
Cloud Index

Eight health scores. One number.

The Cloud Index combines eight sub-scores across four categories into one overall health number. Here are the categories behind it.

Cloud Index
Example
6,6
out of 10 — combined from four categories
The Cloud Index updates daily and preserves history, so you can see whether actions actually shifted the health in the right direction over time.
Security
6,8
  • Cloud security6,2
  • User security7,4
Cost
5,1
  • Cloud cost4,7
  • License cost5,5
Sustainability
7,9
  • Carbon and emissions7,2
  • Efficiency8,6
Platform
6,5
  • Operational health6,8
  • Alerts and actions6,2
AI, demystified

Not magic. Math.

We use AI where it makes sense: to explain numbers in plain language and to find patterns across millions of rows. The ranking itself is deterministic and auditable.

What the AI actually does

Large language models are very good at two things: plain-language summaries and pattern recognition. Cloud Control uses them for exactly that, and nothing more.

  • Explains in plain language what a score or recommendation means. No technical noise.
  • Groups similar findings so 50 isolated alerts become 3 concrete actions.
  • Prioritizes deterministically by impact, severity, and effort. Same input, same answer.
  • Takes no action. It reads, proposes, explains. Humans execute.
How a recommendation is ranked
Three factors determine the order
Impact
Savings or risk removed
Severity
How critical it is
Effort
How much work is required
High-impact, low-effort actions float to the top. The same input always produces the same order, and every step is auditable.
Privacy and security

It's your data. Not ours.

Cloud Control has read-only access, data is stored in the EU, and you can request deletion at any time. Here is what matters most.

Read-only access

Cloud Control can never modify your environment. We read. You act. Simple and audit-friendly.

Data stored in Norway/EU

All data is encrypted at rest and in transit, stored in Azure regions within the EU. No transfer outside the EEA.

No third-party sharing

Your data isn't shared with third parties, isn't used to train general models, and is never visible to other customers.

Only aggregated signals

We pull metadata and aggregated metrics. No document content, log files, messages, or sensitive personal fields.

Deleted on request

If you end the contract, all data is removed within 30 days. You can request export or deletion at any time.

Access you control

The app registration sits in your tenant. You can revoke access instantly by disabling it in Entra ID.

Frequently asked questions

Questions and answers

Azure, AWS, and Oracle Cloud. We are continuously expanding with new integrations and providers.
It depends on the size of your environment. For some it takes minutes, for others it can take up to a day. We set up an app registration with read-only access and guide you through the entire process.
No. We have read-only access with no write permissions. All actions are executed by your team, not by us.
In Azure regions within the EU/Norway, encrypted at rest and in transit. Only you and the iStep team have access.
It groups similar findings, explains them in plain language, and ranks them deterministically by impact × severity ÷ effort. The decision is always yours.
We always start with a free, no-obligation health check. Further pricing is tailored to the needs and size of the environment.
Yes, Cloud Control supports export to Excel, CSV, and common IT governance tools like Jira and ServiceNow. We adapt as needed.

Want to see it on your own numbers?

Start with a free health check. We connect your environment and show the same pipeline. Just on your own numbers.