Can't recommend for basic security reasons.
We can't speak for the quality of the features of the platform as we decided to stop the evaluation right away while starting its use.
In order to make use of this platform you need to provide ADMIN access to your cloud infrastructure. While there is some explanation as to how to proceed, there is a total lack of information as to what the scripts do and why they are necessary.
This is not good practice and should be a red flag for just about anyone.
The developers will certainly push back because this review will look bad on the product.
Don't let that fool you: anyone "needing" to have Admin/root level access to your infrastructure for any of their products is simply not to be trusted. There are proper ways to do this. Security can't be an inconvenience to be dismissed lightly.
Refunded immediately.
Sudeep_Cloudshot
Dec 27, 2024Dear TIOF,
I think there must be some misunderstanding. Cloudshot DOES NOT mandatorily need admin access. Administrative access is only required if you want to deploy anything in your cloud environment. This is precisely the same as your AWS/Azure/... account. To deploy anything, you need access. In fact, Cloudshot securely assumes the role of the logged-in user when you connect your account with IDP, etc. There are some features for which you don't even need to connect your Cloud account, e.g. uploading Terraform script to visualise or draw the landscape diagram and generate Terraform script. :)
I hope this clarifies. If you need more information, please feel free to write to support@cloudshot.io. I'll be happy to schedule a 1:1 meeting to provide the security details.
Thank you.