Platform · How it works
Four steps, and only the first one is yours.
Setup is a single read-only permission grant, done once in your own console. Everything after that is our problem.
Connect
One read-only IAM grant. No keys, no agents.
You turn on your provider’s FOCUS billing export and give Atumica read access to it. On AWS, that is one read-only IAM role, created from a CloudFormation template. On Google Cloud, it is a grant to our service account. That access is the whole integration, and you can revoke it from your own console at any time.
Ingest
Corrections and credits included.
Atumica picks up new billing data from your export throughout the day. When your provider issues a correction or a credit, it shows up in your figures, and nothing is counted twice.
Normalize
To FOCUS, the open FinOps standard.
Cost rows are normalized to FOCUS, the FinOps Foundation’s open specification for cloud cost and usage data: the same field names and definitions your provider and your other FinOps tooling already use. What you learn about the schema here carries over to any other FOCUS tooling.
Analyze
Slice it by whatever your data actually carries.
Cost over time, broken down by service, project, region, SKU and more, with cascading filters that only ever offer you values that exist in your data. Period-over-period comparison labels a partial month as partial, so it doesn’t read as a drop in spend. Any view you land on can be saved as a named report and shared read-only inside your organization.
Access and data
The least access that does the job.
We get read access to one billing export. That is the entire permission — there is nothing in Atumica that could reach your infrastructure, and nothing to install inside it.
Read-only, and revocable by you
The only access we ask for is read permission on your billing export. The grant lives in your console — revoke it at any time and ingestion simply stops.
Nothing runs in your environment
No agent, no sidecar, no collector, no daemon. Access is granted between cloud identities directly, so there is no credential file to store, rotate, or leak.
Billing data only
We ingest cost and usage metadata — which services ran, in which projects and regions, at what SKUs and cost. Not your application data, databases, logs, or source code.
Tenant isolation on every query
Every query against cost data is scoped to the tenant making it, enforced in the data access layer and covered by automated tests.
Want to go deeper before connecting anything? Ask, and we'll walk your security team through the architecture directly — that conversation is with the person who built it.
Early access
See it against your own bill.
Tell us what you run on and the question you can’t answer today. We’ll set up the account and connect your export.