Supported AWS Services & Regions
TattvaLens connects to your environment agentlessly, mapping resources and their relationships. Below is the current matrix of supported services across standard AWS partitions.
| Service Name | Discovery | Graph Relationships | Cost Metrics |
|---|---|---|---|
| Amazon EC2 | VPC, EBS, IAM, ELB | ||
| Amazon RDS | VPC, KMS, SG | ||
| Amazon S3 | IAM, KMS, CloudFront | ||
| AWS IAM | All Resources | - | |
| Amazon VPC | EC2, RDS, Lambda |
Supported Partitions
Region Support
Global support across all commercial `us-*`, `eu-*`, `ap-*`, `sa-*`, `ca-*`, and `af-*` regions. (Opt-in required for certain non-default regions).
Assessment Outputs
TattvaLens generates actionable artifacts designed for different stakeholders—from executive summaries to engineering-ready JSON payloads.
Executive Report (PDF)
A high-level overview of architectural health, total cost waste, and critical security risks. Designed for CTOs and CISOs.
View SampleRemediation Data (CSV)
Detailed spreadsheets containing exact resource ARNs, region info, cost metrics, and step-by-step remediation runbooks.
Included in all tiersAPI Payload (JSON)
Raw structured findings ready to be ingested into Jira, ServiceNow, or your SIEM for automated ticketing and tracking.
Enterprise OnlyCompliance Frameworks
Our findings are automatically mapped to industry-standard compliance frameworks to streamline audit preparation and reporting.
Security & IAM Access
TattvaLens operates with strict least-privilege principles. We require a cross-account role with read-only AWS managed policies. No agents, no write access.
Required Policies
- SecurityAuditAWS Managed Policy used to read security configuration metadata across supported services.
- ViewOnlyAccessAWS Managed Policy used to read resource attributes and tags for graphing and cost attribution.
- Custom Cost Explorer PolicyInline read-only policy specifically scoped to
ce:GetCostAndUsagefor FinOps analysis.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::123456789012:root"
},
"Action": "sts:AssumeRole",
"Condition": {
"StringEquals": {
"sts:ExternalId": "tattvalens-unique-id"
}
}
}
]
}Current Limitations & Roadmap
Not Yet Supported
- GCP and Azure (Planned Q4 2026)
- On-premise infrastructure mapping
- Automated remediation (Read-only by design)
Coming Soon
- Kubernetes (EKS) workload-level scanning
- GitHub / GitLab repository integration
- Custom compliance framework creation