Skip to main content
Book a walkthrough

INFRASTRUCTURE INTENT, GOVERNED BY DESIGN

From plain English to applied, audited infrastructure

Describe the change. ZeroOps compiles it into safe Terraform, Terragrunt and Ansible across GCP, AWS and Azure — with policy gates, approvals, cost, drift and a full audit trail already in the path.

AI drafts. Deterministic code disposes.
No automated destroy. No direct cloud mutation from the UI.

zeroops · workspace / dashboardLIVE
ZeroOps dashboard: composite risk, health score, monthly cost, drift items and run activity

01 — AUTHOR

Describe intent. Get a correct plan.

Ambiguity becomes an interactive clarification instead of a silent guess. The model proposes; deterministic code disposes.

/chatAI CHAT
ZeroOps AI Chat: natural-language prompt on the left, live draft spec with confidence and clarifications on the right
AI Chat — prompt left, live draft spec, confidence and clarifications right.
/intentINTENT YAML
ZeroOps Intent YAML editor with validate, lint, explain, diff, plan, estimate and apply actions
Intent YAML — full control for power users, same engine as the chat path.

Fidelity by construction

A validator→model retry loop, schema-constrained output and a semantic diff-gate stop a turn from quietly changing a resource you never mentioned.

Templates picker

The assistant selects from a catalog of hand-validated patterns rather than writing raw YAML — there is nothing to hallucinate, and you review the template before use.

Clarify, don't assume

Risky inferences are raised as questions. Spec confidence is shown as it climbs, so nobody deploys a guess.

02 — GOVERN

Nothing ships unchecked

A plan that violates a rule is blocked, not silently applied. A risky change stops at a human gate with the blast radius and the cost delta already on the screen.

/approvalsBLAST-RADIUS GATE
ZeroOps approvals: blast-radius score, resources affected, policy gate, cost delta and recorded decision
Approvals — blast radius, affected resources, policy gate and the recorded decision.
/costCOST BEFORE APPLY
ZeroOps cost estimation with live per-cloud SKU pricing, monthly and annual projections and budget status
Cost — live SKU pricing across three clouds, estimated before the apply.

POLICY ENGINE

OPA / Rego, plus your own rules

Encryption-in-prod, no-public-ingress and the rest ship built in. Your policies sit beside them and are evaluated the same way.

RBAC + TENANCY

20+ fine-grained permissions

Operator and admin roles, with every tenant and workspace isolated end to end.

APPROVALS

Slack deep-link, full record

Approve or reject where the team already is. The decision, the approver and the diff are kept together.

03 — OPERATE

Apply, watch, and recover

Parse → plan → gate → apply, streamed live. State is locked per scope so concurrent runs never clobber each other, and in-flight work survives a restart.

/runsSTREAMING
ZeroOps pipeline runs: eleven-step execution pipeline with per-step timing and status, streaming live
Pipeline Runs — eleven steps from capture intent to published outputs, with timings and gates.

Day-2 operations

Guided per-resource changes — resize, labels, start/stop, deletion protection — without hand-editing YAML.

Rollback + snapshots

Per-resource rollback backed by state snapshots, so recovering one resource never disturbs its siblings.

Drift + reconciliation

Continuous scans surface drift by severity. Adopt the live change, accept the deletion, or re-converge — each explicit and audited.

Brownfield adoption

Bring existing cloud resources under management with dependency-aware import instead of a rewrite.

One change, end to end

Step through a single request as ZeroOps handles it. ILLUSTRATIVE

zeroops · prod · payments-apiHELD
statusapply blocked — awaiting approval
approvers.menon · head of platform
seesthe full diff, the flag, and the projected cost
windowexpires in 4h, then the plan is stale and re-runs
overridenone — the gate is not configurable away

APPROVAL GATE

Held until a person says yes

The apply stops here. Not throttled, not queued behind automation — stopped, waiting on a named human with the authority your own rules gave them.

The gate at step four is not configurable away. An estate can be operated fast or operated blind; ZeroOps is built on the assumption that you were asked to prove which one you are.

04 — SEE

One place for the whole estate

Per-cloud posture scores, a graph of what is actually deployed, and real metric trends with SLOs and error budgets — not fabricated sparklines.

/securityCSPM
ZeroOps security page: control violations, compliance coverage for SOC 2 and CIS, and per-cloud posture scores with findings
Security — SOC 2 and CIS coverage, per-cloud posture and prioritised findings.
/topologyOBSERVED INFRA
ZeroOps topology: cloud-aware dependency graph of observed infrastructure with domain filters and drift status
Topology — a cloud-aware graph of what is deployed, with drift annotated on the nodes.

Multi-cloud, first class

Every capability renders for GCP, AWS and Azure. The console groups and filters by cloud everywhere it matters.

RENDER PARITY

Every domain, every cloud

Full render parity across GCP, AWS and Azure — each GCP domain has an equivalent, with cloud chips on runs, approvals, drift and rollback.

CROSS-CLOUD MIGRATION

A readiness report that writes nothing

Each resource is graded — can-render, can-safely-apply, can-migrate-data — and the output is a per-resource data-move plan.

DISCOVERY

Projects, accounts, resource groups

Enumerate what exists per cloud before deciding what comes under management.

Where it runs

Public cloud, and the on-prem platforms an Indian enterprise estate actually contains. Status is stated per platform rather than implied by a logo wall.

PUBLICGoogle CloudFull plan, policy and apply. GCP Premier Partner engineering behind it.SUPPORTED
PUBLICAWSFull plan, policy and apply across accounts and organisations.SUPPORTED
PUBLICMicrosoft AzureFull plan, policy and apply across subscriptions.SUPPORTED
ON-PREMVMware vSphereInventory, drift and governed change on existing clusters.SUPPORTED
ON-PREMOpenStackProjects, quotas and workloads under the same rule set.SUPPORTED
ON-PREMOpenShiftCluster and workload governance alongside the public-cloud estate.SUPPORTED
ON-PREMHyper-VInventory and governed change on Windows-centric estates.SUPPORTED
ON-PREMNutanixRead and inventory today; apply is on the near roadmap.IN PROGRESS
ON-PREMBare metalProvisioning integration in progress; inventory is available now.IN PROGRESS
ON-PREMProxmoxIn progress. Raised by customers with mixed-hypervisor estates.IN PROGRESS

The questions we get asked first

Short answers. Every one of them is testable in a walkthrough.

Does ZeroOps replace my platform team?

No. It makes the team you already have faster at the changes they already own. Every apply passes a plan review and a human approval — there is no path where the platform acts alone.

Who owns the Terraform state?

The organisation running the estate. State is held per tenant, locked per scope, and never leaves the environment it governs.

Does this work outside public cloud?

Yes — VMware, OpenStack, OpenShift and Hyper-V are supported today, with Nutanix, bare metal and Proxmox in progress. Status is stated per platform rather than implied by a logo wall.

HARD LIMITS

No automated destroy. No direct cloud mutation from the UI. Every path to the estate goes through a plan, a policy evaluation and a recorded decision.

HOW IT IS SOLD

Direct to the organisation that will operate it. There is no reseller motion for ZeroOps.

WHO OPERATES IT

Your own platform team. ZeroOps removes the queue between a decision and a governed change; the judgement stays where it already is.

See it against your own estate

A walkthrough runs on the live console, not a slide deck. Bring one change you would normally raise a ticket for.

Book a walkthrough →
ZeroOps

The governed control plane for infrastructure intent, by CloudWorX / SISLCloudWorx.

INTELLIGENT · SECURE · TOGETHER

PLATFORM

GET STARTED

CONTACT

CMMI Level 3ISO 27001:2013ISO 9001:2015GCP Premier PartnerAuthorized Anthropic PartnerGeM Registered
© SISLCloudWorxZeroOps