Reclaimer · Included in both bundles

Bring the app on that one box under infrastructure as code.

You run a read-only script on the instance and answer six questions. Reclaimer generates the CloudFormation, opens a pull request, rehearses the stack idle before it serves, then moves the data with every row and every byte counted. The numbers below come from our own lab runs, and we say so on purpose.

We agree on access and scope with you before any scan. The baseline covers resources under IaC, findings, and top exposures. Reclaimer is a bundle capability, not a separate credit purchase.

29 / 29
applications that reached a deploy served on Fargate and RDS, five lab barrages
15 / 15
data migrations passed with row counts and file bytes verified, SQLite and multi-directory included
23–60 s
a deploy job with deploy-and-leave, instead of 8 to 40 minutes idling in a runner

Discover

  • One read-only script on the box: image, ports, mounts, variables by name, secrets never by value
  • The database beside the app, and which variables carry its connection, compared on the box
  • Six intake questions no scan can answer: who, when it may stop, how people reach it

Convert and rehearse

  • A deterministic CloudFormation stack, every derived value explained in the PR
  • Deployed idle, rehearsed with one task and its own health check, served only on a healthy verdict
  • A failed rehearsal gets a bounded fix proposal; nothing that weakens TLS or host checks gets through

Migrate and cut over

  • Offline copy inside your window, counts after the freeze, files by bytes
  • Cutover adds deletion protection; unfreeze is a one-file PR that starts the old box again
  • Every plan is content-addressed: what you approved is what runs
ClickOps to CloudFormation

Import what someone built in the console into infrastructure as code.

Reclaimer finds AWS resources nothing manages, works out who owns them from evidence, and opens a pull request that imports them into CloudFormation without replacing them. Your workflow runs the import after you merge.

Ownership from evidence

A CloudFormation stack, deleted-stack history, templates in your repository, or AWS defaults decide who manages a resource. Tags are never enough. A resource with no provable owner stays blocked until a named person attests that it is unowned.

Import, don't replace

The pull request carries an import template with DeletionPolicy: Retain, an import manifest, and the workflow that runs an import-only change set under your deploy role. Nothing is recreated.

Thirteen resource types

CloudWatch log groups, EC2 instances, S3 buckets, security groups, RDS instances, ECR repositories, Lambda functions, DynamoDB tables, IAM roles, EFS file systems, ECS services, SNS topics, and SQS queues.

Reclaim Score is the share of your resources under IaC management. Reclaimer raises it one reviewed pull request at a time.

Frequently asked questions

Does Reclaimer change or recreate my resources?

Imports don't. The pull request adds existing resources to a CloudFormation stack with DeletionPolicy: Retain, and your workflow runs an import-only change set after you merge. Moving an application off its box is a separate migration with its own rehearsal and cutover window.

Is Reclaimer a separate purchase?

Reclaimer is included in Security Garrison and Compliance Corps. You can also start with it on its own in the app.

What if Reclaimer can't tell who owns a resource?

It stays blocked. Reclaimer only proposes an import when evidence shows the resource is unmanaged, or when a named person on your team attests to it.