Back to the registry
Agent passport

Autonomous Cloud Operations (ACO) for Security by Firemind

Firemind · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownProfessional service
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

**Overview**

Cloud security and operations teams face a familiar problem: manual access, slow incident containment, and configuration drift accumulate faster than headcount can keep pace. Traditional monitoring and ITSM tooling surfaces the noise; it doesn't resolve it.

Show the rest of the publisher’s description (10 more lines)

Firemind Autonomous Cloud Operations (ACO) is an AI-driven service that executes routine cloud operations — monitoring, incident triage, remediation, patching, backups, and standard service requests — as policy-governed, closed-loop "episodes." ACO removes humans from the routine control path while retaining explicit human approval for high-risk actions, so operations teams spend their time on architecture and risk decisions instead of firefighting.

**Security & Trust**

Authorization is checked twice, independently, before any action reaches a customer environment:

  • Plan time: the planner validates every operation against the permissible-actions catalogue and embeds the result in the plan; high/critical steps cannot proceed without human approval.
  • Execution time: a guard sits in front of every connector and independently re-checks every tool call, scoped to the tenant, before it reaches a cloud or API. Anything not explicitly allowed is denied; approval-gated or uncatalogued actions pause the episode for a human.

The system fails closed by design: if tenant context is missing, the policy database is unreachable, or a command cannot be parsed, the action is blocked — never allowed by default.

**AI data handling**

Inference runs via Amazon Bedrock (Anthropic Claude) in the customer-selected region. Bedrock does not store prompts or responses and does not use them for model training; no data is shared with any model provider or third party. No business or personal data is collected by default (only infrastructure telemetry) and any incidental data in logs is subject to configurable retention and deletion.

**Auditability**

Every action is recorded in an immutable, end-to-end audit trail using OpenTelemetry (OTEL) distributed tracing. Audit records cannot be updated or deleted and are exportable for compliance reporting, capturing per episode: the AI's decision and reasoning, the remediation proposed, approval or rejection (with approver identity and justification), the execution itself, AssumeRole usage, and any configuration change.

Highlights

Highlighted by the publisher on AWS Marketplace.

Cut incident resolution time and manual toil — ACO autonomously detects, diagnoses, and remediates routine incidents end-to-end, escalating only what genuinely needs a human

Safe by construction, not by policy alone — a default-deny, permissible-actions whitelist and independent plan-time + execution-time enforcement mean an action that isn't explicitly allowed cannot run, even if the underlying IAM role would permit it.

Audit-ready from day one — every decision, approval, and execution is captured in an immutable OpenTelemetry trail, backed by an ISO 27001:2022-certified ISMS and independent penetration testing.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Professional service
For support, questions, or to scope a pilot, contact Firemind at hello@firemind.com. We respond to all enquiries within one business day (UK business hours, Monday to Friday). Active ACO engagements include: Defined response SLAs by severity Dedicated Slack or Microsoft Teams channel with your engagement team Weekly status reviews and quarterly business reviews A named engagement lead and technical owner 24/7 monitoring of agent actions with documented engineer escalation paths agreed during onboarding Website: https://www.firemind.com
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.