Built for trust

Autonomy without surrendering control.

You own the cloud. You set the limits. You can stop access at any time.

Your cloud remains yours.

UltraInfra uses temporary, customer-controlled access for approved work only.

UltraInfra control planeEvidence + decision + workflowNo customer account ownership
Temporary STS credentialsExact account · purpose · action · time
Customer cloudRevocable role boundaryCustomer retains runtime and billing ownership

AI cannot give itself permission.

Clear rules decide whether a change can happen—not a model response.

01

Tenant scope

Organization, project, account, environment, and resource ownership are checked explicitly.

02

Evidence

Required sources, freshness, coverage, and version alignment fail closed when incomplete.

03

Action policy

Autonomy mode, budget, risk, maintenance windows, entitlements, and safety stops govern eligibility.

04

Temporary authority

Purpose-scoped AWS credentials resolve only for the exact approved operation.

05

Decision ledger

Immutable evidence binds parameters, workflow, policy facts, and evaluation versions.

06

Verification + recovery

Expected and actual outcomes determine completion, rollback, abandonment, or escalation.

What teams ask before they connect.

Can UltraInfra access an AWS account after disconnection?

New actions require a valid connected role and exact-account STS validation. Removing or invalidating that role stops new AWS authority. Offboarding preserves customer ownership and an appropriate sanitized history.

Does UltraInfra need long-lived AWS access keys?

No long-lived IAM user access keys are required for the supported customer connection model. The system assumes a role and receives expiring AWS STS credentials.

Can an agent invent an infrastructure action?

Candidate plans may be generated from semantic context, but only versioned action-catalogue operations can reach the independent action evaluator and workflow layer.

What happens when evidence or policy changes mid-workflow?

Decisions expire or re-evaluate when their bound facts, parameters, authority, or workflow context no longer match. The safe result is to stop rather than reuse stale authorization.

Are GCP and Azure mutations available?

No. Current provider-neutral semantics support observation, recommendation, and planning only. They do not add GCP or Azure credentials, live collectors, or mutation paths.

Read the AWS access guide →

Begin with an explicit trust boundary.

Start with visibility. Add autonomy when you are ready.

Privacy controls

Your choice applies to this website and the UltraInfra portal. You can change it at any time.