CloudQuery
Central visibility has strengthened our cloud security, compliance, and governance controls
What is our primary use case?
We faced a problem whereby our databases were not being encrypted, and we wanted a solution that could help us. We had to search for a few options and we went with CloudQuery. CloudQuery gives us a central way of managing our cloud infrastructure. We use it to collect information from our cloud accounts and query that information to identify our security issues, compliance, and configuration issues. For example, we normally use it to check whether production databases are encrypted. That was the reason why we purchased it. If there is any storage issue which is publicly accessible, as someone working in the banking environment, our information is too sensitive. If we don't encrypt it, then we are going to face issues. Because we deal with sensitive customer financial information, we have to use it to give us an option to have DevSecOps and governance over our cloud infrastructure.
What is most valuable?
The feature which is called Cloud Asset Inventory is what I like most about CloudQuery, and I use it daily. It gives us that central view of all our cloud resources, even across all different accounts we have and also the environments we have. It gives us that option whereby we know exactly what infrastructure we have. Sometimes we may be having a lot of cloud accounts, a lot of environments, and we're not sure that some exist. CloudQuery gives us that way to see cloud environments we have.
The SQL-based querying is another feature I use as a software engineer. Its role allows us to ask specific questions about our environment so it can give us feedback about it. If we query a database, it can give us an answer if our database is encrypted or if it is not encrypted, if it is publicly accessible or if it is not publicly accessible.
From the compliance perspective, I saw that we can define rules and also the identity resources, so we don't have to manually trace them every day. We just set them and we're all good to go. CloudQuery SQL compatibility database feature helps us to analyze information about our cloud infrastructure. The resources can be from a central location, and it helps us to analyze that information. In the banking environment where I work, we mainly use it to answer questions about production databases which are not encrypted and storage resources which are publicly accessible or not, and also the resources that are missing required ownership tags.
CloudQuery itself gives metrics and provides insights about the cloud environment. It can give us the number and type of resources we have, identity security and compliance issues we have in the cloud environment, and it can also track the changes across the infrastructure.
CloudQuery is customizable, and it is valuable when we're defining the rules and compliance. The solution can adapt queries and adapt to policies we set and also the monitoring rules. For example, in the banking environment, we can customize it to correspond to the policies we have. We can create custom SQL queries and policies for requirements like encryption, access control, resource tagging, and internal security standards. We can customize how we monitor and how we report the infrastructure issues.
What needs improvement?
I find CloudQuery more complicated to use, especially when starting to use it, because it uses the documentation it has, but it is not well documented to the fullest. It also lacks video tutorials that can help us onboard for the first time. Additionally, CloudQuery should be made easier for non-SQL users. It is very hard for someone who doesn't have knowledge about CloudQuery and SQL to use it. I would like to see more ready-made compliance policies, especially for our financial regulation, because we spend a lot of time creating these custom policies.
For how long have I used the solution?
What do I think about the stability of the solution?
For stability, I give CloudQuery a 10 out of 10. It has been very stable because it continuously collects our data and organizes the cloud infrastructure without us having to manually check every environment. It hasn't experienced any downtime in two years.
What do I think about the scalability of the solution?
I rate the scalability of CloudQuery as almost a 10. Every month, at the end of every quarter, we add more applications, more cloud resources, and the accounts increase. CloudQuery has been stable because it continuously collects all the infrastructure data. We do not have to rely on manual checks for each environment. CloudQuery has been scalable because we have added more cloud resources and applications, but we haven't seen it crashing or having downtime because of scaling.
How are customer service and support?
I have interacted with technical support a few times since we started using CloudQuery. I mostly interacted with them when we were setting up. CloudQuery has some documentation addressing basic issues we can encounter. The few times we have escalated the issues to customer support, it has been generally positive. When we have questions about configuration, integration, or want to troubleshoot, the support team provides us technical guidance and helps us resolve the issues very fast. I would rate it a 9 out of 10. The support portal is not good enough, which is why I've deducted one.
Which solution did I use previously and why did I switch?
My experience comparing CloudQuery with other solutions or other vendors is that it is good. Initially, we were using AWS Config to monitor our cloud resources. However, as our environment grew, we needed better and central visibility and more flexible querying. CloudQuery was actually better in terms of cost and infrastructure.
How was the initial setup?
The deployment was not all that easy. It took us more than two weeks to deploy it across our infrastructure. The complex part came on connecting the cloud accounts and also configuring the permissions. Since we work in a regulated environment, it was not all that easy to integrate and also to set up the appropriate permissions, so it took time on that. With the help of customer support, we were able to navigate through.
What about the implementation team?
What's my experience with pricing, setup cost, and licensing?
The pricing is not cheap in general. It is reasonable. When we consider the time it saved for us during the security and infrastructure team, it is reasonable, although it is a little bit expensive.
What other advice do I have?
I would recommend CloudQuery to any person, individual, organization, or company that needs better visibility and control over their cloud infrastructure. I find it especially useful for organizations with multiple cloud accounts or environments where manually tracking resources can become difficult. I give this review a rating of 8 out of 10.
SQL queries have simplified cloud inventory, compliance reporting, and security auditing tasks
What is our primary use case?
My main use case for CloudQuery is as a tool for inventory platforms that lets me extract, transform, and query infrastructure data using SQL.
A quick specific example of how I use CloudQuery in my inventory platforms is that I use it for compliance and governance reporting, and I also use it for security auditing to identify misconfigured or exposed resources.
In addition to that, I also use it to connect custom dashboards and analytics with some BI tools.
How has it helped my organization?
CloudQuery has positively impacted my organization because instead of navigating through multiple cloud consoles, I can run an SQL query and get, for example, all my S3 buckets that are public, private, or that I need to do something with.
Since I started using CloudQuery, we have reduced our auditing and checking data by almost 20 to 30%.
What is most valuable?
The best features CloudQuery offers include some FinOps tools to help you analyze unused or underutilized resources, and it helps you assure that all your resources are in compliance and governance.
Regarding how those FinOps tools have helped me analyze resources or ensure compliance, what I use helps me to identify what my resources are that are not being used, because when I start a development, I sometimes deploy many things and then forget to turn them off or shut them down.
What needs improvement?
CloudQuery could maybe integrate with some AI agents like ChatGPT or Claude to help us do some things like writing in natural language instead of SQL.
Regarding CloudQuery's AI capabilities, I think its governance and security could be improved because it has some features that maybe can be changed, but it is mainly good.
Regarding CloudQuery's AI capabilities and its accuracy and reliability of output, it is very good because it transforms all your SQL and gives you some advice about what to do.
For how long have I used the solution?
I have been using CloudQuery for almost three years.
What other advice do I have?
My advice to others looking into using CloudQuery is that if you like SQL, you can use this product as if it was MySQL, SQL Server, or any other relational database. I would rate this product a 10 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
AI-driven queries have transformed how I discover hidden cloud assets and misconfigurations
What is our primary use case?
My main use case for CloudQuery is to help find assets within our cloud environment.
A specific example of how I use CloudQuery to find assets is with Prisma Cloud, where we have issues detecting all of the different assets that don't seem to be picked up by Prisma Cloud. I was using CloudQuery in order to write SQLs to find specific types of assets that weren't originally being picked up by Prisma.
I use CloudQuery whenever I have issues writing RQLs for Prisma Cloud. The SQLs to find assets are a little bit easier to write, enabling me to handle more complex queries.
What is most valuable?
I think the best feature CloudQuery offers is the AI aspect that allows you to tell it what you want, and it writes SQL for you. This really cuts down on time and effort.
The AI-generated SQL works well for my team as it gets things right most of the time. When it was first introduced, there were issues where I had to edit it, but after updates, it became very useful to the point where minimal edits were needed. If an edit was necessary, I could follow up with the AI and it would fix any mistakes automatically.
CloudQuery positively impacts my organization by helping us find assets easier. For instance, I was looking for any type of publicly accessible assets within the cloud environment and was having issues with Prisma, so CloudQuery made it easier to find those assets.
It became much easier to find assets with CloudQuery, and I noticed a lot of time saved, especially because of the AI SQL writer that does the work for us. I was spending hours trying to craft an RQL for Prisma, but I could figure out the SQL in CloudQuery in minutes.
What needs improvement?
One of the improvements that could be made to CloudQuery is the GUI. In the past, I had issues where I couldn't see all the information that would pop up at the bottom. That might be fixed by now, but I was experiencing issues with the GUI itself.
CloudQuery's AI capabilities lack governance and security features. While the AI is great for helping me craft SQLs to find assets in the environment, it does not have real security features for blocking or similar tasks. I can set up SQLs for alerting, but I find that a bit limiting.
For what it is, CloudQuery is great. The only improvement I could suggest would be to set up more alerting features, but overall it is great for what it is, and I would say it feels a little bit limiting.
For how long have I used the solution?
I have used CloudQuery for about three to four months.
What do I think about the stability of the solution?
CloudQuery is very stable, and I have not had any issues.
What do I think about the scalability of the solution?
CloudQuery's scalability seems fine. It has not had any issues when I put my environment on it.
How are customer service and support?
Customer support is great. I have calls with two of the team members at CloudQuery on a semi-regular basis, and they took my feedback and implemented things very quickly. I was very impressed by the support that I received while using it.
Which solution did I use previously and why did I switch?
I used CloudQuery in conjunction with Prisma Cloud. I did not fully switch; instead, I used it as an additional layer of my security.
How was the initial setup?
I proceeded with a free trial, but I was not involved when it came to the cost, so I am not sure.
What about the implementation team?
I do not have a business relationship with this vendor other than being a customer.
What was our ROI?
I am unsure about the money saved, but as I mentioned earlier, there was definitely a lot of time saved. I spent a couple of hours trying to craft certain RQLs in Prisma, but I could find the same asset information in CloudQuery in less than an hour, whereas Prisma took hours and hours to get things figured out.
What's my experience with pricing, setup cost, and licensing?
I did not purchase CloudQuery through the AWS marketplace; I just used it for a free trial for a few months.
Which other solutions did I evaluate?
Before choosing CloudQuery, I did not evaluate other options.
What other advice do I have?
CloudQuery really acts as an asset inventory tool, which is great, but I find that somewhat limiting.
My advice to others looking into using CloudQuery is to know the limitations. CloudQuery is a great product for getting asset inventory of your cloud environment, at least based on my experience from a few months ago, but it is not much more than that, and it excels at what it does. I would rate this review an eight out of ten.