Early access is open for multi-cloud teams

Run every cloud from one place. Let AI agents do the work.

Paco is the control plane between AI agents and your infrastructure. One interface across six providers, your rules on every action, and approvals in your pocket.

  • AWS
  • Microsoft Azure
  • Google Cloud
  • Huawei Cloud
  • Alibaba Cloud
  • Oracle Cloud

Multi-cloud was meant to reduce risk. It multiplied the work.

Teams run on several providers for resilience, regulation and regional reach, then spend their days stitching them together by hand. AI agents could help, if they could be trusted.

TodaySix consoles, six CLIs, six APIs. Every automation is rebuilt per provider.

One model for every provider

A single resource graph and API across all six clouds. Write automation once; it runs everywhere.

TodayGiving an agent cloud keys means it can do anything, so it does nothing.

Agents act inside your rules

Agents never hold cloud credentials. Every request is checked by policy, risky ones wait for a person, and all of it is logged.

TodayAlerts at 2 a.m. with no context. Which cloud, which service, which change?

Root cause across clouds

Paco correlates health, events and recent changes across providers, explains the likely cause and proposes a fix.

TodayEach cloud has its own release process, so rollouts are slow and rollbacks are scary.

One release, every cloud

Roll out in waves across providers with health gates, then pause or roll back everywhere with a single action.

TodayLeadership asks engineers for status, usually in a meeting after the fact.

Status in plain language

An executive view of availability, open risks and spend across every cloud, written for people who don't read dashboards.

TodayHuawei Cloud, Alibaba Cloud and Oracle Cloud are partial or missing in most tools.

All six are first-class

The same monitoring, actions, pipelines and cost tracking on every supported provider from the first release.

Every change follows the same six steps

Whether an agent, a pipeline or a person starts it. Pick a step, or watch a real-world incident play through.

Incident 142, replayed Illustrative

    Nothing reaches a cloud without identity, policy and audit

    Paco sits between everything that wants to change your infrastructure and the clouds themselves. Agents never hold cloud keys.

    Paco architecture AI agents, CI/CD systems, the mobile app and the web console connect to Paco's gateway: an MCP server, a REST API and identity and access. Requests go to the Paco core, where the policy engine, operations, pipelines and AI analysis run on a unified resource graph, telemetry and cost data, and an audit log. Six provider adapters reach your cloud accounts with short-lived, least-privilege credentials. Who connects AI agentsClaude, any MCP client CI/CD systemsGitLab, GitHub, Jenkins Paco mobile appApprovals and alerts Web consoleSetup, policy, audit Gateway MCP serverTools agents discover and call REST API and webhooksFor pipelines and integrations Identity and accessSSO, roles, scoped agent tokens Paco core Policy engineScores every request OperationsRuns, verifies, rolls back PipelinesWaves and health gates AI analysisRoot cause, by Claude Unified resource graphOne model for six providers Telemetry and costHealth, changes, spend Audit logEvery request and change AWS Azure Google Cloud Huawei Cloud Alibaba Cloud Oracle Cloud Your cloud accounts, reached with short-lived, least-privilege credentials

    No keys for agents

    Agents get scoped Paco tokens. Only Paco reaches providers, through short-lived roles.

    Policy before action

    Every change, from any source, is checked against your rules before it reaches a cloud.

    Read-only by default

    Start with visibility. Grant write access per action type and per environment.

    Open to any agent

    A standard MCP server lets Claude and other agents use Paco without glue code.

    One app, the right view for each person

    Engineers on call, team leads and executives open the same app and see what matters to them. Design previews with sample data.

    Bring your agents to every cloud, safely.

    We're building Paco with a small group of teams that run on more than one cloud. If that's you, or you just want to talk about the problem, we'd like to hear from you.