Skip to content

36 images live · AWS and Azure · GCP next

Cloud imagesyou can prove.

AMIs and Azure images built clean-room from official sources, with no credentials baked in and every package listed before you launch. Passwords are generated on your instance at first boot — never on ours.

36
Production-ready images

every one live in the catalog today

3
Cloud platforms

AWS and Azure shipping, GCP next

0
Credentials shipped in any image

passwords are generated on your instance at first boot

100%
Built from official sources

every component from its vendor’s own repository or release

01How it works

From catalog to production in four steps.

No new control plane, no runtime agent, no lock-in. You get an image ID for your cloud and the documentation to defend it in an audit.

  1. 01

    Pick your cloud and image

    Browse by provider, OS, architecture, region, and workload. Every image lists its full software inventory before you launch anything.

    catalog — aws + azure

  2. 02

    Subscribe in your account

    Shared to your AWS account IDs, or to your Azure subscription through a Compute Gallery, then referenced by image ID from Terraform, CloudFormation, or Bicep. No agents, no control plane, no pipeline changes.

    terraform apply

  3. 03

    Stay on the latest version

    Patched revisions land on a predictable cadence, each with release notes and the updated software inventory. Upgrading is a version bump, not a migration project.

    v2026.07.1 → .2

  4. 04

    Need it customised? Talk to us

    Extra packages, your own hardening profile, a different base OS, or a region we do not publish to yet — we build bespoke images against the same pipeline and provenance.

    custom build — on request

03Multi-cloud

One clean-room build, every cloud you run.

The same official sources, the same first-boot credential model and the same documented posture — built natively for each cloud rather than lifted-and-shifted between them. AWS and Azure ship today; Google Cloud is next.

AWSimage for Amazon Web Services35 images

Amazon Web Services

Published as AMIs you launch by ID, or shared privately to your AWS account IDs. Drops straight into an existing launch template.

Identifier
AMI ID
Compute
EC2 instance types
Storage
EBS volume
Region format
us-east-1
Azureimage for Microsoft Azure1 image

Microsoft Azure

Published through an Azure Compute Gallery, versioned per image definition and shared to your subscription. Works with your existing VM and AKS deployments.

Identifier
Compute Gallery image ID
Compute
VM sizes
Storage
Managed OS disk
Region format
westeurope
GCPon the roadmap

Google Cloud

The same clean-room build, credential model and patch cadence, published as Compute Engine images. In the pipeline now — tell us which images you need first, and they ship first.

Identifier
Compute Engine image
Compute
Machine types
Storage
Persistent disk
Region format
us-central1

Running more than one cloud? Tell us about your setup — image parity across clouds is the whole point.

04Why ProvenCloud

Nothing hidden, nothing baked in.

Every image is built clean-room from official sources and ships with its full software inventory and a written security posture. The only secrets on your instance are the ones it generates for you at first boot.

BUILD RECORD — clean-room image · Ubuntu 24.04 LTSSpecimen — sample record
Base image
Canonical Ubuntu LTS · official
Sources
vendor repositories and releases only
Credentials in image
none · generated at first boot (IMDSv2)
SSH
key-only · root login refused
Database bind
127.0.0.1 only
Build artefacts
keys, shell history, logs removed
vendor-string scan · before capturepassed · verified with a real sign-in

Illustrative sample. Every product page states these facts for its own image, in full, under Security posture — alongside the complete list of installed software and versions.

Official sources only

Every component comes from its vendor’s own repository or release. Nothing is copied from a third-party image, and the finished image is scanned for stray vendor strings before capture.

No credentials in the image

Admin, database and console passwords are generated on your instance at first boot from instance metadata, and the scripts that set them delete themselves afterwards.

Locked down before capture

SSH is key-only with root login refused. Databases listen on 127.0.0.1. Build-time keys, shell history and logs are removed before the image is taken.

Nothing to install

No agent, no daemon, no phone-home. You launch a plain AMI or gallery image, and it keeps working exactly the same if you never talk to us again.

Any region, on request

2 regions live

Every product page lists the regions its image is published in today. Copying a build to another region is routine work and included — tell us where you run.

Oregon (us-west-2) — on requestIreland (eu-west-1) — on requestFrankfurt (eu-central-1) — on requestMumbai (ap-south-1) — on requestSingapore (ap-southeast-1) — on requestTokyo (ap-northeast-1) — on requestSão Paulo (sa-east-1) — on requestVirginia (eastus2) — on requestIowa (centralus) — on requestNetherlands (westeurope) — on requestIreland (northeurope) — on requestLondon (uksouth) — on requestSydney (australiaeast) — on requesteastusus-east-1

publishedon request

eastusus-east-1

Drops into the tooling you already run

  • Terraform
  • CloudFormation
  • Bicep
  • Pulumi
  • Ansible
  • Packer
  • Auto Scaling
  • Systems Manager
  • CloudWatch
  • Azure Monitor

Publish with us

List your product in our catalog.

Ship your software as a clean-room, production-ready image on AWS and Azure. We handle the build pipeline, the documentation, the patch cadence and the multi-region replication — you keep the customer relationship.

A real engineer reads every message, and we reply within 1 business day.