Montro

AWS Cloud Infrastructure Governance

Most organisations know what SaaS tools they use. Far fewer know what is actually running in their AWS account. Connect AWS to Montro to bring cloud infrastructure - users, resources, services, and policies - into the same governed view as the rest of your application estate.

01GDPR

GDPR

AWS and GDPR - your cloud is where your data actually lives

Personal data processed by your organisation does not sit in a SaaS dashboard - it sits in cloud storage, databases, and compute environments, most of which run on AWS. Every S3 bucket, RDS instance, and data pipeline is a data processing activity under GDPR. AWS is the processor of that data; your organisation is the controller. A Data Processing Agreement must be in place, and the data residency of each resource matters under GDPR Chapter V. Montro brings your AWS inventory into view.

Learn more →
02EU AI Act

EU AI Act

AWS and the EU AI Act - SageMaker, Rekognition, Bedrock

AWS provides a suite of AI and machine learning services - SageMaker for model training and deployment, Rekognition for image and facial analysis, Comprehend for text analysis, Bedrock for foundation model access. Any of these deployed in a business context are AI systems under the EU AI Act. If your organisation uses them, deployer obligations apply. Montro surfaces active AWS services so AI capability usage is visible and can be assessed before the August 2026 deadline.

Learn more →
03DORA

DORA

AWS and DORA - this is the concentration risk DORA was written for

DORA was created in direct response to the concentration of European financial services on a small number of cloud providers. AWS is one of them. Financial entities running critical ICT functions on AWS must register it as a critical ICT third-party provider, conduct due diligence, maintain contractual provisions under Article 30, and assess concentration risk explicitly. Montro surfaces your AWS service footprint so that assessment is grounded in actual usage, not assumptions.

Learn more →
04NIS2

NIS2

AWS and NIS2 - critical infrastructure runs here

NIS2 explicitly brings cloud computing service providers into scope as digital infrastructure. AWS, as the underlying platform for your critical applications, services, and data, is a foundational supply chain dependency. Article 21(3)(d) supply chain security obligations apply directly. Montro connects your AWS resource and service inventory to your compliance posture - making the dependency visible and assessable rather than assumed.

Learn more →
05ISO 27001

ISO 27001

AWS and ISO 27001 - your cloud estate needs to be in the asset register

ISO 27001 Annex A requires a complete inventory of information assets (A.5.9), cloud security controls (A.8.23), and documented access management for cloud environments (A.5.15, A.5.16). An asset register that covers SaaS tools but not cloud infrastructure is structurally incomplete. Montro imports AWS users, resources, and services into your governed inventory - closing the gap between your ISO 27001 asset register and what is actually running.

Learn more →

Discovery

What Montro discovers from AWS

Cloud environments grow faster than the governance processes meant to track them. AWS accounts accumulate users, resources, services, and policies that were stood up for a specific purpose and never decommissioned. Montro pulls that inventory into your governed view - so your compliance picture includes your cloud estate, not just your SaaS tools.

Cloud user and access visibility

Montro imports AWS IAM user identities, giving you a consolidated view of who holds cloud account access alongside your SaaS users. IAM users created for a project, a contractor, or a one-off task and never removed represent a specific category of cloud access risk that rarely appears in SaaS governance tools.

Infrastructure resource inventory

AWS resources deployed across your account - compute instances, storage buckets, databases, containers - are pulled into Montro's resource inventory. This is the foundation of any meaningful cloud governance programme: you cannot assess risk, manage cost, or demonstrate compliance against infrastructure you have not catalogued.

Service usage intelligence

See which AWS services are active across your environment and understand how your cloud footprint maps to your operational needs. Unrecognised services - particularly AI and machine learning services like SageMaker, Rekognition, or Bedrock - are exactly the kind of shadow cloud capability that creates EU AI Act exposure without anyone realising it.

Policy and governance visibility

IAM policies define what every user and service in your AWS account is permitted to do. Montro imports policy information so security and compliance teams have visibility into the permission landscape across the cloud estate - supporting access control reviews, least privilege assessments, and the evidence requirements that NIS2, DORA, and ISO 27001 demand.

Technical details

Authentication Method


AWS authenticates using an AWS Access Key ID and Secret Access Key. These credentials are generated from AWS IAM and scoped with the minimum read-only permissions required for Montro to import users, resources, services, and policy information. 


How to Connect:


  1. Navigate to Integrations in your Montro dashboard.
  2. Select AWS from the integrations catalogue and click Connect.
  3. Enter your AWS Access Key ID.
  4. Enter your AWS Secret Access Key.
  5. Click Connect to authorise the integration.
  6. Montro validates the credentials and establishes a secure connection.
  7. AWS users, resources, services, policies, and cloud usage information are synchronised automatically.
  8. Review imported cloud data within Montro.


Data Synced

Users

AWS IAM user identities, including account information and access details.

Resources

Cloud resources deployed across your AWS environment, including compute, storage, and database instances.

Services

AWS services active across your account, including AI/ML services such as SageMaker, Rekognition, and Bedrock.

Policies

IAM policy information supporting access control visibility and governance assessments.


Data Residency


AWS data imported into Montro is stored on AWS Frankfurt (eu-central-1), within the European Union. This is separate from your own AWS environment - Montro's infrastructure is EU-only regardless of which AWS regions your own resources operate in. Data residency terms are specified in Montro's Data Processing Agreement.


Sync Frequency


Data can be synchronised manually at any time after the initial connection, with no limit on the number of manual syncs. Montro also provides an automatic sync option - when enabled, the platform synchronises data once every night to keep information current.


Permission Scope


Montro uses read-only AWS credentials scoped to the minimum permissions required to retrieve user, resource, service, and policy information. Montro does not create, modify, or delete any AWS resources, users, policies, or configurations. We recommend generating credentials for a dedicated IAM user with read-only permissions rather than using root credentials or existing administrative accounts.


EU Data Storage


Montro's infrastructure runs exclusively on AWS eu-central-1 (Frankfurt), governed by Irish and EU law. There is no FISA 702 exposure and no Schrems II ambiguity. Your data is never replicated outside the EU without your explicit, documented consent. EU data residency is not a configuration option, it is the architecture.

Related

Apps commonly used with AWS

Discover compliance profiles for tools in your stack.

Project & Knowledge Management

Confluence Data Governance & Access Compliance

Confluence is where your organisation documents the things it would least want exposed - security policies, incident reports, HR processes, client project data. Connect Confluence to Montro to govern who can read it.

Learn more →

Collaboration & Messaging

Slack Workspace Access & AI Governance

Slack is where work happens, and where ungoverned access accumulates. Guest accounts, inactive seats, and users added outside your identity provider all show up when Montro connects to your workspace.

Learn more →

Jira External User Discovery & Governance

Jira accounts are where contractors, agencies, and external collaborators often live - outside your identity provider, outside your offboarding process, and outside your compliance picture. Connect Jira to Montro to bring them in.

Learn more →

Identity & Access Governance for Microsoft Entra ID

Microsoft Entra ID is the identity backbone of your Microsoft environment. Connect it to Montro and bring your entire directory - users, roles, licences, MFA status, and application access - into a single governed view alongside your wider SaaS and AI estate.

Learn more →

Identity & Access Management

Okta Identity Governance & Compliance

Okta controls who gets into everything else. Without it in your governed inventory, your compliance picture has a gap at the foundation. Montro connects Okta identity data to your full application estate.

Learn more →
Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.