See what's actually running in your Azure tenant.
NubOps takes a read-only snapshot of your Azure environment and turns it into interactive architecture diagrams, custom resource reports, policy audits, vulnerability findings and a full IP address inventory. No manual documentation. No scripts to maintain.
Free while in beta. Sign in with your Microsoft account and get your first diagram in about five minutes. No App Registration required to start.
Read-only access · Per-project encryption keys in Azure Key Vault · Hosted in Sweden (EU) · Available on Azure Marketplace
Manual documentation doesn't just cost time. It hides risk.


The diagrams are wrong.
Every hand-drawn diagram is a snapshot that never updates. When it matters most β during an incident, a design review, or an audit β you can't fully trust what you're looking at.
The picture is incomplete.
Native Azure tools show you resources one blade at a time. The dependencies between them stay invisible until something breaks.
The work never ends.
Collecting configuration details by hand, subscription by subscription, doesn't scale with the environment you're responsible for.
Living architecture doesn't mean real-time. It means you never draw it again.
NubOps captures a snapshot of your Azure environment and builds your diagrams, reports and findings from it. Take a new snapshot whenever you need current data, and every snapshot is kept.
A hand-drawn diagram is a snapshot that can never update and can never be compared. Yours can do both.
One snapshot. Every view you need.
Everything below is generated from the same read-only snapshot. Nothing to configure separately. Nothing to keep in sync.
πΊοΈ Architecture diagrams
Interactive diagrams generated per resource type, showing how your resources are actually connected β including dependencies you didn't know were there.
π Custom resource reports
Build your own reports from every detail we extract. Choose the resources, choose the properties, export for your team, your management or your auditors.
π‘οΈ Vulnerability findings
Microsoft Defender vulnerability findings for your virtual machines, with full resource and environment context β so you can see which vulnerable resources are actually exposed.
π Policy audit
See every resource that fails your chosen policy baseline. Run our default policy set, the CIS Benchmark, or a custom selection where you toggle exactly which policies apply.
π IP address management
A complete inventory of your address space, network segments and public IP addresses across subscriptions.
π Overview dashboard
Track Secure Score, audit findings and vulnerability counts across snapshots, so you can see whether things are actually improving.
Two ways to connect. Start with whichever is easier.
| Sign in with your Microsoft account | Register an application | |
|---|---|---|
| Setup | Just sign in | Create a read-only App Registration |
| Permissions used | Your existing read access | Dedicated read-only access |
| Snapshot covers | Everything your account can read | Everything the registration can read |
| Needs admin help? | Sometimes | Yes |
| Best for | Trying NubOps right now | Consistent coverage for a team |
Nothing to provision. Nothing to request. Sign in with the account you already use, and NubOps reads only what your permissions already allow. Move to an App Registration later when you want consistent coverage across a team.
Your snapshot covers what your account can read. If subscriptions or resources are missing, that's a permissions boundary, not a gap in NubOps.
What do you need to see?
Control over an environment you didn't draw by hand.
You're accountable for an Azure environment that changes faster than anyone can document by hand. NubOps gives you one interactive map of it, generated from your real environment, across every subscription you can read.
- Diagrams generated, not drawn. Interactive architecture diagrams built from your actual environment, per resource type.
- Find what you didn't know was connected. Dependencies and configurations surfaced across subscriptions, not one blade at a time.
- Unlimited snapshot history, at full detail. Every snapshot is kept until you delete it. Nothing thinned out, nothing capped.
- Overview or detail, on demand. Filter and adjust views to move from a tenant-wide picture to a single resource property.
- Report to people who will never log in. Build custom resource reports across subscriptions and export them for stakeholders and auditors.
No limits on your own data. Your environment's real complexity is exactly what we want you to test against.
From guesswork to a picture you can trust β in about five minutes.
You're the one who ends up maintaining the diagrams nobody quite believes. NubOps reads your environment through the Azure APIs and builds the picture for you.
- Sign in and go. No App Registration needed to start. No agents, no complex configuration, nothing to maintain.
- Answers instead of hunting. Every resource, its settings and its relationships, without jumping between portal blades.
- Every detail we extract, in a report you define. Pick the resources and properties you care about, filter, and export.
- Full IP address inventory. Address space, network segments and public IPs across the subscriptions you can read.
- One click to refresh. Take a new snapshot and every diagram, report and finding regenerates. No redrawing, no script maintenance.
Honest about scope: NubOps goes deep on Azure. We don't support other cloud providers.
Verify your Azure security posture β without adding another alert stream.
One misconfigured storage account is all it takes. NubOps automates the technical analysis and shows you your actual exposure, visually, so you can prioritize by what's really exposed to risks.
- Choose the baseline you're measured against. Run our default policy set, the CIS Benchmark, or a custom selection where you toggle exactly which policies apply.
- See your attack surface. Interactive diagrams show which resources are exposed to the internet and how they're connected.
- Defender findings with resource context. Microsoft Defender tells you what's vulnerable. NubOps shows you which subscription, resource group and environment it's in β making it easier to find vulnerable virtual machines that have internet connectivity.
- Compare vulnerability findings between snapshots. See what's been remediated and what's new.
- Evidence, not assertions. Snapshots are kept until you delete them, so you can show what the environment looked like on a given date.
- Reports for the people who ask for them. Export policy audit and resource reports for management and auditors.
- Separate keys per project. Each project's snapshots are encrypted with a key unique to that project, held in Azure Key Vault.
Two things to know up front: vulnerability findings come from Microsoft Defender and require Defender to be enabled on the resources you want covered. And NubOps is focused Azure analysis β not a full security suite for your entire infrastructure.
Three steps. Read-only. About five minutes.
1 β Connect
Sign in with your Microsoft account, or create a read-only App Registration. Either way, NubOps only needs read access. NubOps will not impact your environment in any way.
2 β Snapshot
NubOps queries Azure Resource Manager APIs and captures your environment. Your diagrams, reports, policy audit, vulnerability findings and IP inventory are all generated from that snapshot. A snapshot takes less than five minutes, depending on the size of your environment.
3 β Refresh when you need to
Take a new snapshot whenever you want to refresh data after you made configuration changes in Azure. Every snapshot is kept until you delete it, and you can easily switch between snapshots.
We're asking for read access to your tenant. Here's exactly what happens to your data.
Access
Read-only, always. Connect with your own Microsoft account or with a read-only App Registration. NubOps will not create, modify or delete anything in your Azure environment.
Where your snapshots are stored β your choice
| Local | Cloud | |
|---|---|---|
| Stored in | Your own browser (IndexedDB), encrypted | Our Azure Storage Account, Sweden (EU) |
| Encryption | AES-256, encrypted in your browser | AES-256 double encryption at rest |
| Key location | Azure Key Vault | Azure Key Vault |
| Key scope | Unique per project | Unique per project |
| Key management | NubOps | NubOps |
| Snapshot data leaves your device | No | Yes, encrypted |
| Number of snapshots | Unlimited | Unlimited |
| Detail retained | Full detail | Full detail |
| Shareable with colleagues | No β single user | Yes β across your organization |
| Retention | Until you delete it | Until you delete it |
Both modes keep unlimited snapshots at full detail. The difference is sharing, not capability.
Need something more specific?
Some organizations have requirements beyond either option above β for example bringing your own encryption key, a dedicated storage account, or data residency outside Sweden. We handle these case by case rather than as a fixed plan, so tell us what you need and we'll tell you what's possible.
How keys are handled
- A separate key for every project. Each project's snapshots are encrypted with a key unique to that project. No project β and no client β shares a key with another.
- Keys are never stored in our application database. All key material is held in Azure Key Vault, with access control and audit logging.
- Deleting a project deletes its key. Once the key is gone, those snapshots can no longer be decrypted.
- Protected against accidental loss. Soft delete and purge protection are enabled on our Key Vault, so keys cannot be permanently removed during the retention period.
One thing to be aware of
Local snapshots exist only in that browser, on that device. Clearing your browser data or moving to another machine means they're gone. Use cloud storage if you need snapshots preserved or shared.
Built for more than one environment.
In NubOps, snapshots live in projects, and projects live in your organization. One project per client, per tenant or per environment β shared with the colleagues who need access.
- Consultants and managed service providers: keep each client's environment cleanly separated, with a separate encryption key per project.
- Flexible support for Azure tenants: use organizations and projects to structure your snapshots, based on your access to different Azure tenants and subscriptions.
- Shared source of truth: architects, engineers and security specialists all work with the same captured data instead of making different assumptions.
You've probably already tried these.
| Hand-drawn diagrams (Visio) | Azure portal and scripts | NubOps | |
|---|---|---|---|
| Accuracy over time | Out of date the moment it's saved | Accurate, but information is spread out over multiple blades | Refreshed every snapshot, with detailed information assembled from multiple sources |
| Dependencies visible | Only what someone remembered to draw | Fragmented across the portal | Mapped automatically |
| Effort to maintain | Continuous manual work | Scripts are complex and difficult to maintain | None |
| Policy verification | Not possible | Manual review and custom scripts | Automated verification of security settings based on CIS Benchmarks and Microsoft best practices |
| Vulnerability management | Not possible | Separate tool, separate view | Prioritize vulnerability remediation based on risk exposure and export findings to Word to share with application owners |
| History | Whatever versions someone saved | Limited to saved script output | Unlimited snapshots, shared access to detailed historic data |
The second snapshot is where it gets interesting.
A single look at your environment is useful.
A record of how it changes is worth more.
- Travel back in time. Revisit previous snapshots to understand what your environment looked like and how resources were configured.
- Unlimited snapshot history, full detail. Every snapshot is kept until you delete it. No caps in retaining historic snapshots, no thinned-out data.
- See your direction of travel. Secure Score, audit findings and vulnerability counts tracked across snapshots on your Overview dashboard.
- Compare vulnerability findings between two snapshots. See what's been fixed and what new findings have been discovered since.
- Share snapshots across your organization. All users can be assigned access to the same captured data.
We'd rather tell you now than waste your evaluation time.
- Snapshot-based, not real-time. NubOps captures your environment when you take a snapshot. It isn't a live stream or a monitoring system.
- Snapshots are taken manually. You decide when to take one.
- Vulnerability data comes from Microsoft Defender and requires Defender to be enabled on the resources you want covered.
- You choose a policy baseline, you don't write one. Choose between our default policy set, our CIS Benchmark set, or a custom selection of our policies.
- Change tracking is metric-level, not resource-level. Trends for Secure Score, audit findings and vulnerabilities, plus vulnerability comparison between snapshots β not a resource-by-resource diff.
- Not a diagramming tool you draw on. Diagrams are generated from your existing resources, not drawn from a blank canvas.
- Azure only. No AWS, no Google Cloud.
- Not cost optimization. We show you what exists and how it's connected, not how to lower your bill.
- Not log analytics and not a SIEM. NubOps focuses on software vulnerabilities and misconfigurations.
- Not a full security suite. Focused Azure analysis, not endpoint-to-cloud coverage.
- Sharing requires cloud storage. Local snapshots stay on your device by design.
- Built for the desktop. NubOps is designed for full-screen work, because that's where architecture and security reviews actually happen.
Free while we're in beta. Transparent when we're not.
NubOps is free to use during beta. We're a small team building this for the people who do this work, and your feedback shapes what we build next. Feedback is welcome, never required.
When we introduce paid plans:
- Pricing will be published on this site, in full.
- No sales call required to find out what it costs.
- Existing beta users will be told well in advance. Nothing changes without notice.
Frequently asked questions
See what's actually running in your Azure tenant.
Sign in with your Microsoft account and get your first snapshot in about five minutes. Read-only, and free while we're in beta.
Start free β no credit card Book a 20-minute demo
Read-only access · Per-project encryption keys in Azure Key Vault · Hosted in Sweden (EU)



