OPEN SOURCEAVAILABLE NOW

The open-source AWS evidence engine behind Mission FinOps.

Free to inspect, install, and run on its own: the local-first CLI behind every Mission FinOps investigation.

Get started.

1. Install

pip install kulshan (Python 3.9+). Optional extras: kulshan[mcp], kulshan[pdf], kulshan[excel], kulshan[pptx], or kulshan[all].

2. Authenticate

Using your own AWS credentials: an AWS CLI profile or an assumed role. Kulshan never stores or requests long-lived keys.

3. Generate evidence

kulshan report for a cost baseline, or kulshan preflight first to check connectivity and readiness without running a scan.

Apache 2.0.

Why it exists.

Enterprise cost investigations stall because billing evidence, architecture evidence, and ownership information live in different places, held by different teams, in different formats. Kulshan builds one reproducible, inspectable evidence base instead of a fresh manual pull every time the question comes up.

Verified capabilities (0.6.2, current PyPI release).

Cost & usage evidence

kulshan analyze cost and kulshan analyze ec2 for CUR/Data Export evidence; Cost Explorer coverage including cost/usage, anomaly history, forecasts, and RI/SP utilization and recommendations.

Resource & architecture context

Ten read-level diagnostic packs: cost, security, sweep, dr, age, drift, tag, pulse, limit, topo. Run individually, combined, or with --packs all.

Evidence artifacts

Output as terminal, HTML, JSON, SARIF, or CSV. Structured provenance, evidence IDs, billing-integrity status, and a human_review_required flag on outputs.

Workspaces & investigation history

kulshan workspace for multi-payer isolation (create, list, show, use, rename, reconcile); kulshan history for local SQLite scan history with scores and timestamps.

Consultant / analyst workflows

kulshan shell for an interactive REPL; kulshan convert to re-render a past JSON scan into another format; kulshan mcp-serve to expose deterministic Kulshan evidence to compatible MCP clients over stdio.

Redaction / schema-preserving evidence export

A consultant evidence export path with alias/pseudonymization gates for AWS account and resource identifiers, so an evidence package can leave the customer's environment for review without carrying real identifiers. See the Trust Ledger disclosures at /policy/ for how those gates have been tested and corrected.

IAM & access boundary

160 unique read-level IAM actions across 33 AWS services, published, SHA256-attested, and downloadable at /policy/. No Put, Create, Update, Modify, or Delete action anywhere in the policy.

Capability list matches agents.md and the published README; verify current detail against github.com/MissionFinOps/kulshan before relying on a specific command shape.

How it supports Mission FinOps.

Kulshan produces evidence. It does not replace engineering judgment, finance policy, workload ownership, or a material business decision.

Mission FinOps uses that evidence to test possible explanations, document what supports the conclusion, document what contradicts it, identify missing evidence, state confidence limits, and connect the movement to a workload, account, team, or business event where the evidence allows it. The Early Access Mission FinOps Agent is designed to make that same method available conversationally.

access --policy

Trust model.

kulshan-controlsACTIVE
execution

Local. Your credentials, your machine.

source

Open source. Apache 2.0.

telemetry

None.

billing-data upload

Not required.

credentials

Customer-issued and revocable. Never stored by Kulshan.

access

Read-level only. Published IAM policy.

Review the data flow, access boundary, and engagement controls at Trust.

Use it without hiring me.

You can inspect, install, and run Kulshan without hiring Mission FinOps. Nothing about the tool requires an engagement.

Mission FinOps is useful when the difficult part is not running the CLI. It is interpreting the evidence, connecting it to the architecture, reconciling finance and engineering, or producing an explanation that survives executive scrutiny. If you cannot grant AWS access at all, Kulshan-assisted Evidence Review works from an approved evidence package instead.

Bring me the messy question.

Kulshan gives you evidence. If you want help turning it into an answer finance and engineering both accept, see how the work is shaped.

calendar → book