env0 now goes by env zero, and the pitch has moved. What used to be Terraform-orchestration-plus-drift is now, in their own words, “the Autonomous Cloud Control Plane for the AI era” - self-service infrastructure, cost governance, policy enforcement, and an AI agent layered on top. Drift detection is one feature inside that platform, not the product.
Every claim about env zero below is sourced from their own pricing and marketing pages, read live on 2026-09-12, not from an older snapshot.
What env zero actually is now
Their homepage describes it as unifying “declared state and discovered state into a single context lake where agents can reason and take deterministic action.” The named solution areas are self-service infrastructure with guardrails, drift detection and remediation, cloud asset management, and continuous policy enforcement. If you’re evaluating it purely as a drift tool, you’re buying into a much larger platform to get there.
Where the gap is
- Self-hosted is a sales conversation, not an install. Their pricing page states plainly: “env zero is available as a Self-Hosted Agent! Contact us for details.” There is no self-serve self-hosted path. Cloudkeel-DD is self-hosted by default, for every tier, via a public Helm chart - no call required.
- No Kubernetes, anywhere. Neither their pricing page nor their homepage mentions Kubernetes once. env zero’s drift and remediation features are scoped to cloud infrastructure through Terraform, not a live cluster. Cloudkeel-DD reads the live cluster directly: Helm, ArgoCD, and Flux, sixteen kinds.
- Remediation writes to your cloud. Their own feature list names “Drift Remediation: Update your cloud” and “Drift Remediation: Update your code” as capabilities. Cloudkeel-DD never writes to your cloud; every fix is a pull request you review and merge yourself.
- Free tier is capped at 250 runs a month and 30 environments. Past that, every tier is “Custom Priced,” billed per successful apply or environment - a metering model tied to how often you deploy, not how much you’re watching.
Where that leaves you
| Cloudkeel-DD | env zero | |
|---|---|---|
| Entry price | Not set (pilot stage) | Free: 250 runs/mo, 30 environments; Cloud Navigator and Cloud Pilot both custom-priced per apply/environment |
| Deployment | Self-hosted Helm chart, standalone, self-serve at every tier | SaaS; self-hosted agent exists but is “contact us,” not self-serve |
| Drift on managed resources | Yes | Yes: named as a product capability (Drift Detection and Alerting, Cause Analysis, Monitoring Dashboard) |
| Unmanaged resource discovery | Yes: AWS, Azure, GCP | Not named as a capability on any page read |
| Kubernetes | Live cluster read: Helm, ArgoCD, Flux, sixteen kinds | Not mentioned on any page read |
| Cloud write access | None: read-only, enforced in code | Yes: “Drift Remediation: Update your cloud” is a named feature |
| Remediation model | Reviewed pull request, never an unattended write | Direct cloud update, or a code update, both listed as automatable |
| Access control | Email/password, RBAC (owner/admin/viewer) | RBAC on every paid tier; OpenID Connect and SAML on higher tiers |
| Project status | Pre-1.0, pilot | Active, mid-rebrand to an AI-agent platform |
The difference that actually matters
env zero is building a platform for AI agents to operate your infrastructure. Cloudkeel-DD is built so nothing, human or agent, gets write access through it.
Their “context lake” framing is explicit: the goal is agents that “reason and take deterministic action” on your cloud. That is a different bet than the one this product makes. Read-only isn’t a missing feature here - it’s the reason the security review is short.
Where env zero is ahead
Said plainly, because a comparison that only lists our wins is an advert.
- A genuinely useful free tier exists today: 250 runs/month, 30 environments, unlimited users, with real drift features included. Cloudkeel-DD’s pricing is not set yet.
- It’s an active, funded, actively-repositioning product, with case studies and a resource library. We are pre-launch, with none of that yet.
- It closes the loop: detection and remediation (to cloud or to code) in one platform, if you want a tool that acts rather than just reports.
- SSO/SAML and OpenID Connect are available now. Ours is on the roadmap.
What we do not do
The limits, in the same breath as the claims:
- Unmanaged detection needs a Terraform state source. Something has to define “managed.” A cloud credential on its own produces nothing.
- Attribution is best-effort and can fail quietly. If the IAM permission it needs is missing, the actor is simply absent and nothing on screen says why.
- No PDF export. CSV exists, is generated in the browser, and carries aggregate report metrics only.
- No cost governance, no FinOps dashboard, no AI agent layer. If that’s what you’re evaluating env zero for, we don’t compete on it at all.
- Scans are point-in-time, on a schedule you set. This is not a live feed and we will not describe it as one.
- Nothing phones home: no telemetry, no analytics, no licence server, and it runs air-gapped. Three paths do carry finding data outward when you configure them: notification webhooks, and the GitHub and GitLab integrations that open remediation pull requests.
Which one to pick
Choose env zero if you want a platform that provisions, governs, and can act on infrastructure automatically, including letting an AI agent make changes, and you’re comfortable with a SaaS vendor holding that capability.
Choose Cloudkeel-DD if you want drift and unmanaged-resource detection alone, self-hosted by default with no sales call required, and you’d rather review every change yourself than let a platform - or an agent - apply it for you.
What about the clouds’ own tools?
Azure Policy, AWS Config and GCP Asset Inventory each answer part of this: inside their own cloud, in their own query language, without reference to your Terraform. If your estate is one cloud, evaluate them first; they are already paid for. If it spans clouds, the check becomes three different checks, and none of them can say “this resource is in no Terraform state,” because that comparison needs your state, which is the input they do not take.
Read more
- What Cloudkeel-DD is: the product page
- Exactly where the depth ends: coverage, generated from the engine
- Install it yourself: no call, no account
Sources
- env zero pricing, tiers, and feature comparison table: env0.com/pricing
- env zero homepage positioning (“Autonomous Cloud Control Plane for the AI era”): env0.com
Read 2026-09-12. If any of this has changed, tell us and we will correct it: a comparison that goes stale is worse than none.