Terracotta is the closest competitor on this site, and it competes on a different axis than the other two comparisons here. Firefly and Spacelift both do drift detection the same way we do: read the live cloud, compare it to something declared. Terracotta’s headline motion is different: every pull request audited for security, cost, compliance and drift, delivered as PR comments and committable fixes before anything merges. This page says where that axis genuinely overlaps ours, and where it does not.
Every claim about Terracotta below is from their own pricing page and product pages, linked at the bottom.
What actually overlaps
More than we expected going in. Terracotta’s Drift Detection is not limited to PR review; it runs scheduled, continuous scans (hourly, daily or weekly per repo) that compare Terraform state against the live cloud on AWS, GCP and Azure, the same category of check we run. Their coverage page claims 1,618 AWS resource types in their comparison engine.
Their drift lifecycle also mirrors ours more closely than we expected: findings move through Active → Acknowledged → Suppressed → Resolved, and a suppression carries a configurable expiry (7/30/90 days, or indefinite), the same “suppress with an expiry, not a permanent mute” shape our own suppression model uses.
And neither tool auto-applies a fix to your live cloud without a human in the loop. Terracotta’s “Fix All” and “Committable fix” actions land as a commit suggestion on the pull request. You still merge it. Ours land as a pull request you review. Different mechanics, same posture: a person merges the change, always.
Where we actually differ
- Self-hosted by default, versus a sales call. Cloudkeel-DD runs in your own cluster at the only tier there is. Terracotta’s pricing page lists “Self-hosted / VPC deployment” as an Enterprise-only, custom-priced feature; every other tier is SaaS.
- Kubernetes: live cluster, versus manifest content in a PR. Terracotta’s
own Kubernetes page says it plainly: “No kubeconfig, no cluster access…
the analysis runs on manifest content, not your cluster.” It reviews YAML,
Helm charts and Kustomize overlays as they appear in a pull request; it
cannot see a workload nobody opened a PR for, a
kubectl applymade by hand, or drift on a resource already running. Cloudkeel-DD reads the live cluster directly (Helm’s own release records, ArgoCD, Flux), which is exactly the category their own product cannot reach. - Unmanaged resource discovery is not claimed anywhere on their site. Their “MISSING” case in the drift report is the inverse of ours (a resource still named in Terraform state that’s now gone from the cloud), not a live resource no state file ever declared. That category, across AWS/Azure/GCP, is what Cloudkeel-DD leads with and Terracotta does not address at all.
- Cost governance and plain-English guardrails. Terracotta has both: per-resource cost estimates, budget enforcement, and policies written in plain English rather than Rego or Sentinel. We have neither; our policy engine is OPA/Rego.
- Compliance posture. Terracotta’s home page carries SOC 2 Type II and HIPAA badges. We have neither yet: pre-launch, no certifications.
Where that leaves you
| Cloudkeel-DD | Terracotta AI | |
|---|---|---|
| Drift on managed resources | Yes: AWS, Azure, GCP, scheduled scans | Yes: AWS, Azure, GCP, scheduled scans, 1,618 AWS types claimed |
| Unmanaged resource discovery | Yes: AWS, Azure, GCP | Not claimed on any page read |
| Kubernetes | Live cluster read: Helm, ArgoCD, Flux, sixteen kinds | PR-time manifest/Helm/Kustomize scan by content, no cluster access |
| Change attribution: who made it | Best-effort, native cloud audit logs, within a lookback window | Not documented on the pages we read |
| Cloud write access | None: read-only, enforced in code | Not documented as writing to the cloud; fixes commit to the PR branch |
| Remediation model | Reviewed pull request, always | Committable PR suggestion, “Fix All” on grouped root causes |
| Cost governance | None | Per-resource estimates, budget enforcement, plain-English guardrails |
| Deployment | Self-hosted Helm chart, the only mode | SaaS (GitHub/GitLab app); self-hosted/VPC is Enterprise-only |
| Compliance certifications | None | SOC 2 Type II, HIPAA |
| Entry pricing | Free forever: 1 scope, 3 users, every feature | Free: 1 private repo (20 PRs/mo), 5 seats, drift on 1 repo |
| Next tier | Team: $79/enabled scope/mo (annual) or $99 month-to-month | Platform: $49/engineer/mo, unlimited repos and seats |
The difference that actually matters
Terracotta governs the change. Cloudkeel-DD inspects the estate.
Even with its scheduled drift scans, Terracotta’s model still starts from
something declared: a Terraform resource, a Kubernetes manifest in a repo it
watches. A resource nobody ever wrote code for, or a workload someone
kubectl apply’d by hand outside any pipeline, has no PR and no declared state
for Terracotta to compare against or govern. That is the entire category
Cloudkeel-DD leads with, and it is structural: PR-time governance cannot
reach infrastructure that never went through a PR.
The cost is real, and it is the same cost we named on the other two comparison pages: Terracotta ships cost governance, plain-English policies, and two compliance certifications we do not have. If a regulated buyer’s actual blocker is “we need SOC 2 before we can even evaluate a vendor,” Terracotta clears that bar today and we do not.
Where Terracotta is ahead
Said plainly, because a comparison that only lists our wins is an advert.
- Distribution. A GitHub or GitLab app and a couple of minutes, against
our
helm installplus three generated secrets plus per-integration credential wiring. This is the gap most likely to decide who tries either tool first. - Cost governance and plain-English guardrails: a real capability we do not have at all.
- SOC 2 Type II and HIPAA, published on their home page. We have no certifications and are pre-launch.
- A free tier that needs no infrastructure of your own: connect a repo and it starts reviewing PRs. Ours needs a Kubernetes cluster to install into, at every tier including Free.
- Named backing and an active go-to-market. Terracotta is Y Combinator-backed and actively marketed. We have no public reference customers.
What we do not do
The limits, in the same breath as the claims:
- Unmanaged detection needs a Terraform state source. Something has to define “managed”. A cloud credential on its own produces nothing.
- Attribution is best-effort and can fail quietly. If the IAM permission it needs is missing, the actor is simply absent and nothing on screen says why.
- Kubernetes coverage is sixteen kinds, not arbitrary custom resources.
- Codify emits a Terraform
import{}block only, never a resource body. - No PDF export. CSV exists, is generated in the browser, and carries aggregate report metrics only; there is no per-finding export in any format.
- No cost governance and no PR-time gate on Terraform cost or IAM.
- No rollback and no disaster recovery. If a resource is deleted, we can tell you it’s gone; we cannot bring it back.
- Scans are point-in-time, on a schedule you set. This is not a live feed and we will not describe it as one.
- Nothing phones home: no telemetry, no analytics, no licence server, and it runs air-gapped. But three paths do carry finding data outward when you configure them: notification webhooks, and the GitHub and GitLab integrations that open remediation pull requests. We will not tell you nothing leaves your environment, because that would not be true.
Which one to pick
Choose Terracotta if your primary pain is PR-time governance (catching a bad Terraform or Kubernetes change, its cost, and its policy violations before it merges) and you want cost estimation, plain-English guardrails, and SOC 2 / HIPAA compliance without running anything yourself.
Choose Cloudkeel-DD if you want to know what is actually running in your cloud right now, including the resource nobody wrote a PR for and the console change nobody merged back, entirely inside infrastructure you already control, without sending credentials to a SaaS vendor to get it.
What about the clouds’ own tools?
Azure Policy, AWS Config and GCP Asset Inventory each answer part of this: inside their own cloud, in their own query language, without reference to your Terraform. If your estate is one cloud, evaluate them first; they are already paid for. If it spans clouds, the check becomes three different checks, and none of them can say “this resource is in no Terraform state”, because that comparison needs your state, which is the input they do not take.
Read more
- What Cloudkeel-DD is: the product page
- Exactly where the depth ends: coverage, generated from the engine
- Install it yourself: no call, no account
Sources
- Terracotta pricing tiers, feature breakdown by plan: tryterracotta.com/pricing
- Terracotta drift detection: scheduled scans, 1,618 AWS resource types, suppression lifecycle. tryterracotta.com/features/drift-detection
- Terracotta Kubernetes: manifest/PR-only scanning, no cluster access, recognized kinds. tryterracotta.com/features/kubernetes
Read 2026-08-28. If any of this has changed, tell us and we will correct it: a comparison that goes stale is worse than none.