AWS Integration

AWS stays. Everything else joins it.

Most infrastructure teams already run something on AWS, and this page isn't about changing that. Connect the AWS account you already have, and it joins the same control plane as your EU providers and your own hardware - one inventory, one audit trail, one place to provision from. Your AWS contract, billing and account stay exactly where they are, unless you choose otherwise.

Live DNS: yesLive firewall: yesLive network: not yet

Connect the account you already have

Connect your existing AWS account and Sencai discovers what's already running there - nothing migrates, your AWS contract and billing stay exactly where they are, and you can revoke access at AWS at any time. Credentials are encrypted at rest and scoped to what Sencai needs to do the job. If you'd rather not hold the account yourself, Sencai can provision and bill AWS capacity under its own account instead: one contract, one invoice, AWS's own cost passed through plus a 2% margin shown separately on the statement. Both models work in the same organisation - start with your own AWS account and add Sencai-billed capacity later, or the other way around, without re-platforming anything you already run.

What Sencai sees the moment you connect

The moment you connect an AWS account, Sencai inventories what's running - instances, networks, storage, DNS records - the same pass it runs against every other provider you connect. Nothing is auto-imported into active management: existing resources show up as discovered, and you decide, one resource at a time, which ones Sencai actively manages versus simply tracks. That inventory sits next to whatever else your organisation runs - Hetzner, OVHcloud, Scaleway, a rack of bare-metal servers with the fleet agent installed - so an AWS account stops being a separate thing you check and becomes one row in a list you already look at alongside everything else.

One workflow, and two of them are live at AWS

Provisioning, starting, stopping, resizing and destroying AWS instances works the same way it does for every other provider you connect - one workflow, not a separate console habit to keep up. DNS records and firewall rules go further: Sencai manages both live, synchronously, directly against AWS's own API - not a cached mirror that drifts from what's actually configured in your account. Change a DNS record or a security-group rule through Sencai and it's changed at AWS the moment you save it. AWS is one of only two providers, alongside Hetzner, where Sencai's firewall management reaches this deep - most others stop at provisioning. For any Linux server behind your AWS account, the fleet agent adds monitoring, patching, software inventory and approval-gated runbooks, so an incident procedure you write once for AWS runs identically on every other server in your fleet.

One audit trail, one cost view

Every action Sencai takes against your AWS account - a provisioned instance, a changed security-group rule, a DNS record updated - lands in the same append-only, hash-chained audit log as everything else in your organisation. "Who changed this, and when" becomes a query against one log, not a search through AWS's own console history plus whatever else touched the account that week. Cost visibility works the same way: AWS spend sits in the same view as every other connected provider, with anomaly detection watching for the spike that would otherwise show up as a surprise on next month's bill. If Sencai is billing AWS capacity on your behalf, that 2% margin is broken out as its own line next to AWS's own cost, not folded into one opaque number.

Frequently asked

Does connecting AWS to Sencai migrate anything off AWS?

No. Connecting an AWS account discovers what's already there and lets Sencai manage it going forward - nothing moves off AWS, no data is copied elsewhere, and no resource is re-created. Your AWS contract, support plan and billing relationship with AWS stay exactly as they are. If you ever disconnect, revoke Sencai's access at AWS and the account is exactly as you left it.

Is the AWS firewall and DNS management live, or a copy in Sencai's own database?

It's live. Sencai's DNS and firewall management for AWS talks to AWS's own APIs synchronously - a change you make through Sencai is a change made at AWS immediately, not a value stored in Sencai's database that gets reconciled later. AWS is one of two providers, alongside Hetzner, where this live management reaches security-group rules as well as DNS.

Can I manage AWS alongside Hetzner, OVHcloud or other providers in one place?

Yes - that's the point of connecting it here rather than managing it on its own. AWS sits in the same inventory, provisioning workflow, audit log and cost view as Hetzner, OVHcloud, Scaleway, UpCloud, Azure, Google Cloud, DigitalOcean, Vultr, Linode, Oracle Cloud and any bare-metal servers running the fleet agent - one organisation, eleven providers plus your own hardware.

Do I bring my own AWS account, or can Sencai bill AWS for me?

Both are supported in the same organisation. Bring your own AWS account and your contract, billing and support relationship stay with AWS directly - Sencai just operates it. Or let Sencai provision and bill AWS capacity under its own account: one contract, one invoice, AWS's own cost plus a 2% margin shown as its own line. You can start with one model and add the other later.

Is Sencai ISO 27001 or SOC 2 certified for handling our AWS environment?

No, and we say so rather than imply otherwise - Sencai does not hold ISO 27001 or SOC 2 today. What we hand a security review instead is the evidence those frameworks usually check for: an exportable, tamper-evident audit trail of everything done to your AWS account, records of processing, a published sub-processor register, a written data-residency statement and our published Data Processing Agreement.

Visit AWS ↗

Bring AWS into one control plane

Connect your existing AWS account or let Sencai provision and bill capacity for you - both work in the same organisation, alongside ten other providers and your own hardware. Start free, or run the 14-day trial with no card required.

Start free trialTalk to us