36 images live · AWS and Azure · GCP next
Cloud imagesyou can prove.
AMIs and Azure images built clean-room from official sources, with no credentials baked in and every package listed before you launch. Passwords are generated on your instance at first boot — never on ours.
36 images · one clean-room pipeline
Docker
Metabase Business Intell…
n8n Workflow Automation
Nginx Web Server
Redmine Project Management
Rocket.Chat Team Messaging
SonarQube Code Quality
Jitsi Meet Video Confere…
Ruby on Rails Applicatio…
SuiteCRM Customer Relati…
BookStack Wiki
Grafana
Hugging Face NLP Stack
Jenkins CI Server
LEMP Stack
Matomo Analytics
Neo4j Graph Database
PostgreSQL
- 36
- Production-ready images
- 3
- Cloud platforms
- 0
- Credentials shipped in any image
- 100%
- Built from official sources
every one live in the catalog today
AWS and Azure shipping, GCP next
passwords are generated on your instance at first boot
every component from its vendor’s own repository or release
01How it works
From catalog to production in four steps.
No new control plane, no runtime agent, no lock-in. You get an image ID for your cloud and the documentation to defend it in an audit.
- 01
Pick your cloud and image
Browse by provider, OS, architecture, region, and workload. Every image lists its full software inventory before you launch anything.
catalog — aws + azure
- 02
Subscribe in your account
Shared to your AWS account IDs, or to your Azure subscription through a Compute Gallery, then referenced by image ID from Terraform, CloudFormation, or Bicep. No agents, no control plane, no pipeline changes.
terraform apply
- 03
Stay on the latest version
Patched revisions land on a predictable cadence, each with release notes and the updated software inventory. Upgrading is a version bump, not a migration project.
v2026.07.1 → .2
- 04
Need it customised? Talk to us
Extra packages, your own hardening profile, a different base OS, or a region we do not publish to yet — we build bespoke images against the same pipeline and provenance.
custom build — on request
02From the catalog
Recent launches.
The newest images to land in the catalog. Every entry publishes its full software inventory, hardening posture, and region list before you launch anything.
AWSimage for Amazon Web ServicesDocker and Docker Compose with PortainerUbuntu 24.04 LTS · x86_64 · v29.8.0Available
Azureimage for Microsoft AzureBookStack Wiki and DocumentationUbuntu 24.04 LTS · x86_64 · v26.05.4Available
AWSimage for Amazon Web ServicesMetabase Business IntelligenceUbuntu 24.04 LTS · x86_64 · v0.63.16Available
03Multi-cloud
One clean-room build, every cloud you run.
The same official sources, the same first-boot credential model and the same documented posture — built natively for each cloud rather than lifted-and-shifted between them. AWS and Azure ship today; Google Cloud is next.
Amazon Web Services
Published as AMIs you launch by ID, or shared privately to your AWS account IDs. Drops straight into an existing launch template.
- Identifier
- AMI ID
- Compute
- EC2 instance types
- Storage
- EBS volume
- Region format
- us-east-1
Microsoft Azure
Published through an Azure Compute Gallery, versioned per image definition and shared to your subscription. Works with your existing VM and AKS deployments.
- Identifier
- Compute Gallery image ID
- Compute
- VM sizes
- Storage
- Managed OS disk
- Region format
- westeurope
Google Cloud
The same clean-room build, credential model and patch cadence, published as Compute Engine images. In the pipeline now — tell us which images you need first, and they ship first.
- Identifier
- Compute Engine image
- Compute
- Machine types
- Storage
- Persistent disk
- Region format
- us-central1
Running more than one cloud? Tell us about your setup — image parity across clouds is the whole point.
04Why ProvenCloud
Nothing hidden, nothing baked in.
Every image is built clean-room from official sources and ships with its full software inventory and a written security posture. The only secrets on your instance are the ones it generates for you at first boot.
- Base image
- Canonical Ubuntu LTS · official
- Sources
- vendor repositories and releases only
- Credentials in image
- none · generated at first boot (IMDSv2)
- SSH
- key-only · root login refused
- Database bind
- 127.0.0.1 only
- Build artefacts
- keys, shell history, logs removed
Illustrative sample. Every product page states these facts for its own image, in full, under Security posture — alongside the complete list of installed software and versions.
Official sources only
Every component comes from its vendor’s own repository or release. Nothing is copied from a third-party image, and the finished image is scanned for stray vendor strings before capture.
No credentials in the image
Admin, database and console passwords are generated on your instance at first boot from instance metadata, and the scripts that set them delete themselves afterwards.
Locked down before capture
SSH is key-only with root login refused. Databases listen on 127.0.0.1. Build-time keys, shell history and logs are removed before the image is taken.
Nothing to install
No agent, no daemon, no phone-home. You launch a plain AMI or gallery image, and it keeps working exactly the same if you never talk to us again.
Any region, on request
2 regions liveEvery product page lists the regions its image is published in today. Copying a build to another region is routine work and included — tell us where you run.
publishedon request
Drops into the tooling you already run
- Terraform
- CloudFormation
- Bicep
- Pulumi
- Ansible
- Packer
- Auto Scaling
- Systems Manager
- CloudWatch
- Azure Monitor
Publish with us
List your product in our catalog.
Ship your software as a clean-room, production-ready image on AWS and Azure. We handle the build pipeline, the documentation, the patch cadence and the multi-region replication — you keep the customer relationship.
A real engineer reads every message, and we reply within 1 business day.