BY HOOP.DEV / DATABASE DISCOVERY

Map every resource
your company forgot about

A read-only census of every managed database your AWS credentials can reach.
Runs on your machine, output stays local, zero telemetry.

Free & Open SourceRead-OnlyNo Account Required
01

Point it at your AWS credentials

Uses the standard AWS credential chain: env vars, profiles, SSO. Read-only IAM permissions, describe and list calls only. Nothing is ever modified.

blueprint scan --profile prod
02

Census every managed database

Sweeps RDS, Aurora, DocumentDB, Neptune, DynamoDB, ElastiCache, and Redshift across every region, or your whole AWS Organization with --org.

✓ 214 databases · 3 accounts · 12 regions
03

Read the report, locally

One self-contained HTML file, plus JSON and CSV. Scans archive on your machine, so the next run shows exactly what changed.

report written to blueprint-2026-07-16.html
blueprintv0.2.0generated locally · Jul 16, 2026
3 accounts · 12 regions · 214 databasesread-onlycomputed locally · nothing leaves your machine
Databases
214
8 engines · 3 accounts
Attribution score
61/100
owner + environment tagged
Untagged
38
no owner or environment
End-of-life
6
upstream support ended
Exposed
9
public, unencrypted, or no backups
Scan failures
0
every scan unit succeeded
Fully attributed131Partially attributed45Untagged38
NameEngineEnvironmentRegionStatus
payments-primary
aurora-postgresql15.4
production
us-east-1
available
orders-cache
redis7.1
production
us-east-1
availableunencrypted
legacy-reports
mysql5.7.44EOL
eu-west-1
available
growth-events
dynamodb
development
us-west-2
active
billing-staging
postgres13.13
staging
sa-east-1
stopped
generated locally by blueprint — open source: github.com/hoophq/blueprint · nothing leaves your machine

A sample of the HTML report. Engine versions checked against end-of-life dates, ownership scored from tags, scan failures listed, never hidden.

Nothing deployed in your cloud

Runs from your laptop against your own credentials. No agents, no CloudFormation, nothing installed in the target account.

Local-only, zero telemetry

Reports are written to disk and scan history stays in ~/.blueprint. No analytics, no crash reporting, no update checks. The only network calls are to AWS.

Honest coverage, not magic

Maps what is reachable from the credentials you give it. Owner and environment come from tags, imported and never inferred, and every scan failure is listed in the report.

Need this mapped, governed, and access-controlled centrally?

hoop turns discovery into control. Centralize access to every database it finds, with policy, data masking, and full audit logs.