Max, Maximal's infrastructure agent
Meet MaxA careful, tech-savvy agent for your infrastructure.
Now in private beta — apply for early access →

AWS incident response, done safely

Private beta for teams that want evidence-backed AWS incident response, explicit approvals, and scoped remediation with verification and rollback.
Get early accessSee how it works

Approve

Private-beta deployment cap

24

Versioned incident playbooks

Invite only

Guided beta onboarding


Built for safety

Every guardrail, by default

The product is the trusted action layer — not the diagnosis. We built every safety property in from day one.

Typed actions only

No shell access, no eval, no arbitrary commands. Every AWS write is a named, code-defined function with Zod validation at the boundary.

Confidence gating

Plans are evaluated against confidence and corroborating-evidence thresholds. Below the gate, the incident escalates for review.

Snapshot & auto-revert

Before every permitted write, Max captures state, verifies recovery, and automatically reverts when verification fails.

Blast radius limits

Per-service contracts define the maximum scope of any automated action — which services, which environments, which action types.

Append-only audit trail

SHA-256 hash-chained records capture signals, decisions, proposed actions, and approvals for incident review.

Three autonomy levels

The platform supports Observe, Approve, and Bounded Auto policies. The launch beta uses approval-gated execution with scoped AWS roles.

How it works

From diagnosis to resolved in four steps

01

AWS
Connect a scoped AWS role

Provision tenant-specific cross-account roles with evidence-read permissions and tightly scoped remediation permissions for the designated non-production environment.

01

02

Playbooks
Configure playbooks

Write YAML contracts that declare which services Max watches, what thresholds trigger action, what actions are allowed, and what the blast radius limit is.

02

03

Detection
Observe CloudWatch alarms

The private beta validates CloudWatch alarm intake, evidence collection, contract matching, and policy evaluation in a non-production account.

03

04

Remediation
Review the safety evidence

Inspect the proposed action and evidence, approve it, then follow the execution, verification, rollback, and replayable audit trail.

04

Private-beta integration scope

Amazon Web Services
CloudWatch
Private beta

Validate the control plane safely

Private beta access is free, manually provisioned, approval-gated, and not self-serve billed.

Current access
Private beta

Free during beta

Invite-only, guided validation in a designated non-production AWS account. No card required and no automatic conversion to a paid plan.

Request beta access

Scoped non-production AWS connector

CloudWatch alarm intake

Approval-gated remediation execution

Verification and rollback evidence

Guided onboarding

Validate safely, then enable approvals.

We onboard each beta team into a designated non-production AWS environment, verify evidence collection first, then execute one scoped remediation with explicit approval, verification, and rollback evidence.

Request early access

maximal

The safe execution control plane for AWS incident remediation.

Product
FeaturesPrivate betaChangelogRoadmap

© 2026 Maximal. All rights reserved.

Built for platform engineers who care about safety.