Skip to main content

Security and data access

You create the access, so you control it. Here's what you grant, what it can and can't do, what we don't ask for, when we stop using it, and how you can check us.

The access you grant

You create the access in your own account, so you can inspect it and remove it. We send the exact permission list with the access guide, so you can read it before you create anything.

AWS

  • A cross-account IAM role with read-only permissions, protected by an external ID.

Google Cloud

  • A service account with read-only roles on the projects or organization you choose.

Azure

  • A custom view-only role, assigned to the CloudLevy app on the subscription you choose. An admin in your tenant adds the app and assigns the role. You can remove the role and the app at any time.
  • It reads cost data, savings suggestions, resource settings, and usage metrics. It cannot change anything, read stored data, query log data, or open support tickets. It does not include invoices, so Azure checks can use an invoice or cost report that you share.
  • We send the exact list of permissions before you create anything.

What the access lets us do: view your cost and billing data, how your resources are set up, and the usage your cloud already records for them.

What this access cannot do

It cannot create, delete, start, stop, or change your cloud resources.

What we don't ask for

  • Passwords or root credentials.
  • Long-lived access keys or private keys.
  • Permission to change, create, or delete your cloud resources.

When we stop using the access

We use the access for the assessment and for the check of each fix you apply, at your next invoice after the change. After the last check, we stop using it, and we'll ask you to remove it. The assessment and the fixes involve no ongoing monitoring. You can delete it sooner whenever you want, including right after the assessment. If you'd rather not keep it in place, you can share your invoice or cost report for each check instead.

Billing evidence request

For 12 months after you apply a fix, we may ask for billing evidence, such as invoices or cost reports, to confirm which listed fixes you applied and that the fee was right. This asks for documents, not access to your account. It is a request we may make, not monitoring. You choose how to share them, and you can remove anything unrelated to the question before you send it.

Check it yourself

Your own audit logs can show what the access does, though no cloud records every read call by default.

  • AWS: CloudTrail event history keeps the last 90 days of management events with no setup. Reads of CloudWatch metrics are recorded only if you turn on CloudWatch data event logging in a trail.
  • Google Cloud: the Data Access audit logs that record read calls are off by default for most services. You can turn them on for the services you want to watch.
  • Azure: the Activity Log records create, update, delete, and action operations by default and keeps them for 90 days. It does not typically record read calls. You can filter it by our app to see any change the app made.

Remove access any time

Delete the role in AWS, remove the service account's access in Google Cloud, or remove the role and the CloudLevy app in Azure, and the access stops working. Azure documents that removing a role assignment can take up to 10 minutes to take effect.

Cloud API charges

The assessment is free from us. Cloud providers can bill per-request fees to your own account for the read calls the assessment makes. The AWS Cost Explorer API is one that bills per request. The checks make read calls too.

Certifications

CloudLevy holds no third-party security certification or audit report. We'd rather say that plainly than leave you to wonder. What we can offer is access you can read, limit, and remove yourself.