The access you grant
You create the access in your own account, so you can inspect it and remove it. We send the exact permission list with the access guide, so you can read it before you create anything.
You create the access, so you control it. Here's what you grant, what it can and can't do, what we don't ask for, when we stop using it, and how you can check us.
You create the access in your own account, so you can inspect it and remove it. We send the exact permission list with the access guide, so you can read it before you create anything.
What the access lets us do: view your cost and billing data, how your resources are set up, and the usage your cloud already records for them.
It cannot create, delete, start, stop, or change your cloud resources.
We use the access for the assessment and for the check of each fix you apply, at your next invoice after the change. After the last check, we stop using it, and we'll ask you to remove it. The assessment and the fixes involve no ongoing monitoring. You can delete it sooner whenever you want, including right after the assessment. If you'd rather not keep it in place, you can share your invoice or cost report for each check instead.
For 12 months after you apply a fix, we may ask for billing evidence, such as invoices or cost reports, to confirm which listed fixes you applied and that the fee was right. This asks for documents, not access to your account. It is a request we may make, not monitoring. You choose how to share them, and you can remove anything unrelated to the question before you send it.
Your own audit logs can show what the access does, though no cloud records every read call by default.
Delete the role in AWS, remove the service account's access in Google Cloud, or remove the role and the CloudLevy app in Azure, and the access stops working. Azure documents that removing a role assignment can take up to 10 minutes to take effect.
The assessment is free from us. Cloud providers can bill per-request fees to your own account for the read calls the assessment makes. The AWS Cost Explorer API is one that bills per request. The checks make read calls too.
CloudLevy holds no third-party security certification or audit report. We'd rather say that plainly than leave you to wonder. What we can offer is access you can read, limit, and remove yourself.