We take the security of your cloud infrastructure data seriously. Here's how we protect your information.
Security is built into every layer of our platform.
All data is encrypted at rest using AES-256 encryption. Database volumes use AWS EBS encryption with customer-managed keys.
All network traffic is encrypted using TLS 1.3. API endpoints enforce HTTPS with HSTS headers.
We only collect resource metadata needed for cost analysis. No secrets, credentials, or application data are ever accessed.
Hosted on AWS with VPC isolation, security groups, and private subnets. All infrastructure is defined as code and audited.
Role-based access control (RBAC) for team accounts. API keys are SHA-256 hashed and never stored in plaintext.
Data is stored in US regions by default. Enterprise customers can choose EU or other regions for data residency requirements.
Our CLI uses read-only AWS and Azure APIs. Here's exactly what we collect.
We're committed to meeting industry standards and regulatory requirements.
Fully compliant. Data processing agreements available on request.
Fully compliant with California Consumer Privacy Act requirements.
Audit in progress. Not yet certified; contact us for our current security posture and timeline.
Run scans entirely offline with no data leaving your network. Available on Enterprise.
Read-only AWS and Azure API access. It never needs write permissions, and it does not read secrets, credentials, or application data.
Yes. Data is encrypted at rest with AES-256 and in transit with TLS 1.3.
Yes. An air-gapped mode, available on Enterprise, runs scans entirely offline with no data leaving your network.
Yes. CCA is compliant with GDPR and CCPA, and data processing agreements are available on request.