Security & Compliance

We take the security of your cloud infrastructure data seriously. Here's how we protect your information.

How We Protect Your Data

Security is built into every layer of our platform.

Encryption at Rest

All data is encrypted at rest using AES-256 encryption. Database volumes use AWS EBS encryption with customer-managed keys.

Encryption in Transit

All network traffic is encrypted using TLS 1.3. API endpoints enforce HTTPS with HSTS headers.

Minimal Data Collection

We only collect resource metadata needed for cost analysis. No secrets, credentials, or application data are ever accessed.

Infrastructure Security

Hosted on AWS with VPC isolation, security groups, and private subnets. All infrastructure is defined as code and audited.

Access Controls

Role-based access control (RBAC) for team accounts. API keys are SHA-256 hashed and never stored in plaintext.

Data Residency

Data is stored in US regions by default. Enterprise customers can choose EU or other regions for data residency requirements.

What We Access

Our CLI uses read-only AWS and Azure APIs. Here's exactly what we collect.

What We Collect

  • Resource types and configurations
  • Instance sizes and utilization metrics
  • Storage volumes and access patterns
  • Network configurations (public/private)
  • Pricing and cost allocation tags
  • Region and availability zone info

What We Never Access

  • Application data or file contents
  • Database records or queries
  • Secrets, credentials, or API keys
  • Network traffic or logs
  • IAM user passwords or access keys
  • S3 object contents

Compliance

We're committed to meeting industry standards and regulatory requirements.

GDPR

Compliant

Fully compliant. Data processing agreements available on request.

CCPA

Compliant

Fully compliant with California Consumer Privacy Act requirements.

SOC 2 Type II

In Progress

Audit in progress. Not yet certified; contact us for our current security posture and timeline.

Air-Gapped Mode

Supported

Run scans entirely offline with no data leaving your network. Available on Enterprise.

Security FAQ

What access does CCA need?+

Read-only AWS and Azure API access. It never needs write permissions, and it does not read secrets, credentials, or application data.

Is my data encrypted?+

Yes. Data is encrypted at rest with AES-256 and in transit with TLS 1.3.

Can I run scans without sending data to your servers?+

Yes. An air-gapped mode, available on Enterprise, runs scans entirely offline with no data leaving your network.

Are you GDPR and CCPA compliant?+

Yes. CCA is compliant with GDPR and CCPA, and data processing agreements are available on request.

Have Security Questions?

Our team is happy to discuss your security requirements and provide additional documentation.