Read-only on AWS. Honest about what we keep.
You deploy a role we can assume. We never hold your keys. We store finding identity so we can tell you what cleared. We do not store your inventory as a second CMDB. For a signed DPA, email security@unusd.cloud.
Hub and spoke. No agents.
You deploy a read-only IAM role with CloudFormation, Terraform, or StackSets. The scanner in our hub account calls sts:AssumeRole with an ExternalId unique to your organization. There is no agent in your VPC. Nothing in your accounts is changed unless you act. Startup and above can also register and configure those accounts through the public API. We store an HMAC of the key, never the secret.
The role uses the AWS managed SecurityAudit policy plus a small inline set of read-only calls for Cost Explorer, CloudWatch metrics, Cost Optimization Hub, and pricing. You inspect the template before you deploy.
What we store
Per organization we keep the following. The finding ledger is how the product reports realized savings (findings that later scans no longer see).
- ▸AWS account IDs you connect
- ▸User emails and auth records
- ▸Notification settings (email, webhook URLs, Telegram when you enable them)
- ▸Scan schedule
- ▸Scan history: potential savings, resource counts, cost totals
- ▸Finding identity over time: resource IDs, ARNs, estimated monthly savings, and whether the finding is still open or has cleared
- ▸HMAC of customer API keys (never the secret). Keys expire.
we do not store
- ▸Long-lived AWS credentials (we AssumeRole with a unique ExternalId)
- ▸Instance user-data, S3 object contents, or secrets
- ▸A full resource configuration dump or a second CMDB
- ▸The secret of a customer API key (we store an HMAC, and keys expire)
Product data lives in AWS eu-west-1. Cost Explorer APIs are called in your account (AWS requires us-east-1 for that API). At rest: AES-256. In transit: TLS.
Grounded in your scan. Not the open web.
Navi is on Business and Enterprise. It is off until you enable it in Settings. Then it answers from your latest scan and in-app report context. Prompts, findings context (including resource IDs and names), and optional memories are sent to OpenAI to generate the reply. Some HTML report recommendation paragraphs also call OpenAI with a short findings snippet.
We do not use your prompts or scan data to train our own models. OpenAI's API terms currently state that API data is not used to train their models. We have not signed a separate Zero Data Retention addendum.
Who processes data besides us
Slack, Microsoft Teams, and Telegram receive payloads only if you configure them. They are then your processors, not ours by default.
What a DPA is. How to get one.
A DPA (Data Processing Agreement) is the GDPR contract between you as controller of your AWS estate and us as processor of the metadata above. It is not this page. It names the data, the subprocessors, deletion, and breach notice. Enterprise procurement usually asks for it before they sign.
Email security@unusd.cloud to request a DPA, to export what we hold, or to delete an organization. We respond to access and erasure requests without undue delay, and in any event within one month of a verified request. If a request is complex, GDPR allows a further two months, with notice to you.
Standard Contractual Clauses apply for OpenAI. We do not sell scan data.
Who runs unusd.cloud
unusd.cloud is operated by ZOPH.IO, SASU, SIREN 880 003 322, France. Consulting work under the zoph.io brand is a separate practice of the same company.
- name
- ZOPH.IO
- form
- SASU
- SIREN
- 880 003 322
- VAT
- FR69880003322
- country
- France