// Security

Read-only on AWS. Honest about what we keep.

You deploy a role we can assume. We never hold your keys. We store finding identity so we can tell you what cleared. We do not store your inventory as a second CMDB. For a signed DPA, email security@unusd.cloud.

// Access

Hub and spoke. No agents.

You deploy a read-only IAM role with CloudFormation, Terraform, or StackSets. The scanner in our hub account calls sts:AssumeRole with an ExternalId unique to your organization. There is no agent in your VPC. Nothing in your accounts is changed unless you act. Startup and above can also register and configure those accounts through the public API. We store an HMAC of the key, never the secret.

The role uses the AWS managed SecurityAudit policy plus a small inline set of read-only calls for Cost Explorer, CloudWatch metrics, Cost Optimization Hub, and pricing. You inspect the template before you deploy.

// Data

What we store

Per organization we keep the following. The finding ledger is how the product reports realized savings (findings that later scans no longer see).

  • AWS account IDs you connect
  • User emails and auth records
  • Notification settings (email, webhook URLs, Telegram when you enable them)
  • Scan schedule
  • Scan history: potential savings, resource counts, cost totals
  • Finding identity over time: resource IDs, ARNs, estimated monthly savings, and whether the finding is still open or has cleared
  • HMAC of customer API keys (never the secret). Keys expire.

we do not store

  • Long-lived AWS credentials (we AssumeRole with a unique ExternalId)
  • Instance user-data, S3 object contents, or secrets
  • A full resource configuration dump or a second CMDB
  • The secret of a customer API key (we store an HMAC, and keys expire)

Product data lives in AWS eu-west-1. Cost Explorer APIs are called in your account (AWS requires us-east-1 for that API). At rest: AES-256. In transit: TLS.

// Navi

Grounded in your scan. Not the open web.

Navi is on Business and Enterprise. It is off until you enable it in Settings. Then it answers from your latest scan and in-app report context. Prompts, findings context (including resource IDs and names), and optional memories are sent to OpenAI to generate the reply. Some HTML report recommendation paragraphs also call OpenAI with a short findings snippet.

We do not use your prompts or scan data to train our own models. OpenAI's API terms currently state that API data is not used to train their models. We have not signed a separate Zero Data Retention addendum.

// Subprocessors

Who processes data besides us

Slack, Microsoft Teams, and Telegram receive payloads only if you configure them. They are then your processors, not ours by default.

Amazon Web Services
Hosting, Cognito auth, SES email, storage, compute
Product control plane in eu-west-1
OpenAI
Navi chat and some report recommendation text, only if you enable Navi
API processor. We do not opt in to training.
AWS Marketplace
Procurement and metering for paid plans
AWS is seller of record. The paid billing funnel.
// DPA and rights

What a DPA is. How to get one.

A DPA (Data Processing Agreement) is the GDPR contract between you as controller of your AWS estate and us as processor of the metadata above. It is not this page. It names the data, the subprocessors, deletion, and breach notice. Enterprise procurement usually asks for it before they sign.

Email security@unusd.cloud to request a DPA, to export what we hold, or to delete an organization. We respond to access and erasure requests without undue delay, and in any event within one month of a verified request. If a request is complex, GDPR allows a further two months, with notice to you.

Standard Contractual Clauses apply for OpenAI. We do not sell scan data.

// Operator

Who runs unusd.cloud

unusd.cloud is operated by ZOPH.IO, SASU, SIREN 880 003 322, France. Consulting work under the zoph.io brand is a separate practice of the same company.

name
ZOPH.IO
form
SASU
SIREN
880 003 322
VAT
FR69880003322
country
France