// Security

Read-only on AWS. Honest about what we keep.

You deploy a role we can assume. We never hold your keys. We store finding identity so we can tell you what cleared. We do not store your inventory as a second CMDB. For a signed DPA, email security@unusd.cloud.

// Access

Hub and spoke. No agents.

You deploy a read-only IAM role with CloudFormation, Terraform, or StackSets. The scanner in our hub account calls sts:AssumeRole with an ExternalId unique to your organization. There is no agent in your VPC. Nothing in your accounts is changed unless you act. Startup and above can also register and configure those accounts through the public API. We store an HMAC of the key, never the secret.

The role uses the AWS managed SecurityAudit policy plus a small inline set of read-only calls for Cost Explorer, CloudWatch metrics, Cost Optimization Hub, and pricing. You inspect the template before you deploy.

// Data

What we store

Per organization we keep the following. The finding ledger is how the product reports realized savings (findings that later scans no longer see).

  • ▸AWS account IDs you connect
  • ▸User emails and auth records
  • ▸Notification settings (email, webhook URLs, Telegram when you enable them)
  • ▸Scan schedule
  • ▸Scan history: potential savings, resource counts, cost totals
  • ▸Finding identity over time: resource IDs, ARNs, estimated monthly savings, and whether the finding is still open or has cleared
  • ▸HMAC of customer API keys (never the secret). Keys expire.

we do not store

  • ▸Long-lived AWS credentials (we AssumeRole with a unique ExternalId)
  • ▸Instance user-data, S3 object contents, or secrets
  • ▸A full resource configuration dump or a second CMDB
  • ▸The secret of a customer API key (we store an HMAC, and keys expire)

Product data lives in AWS eu-west-1 (Ireland), inside the EU. We do not keep a second copy in a US region. Cost Explorer APIs are called in your account (AWS requires us-east-1 for that API). At rest: AES-256. In transit: TLS. Navi is the exception: it stays off until you enable it, and then a findings snippet goes to OpenAI.

// Navi

Grounded in your scan. Not the open web.

Navi is on Business and Enterprise. It is off until you enable it in Settings. Then it answers from your latest scan and in-app report context. Prompts, findings context (including resource IDs and names), and optional memories are sent to OpenAI to generate the reply. Some HTML report recommendation paragraphs also call OpenAI with a short findings snippet.

We do not use your prompts or scan data to train our own models. OpenAI's API terms currently state that API data is not used to train their models. We have not signed a separate Zero Data Retention addendum.

// Subprocessors

Who processes data besides us

Slack, Microsoft Teams, and Telegram receive payloads only if you configure them. They are then your processors, not ours by default.

Amazon Web Services
Hosting, Cognito auth, SES email, storage, compute
Product control plane in eu-west-1
OpenAI
Navi chat and some report recommendation text, only if you enable Navi
API processor. We do not opt in to training.
AWS Marketplace
Procurement and metering for paid plans
AWS is seller of record. The paid billing funnel.
Fathom
Cookieless pageview counts on the marketing site
No cookie. No account or scan data.
// DPA and rights

What a DPA is. How to get one.

A DPA (Data Processing Agreement) is the GDPR contract between you as controller of your AWS estate and us as processor of the metadata above. It is not this page. It names the data, the subprocessors, deletion, and breach notice. Enterprise procurement usually asks for it before they sign.

Email security@unusd.cloud to request a DPA, to export what we hold, or to delete an organization. We respond to access and erasure requests without undue delay, and in any event within one month of a verified request. If a request is complex, GDPR allows a further two months, with notice to you.

Standard Contractual Clauses apply for OpenAI. We do not sell scan data.

The legal basis for account emails, auth, and the finding ledger is the contract with your organization. We keep that data while the organization is active. There is no automatic expiry timer. Email us to export it or to delete the organization. You can ask for access, correction, deletion, restriction, or portability, or object to a use. You can also complain to the CNIL, the French supervisory authority.

The marketing site counts pageviews with Fathom. Fathom does not set a cookie and does not receive scan data, so there is no cookie banner.

// Operator

Who runs unusd.cloud

unusd.cloud is operated by ZOPH.IO, SASU, SIREN 880 003 322, France. People with access to production are in the European Union. Consulting work under the zoph.io brand is a separate practice of the same company.

name
ZOPH.IO
form
SASU
SIREN
880 003 322
VAT
FR69880003322
country
France