You are about to hand us a credential. Here is exactly what happens to it.
This page is written to be forwarded. If your reviewer needs something that is not here, write to security@hellocloudwatch.com and a person will answer.
Where credentials live
Every cloud and vendor credential you connect is stored in Azure Key Vault, with strict access policies, and nowhere else. Our application database holds a reference to the secret — never the secret. It holds your account, your business-context mappings and the cost figures the agent has read, partitioned per tenant so your records are not co-located with another customer's. If somebody walked out with a copy of our database, they would not have a single one of your keys.
What each vendor's credential can do
Every tool the agent has is a read. None resizes a machine, kills a deploy or changes an access policy — that is a property of the tool surface we built, and it is true for every vendor in the table regardless of what their credential would permit. Where a vendor issues only a broad key, the restraint is ours to keep, and the table says so rather than implying the key itself is narrow.
The table is generated from the same vendor registry the product connects with, so a vendor cannot be added to the product and left off this page.
| Vendor | Credential scope | How to revoke |
|---|---|---|
| Microsoft Azure | Narrow Scoped to billing. The credential this vendor issues us can read what it costs and nothing else — no resource configuration, no ability to change anything. | Disconnect in your account settings — the secret is deleted from the vault immediately — or delete the credential in the vendor's own console. |
| Google Cloud Platform | Narrow Scoped to billing. The credential this vendor issues us can read what it costs and nothing else — no resource configuration, no ability to change anything. | Disconnect in your account settings — the secret is deleted from the vault immediately — or delete the credential in the vendor's own console. |
| Amazon Web Services | Narrow Scoped to billing. The credential this vendor issues us can read what it costs and nothing else — no resource configuration, no ability to change anything. | Disconnect in your account settings — the secret is deleted from the vault immediately — or delete the credential in the vendor's own console. |
| Cloudflare | Narrow Scoped to billing. The credential this vendor issues us can read what it costs and nothing else — no resource configuration, no ability to change anything. | Disconnect in your account settings — the secret is deleted from the vault immediately — or delete the credential in the vendor's own console. |
| Vercel | Narrow Scoped to billing. The credential this vendor issues us can read what it costs and nothing else — no resource configuration, no ability to change anything. | Disconnect in your account settings — the secret is deleted from the vault immediately — or delete the credential in the vendor's own console. |
| OpenAI | Broad An OpenAI admin key can read and manage your whole organization. We only ever call the costs endpoint, and the key is stored in Azure Key Vault — never in our database. You can revoke it at any time. | Revoke in OpenAI One click there and the key we hold stops working. |
| Anthropic | Broad An Anthropic admin key can read and manage your whole organization. We only ever call the cost report endpoint, and the key is stored in Azure Key Vault — never in our database. You can revoke it at any time. | Revoke in Anthropic One click there and the key we hold stops working. |
| Neon | Narrow Scoped to billing. The credential this vendor issues us can read what it costs and nothing else — no resource configuration, no ability to change anything. | Disconnect in your account settings — the secret is deleted from the vault immediately — or delete the credential in the vendor's own console. |
| Apify | Narrow Scoped to billing. The credential this vendor issues us can read what it costs and nothing else — no resource configuration, no ability to change anything. | Disconnect in your account settings — the secret is deleted from the vault immediately — or delete the credential in the vendor's own console. |
How to revoke, in about a minute
Disconnecting an account in your settings deletes the secret from the vault immediately — not at the end of a cycle, not after a support ticket. You can also revoke from the vendor's own console, which is the column above, and the key we hold simply stops working. Deleting your account purges every stored credential immediately; see the privacy notice for what happens to the rest.
Encryption
In transit: TLS. At rest: Azure Key Vault for secrets and Azure Cosmos DB's service-managed encryption for application data, both in Microsoft Azure's East US region. We do not store card numbers at all — those stay with Stripe.
Who else touches your data
Each of these operates under a data-processing agreement. This is the same list the privacy notice renders, from the same source, so the two pages cannot drift apart.
| Provider | Purpose | Region |
|---|---|---|
| Microsoft Azure | Hosting, Cosmos DB, Key Vault, and the Azure OpenAI model the agent reasons with. | USA |
| Firebase (Google) | Authentication. | USA |
| Stripe | Payment processing. | USA |
| Postmark | Transactional email — invitations, observation notifications, and account-lifecycle messages. | USA |
| LogRocket | In-app session replay for debugging. Not used on this marketing site. | USA |
What the model sees, and what it does not
The reasoning step runs on Azure OpenAI. It sees the cost and usage figures for the accounts you have connected and the business context you gave it. It does not see your credentials, it has no access to the public internet, and it has no access to any data outside the cost surface you connected. None of it is used to train models. Microsoft may retain inputs for up to 30 days for abuse monitoring under standard Azure OpenAI terms; the deployment is not used for training.
Retention and deletion
Observation journal entries are kept for 13 months, which is what lets a report compare a month against the same month last year. When you delete your account, credentials go immediately and everything else enters a 30-day window in which it is hidden from your workspace but still restorable, then is permanently deleted. We then hold a minimal billing record — tenant id, cancellation date, plan — with no customer data, for a further 60 days. You can ask us to purge earlier at any time.
What we are not
We are not SOC 2 audited and we hold no ISO 27001 certification. We run on Microsoft Azure, whose certifications are Microsoft's and not ours, and we will not borrow them. What you can verify instead is everything above: credentials stored only in Azure Key Vault and never in our database, the narrowest credential each vendor issues, revocation in about a minute, and every sub-processor named with its purpose and region. When we have a report, this paragraph will say so and you will be able to ask for it.
Reporting something
Write to security@hellocloudwatch.com. Our disclosure policy is published at /.well-known/security.txt (RFC 9116) and carries the same address. We do not run a bounty programme; we do read every report.