Security
Your data is protected with enterprise-grade security standards.
Least Privilege Access
CostObserver connects to your cloud environment using read-only permissions scoped to billing data and resource metadata only. No access to application code, databases, or workloads. Zero impact on your environment by design.
Responsible AI
Inference only AI matches your data against pre-trained patterns for insights and recommendations. Billing and metadata never enter a training set and are never shared with third parties.
Strict Isolation
Customer data is logically isolated at the database level. Every API request is authenticated and scoped to a specific organisation ID. Cross tenant access is architecturally impossible.
Built for Compliance
All data is encrypted in transit via TLS 1.3 and at rest via AES-256. Security practices are aligned with ISO 27001 and SOC 2 standards. Formal certification is in progress.
Enterprise Deployment
The enterprise tier lets you run a CostObserver collector directly inside your own cloud infrastructure. Billing data, resource behaviour and security signals are processed entirely within your cloud environment. Only the results are shared with the CostObserver platform, which runs in a single tenant infrastructure keeping your data fully isolated from other customers.
Contact us about EnterpriseSecurity & Compliance
Enterprise customers can request in-depth security details or schedule a security review with the CostObserver engineering team.
Found a vulnerability? Report it to security@costobserver.com.
