Trust Center
Security stays inside the customer boundary.
Cloud Waste Scanner is designed as a local-first desktop product. The scanner calls cloud provider APIs from your machine and keeps credential handling out of a hosted control plane.
Trust model
- Cloud credentials are entered into the local app, not a hosted SaaS dashboard.
- Scan requests go from the customer machine to cloud provider APIs.
- Scan results and evidence exports stay local unless the customer shares them.
- The website is used for pricing, downloads, documentation, and checkout, not for scanning customer cloud accounts.
Permission posture
Start with read-only provider access. Cleanup should require a separate, explicit approval path and only the permissions needed for the selected resource type.
Cleanup controls
- Findings should be reviewed before action.
- Owners, tags, age, and usage evidence should be checked before deletion or resizing.
- Exports should be kept with internal tickets or governance notes.
- Closed findings that need renewed action should include context for why they reopened.
Corporate networks
The product supports restricted environments through proxy configuration. If your company intercepts TLS or restricts outbound cloud API endpoints, validate network routes before broad scans.
Data handling
Cloud Waste Scanner does not need customer cloud credentials or infrastructure data on our servers to perform scans. Customers remain responsible for how exported reports are stored, shared, and retained internally.
Security review checklist
- Use least-privilege read-only credentials for first scan approval.
- Document who owns provider credentials and who can rotate them.
- Keep cleanup permissions separate from scan permissions.
- Confirm proxy and endpoint access before scanning regulated environments.
- Review exported evidence before sending it outside your organization.