Skip to content
CloudSave

Security

CloudSave is built around one principle: we read, we never write. Every integration point is designed so that a compromise of our platform cannot modify your infrastructure.

Read-only access

You grant CloudSave access through a credential that has read and audit permissions only. On AWS that is an IAM role delivered as a CloudFormation stack: it can list resources, read billing data, and pull metrics — nothing else. Every provider we add uses the equivalent native grant (a service principal on Azure, a service account on GCP). We never receive, store, or accept write credentials of any kind.

You can revoke the credential yourself, at any time, from your own console, without asking us. The stack we provide documents every permission in plain language.

What we store

The platform stores only analysis aggregates and findings — service counts, cost breakdowns, utilisation metrics, and the recommendations we generate from them. Raw billing exports are processed in memory and not persisted beyond the analysis window.

EU data residency

All infrastructure runs inside the EU:

  • Cloudflare edge — TLS termination, DDoS protection, and static asset delivery.
  • Contabo, Germany — the analysis API and the jobs that read your cloud data.
  • Neon PostgreSQL eu-central-1 — the primary database. Backups are encrypted at rest.

No customer data leaves the EU region.

Sub-processors

Sub-processorPurposeData handled
CloudflareHosting, edge compute, Web AnalyticsPage requests, TLS metadata
Contabo (Germany)Analysis API and scheduled jobsCloud resource metadata, cost figures, findings
NeonPostgreSQL hostingAnalysis aggregates, account metadata
ResendTransactional emailEmail address, message content
PCI Proxy / DatatransCard field tokenisationCard data never touches our systems — it is captured inside PCI Proxy’s secure iframes and tokenised before our checkout Worker sees it

We review sub-processors annually and notify customers before adding a new one.

How to reach us

Questions about security, data handling, or a data-processing addendum: hi@cloudsave.co.

Edited in the CMS at /admin; last reviewed 2026-09-18.