Security
CloudSave is built around one principle: we read, we never write. Every integration point is designed so that a compromise of our platform cannot modify your infrastructure.
Read-only access
You grant CloudSave access through a credential that has read and audit permissions only. On AWS that is an IAM role delivered as a CloudFormation stack: it can list resources, read billing data, and pull metrics — nothing else. Every provider we add uses the equivalent native grant (a service principal on Azure, a service account on GCP). We never receive, store, or accept write credentials of any kind.
You can revoke the credential yourself, at any time, from your own console, without asking us. The stack we provide documents every permission in plain language.
What we store
The platform stores only analysis aggregates and findings — service counts, cost breakdowns, utilisation metrics, and the recommendations we generate from them. Raw billing exports are processed in memory and not persisted beyond the analysis window.
EU data residency
All infrastructure runs inside the EU:
- Cloudflare edge — TLS termination, DDoS protection, and static asset delivery.
- Contabo, Germany — the analysis API and the jobs that read your cloud data.
- Neon PostgreSQL
eu-central-1— the primary database. Backups are encrypted at rest.
No customer data leaves the EU region.
Sub-processors
| Sub-processor | Purpose | Data handled |
|---|---|---|
| Cloudflare | Hosting, edge compute, Web Analytics | Page requests, TLS metadata |
| Contabo (Germany) | Analysis API and scheduled jobs | Cloud resource metadata, cost figures, findings |
| Neon | PostgreSQL hosting | Analysis aggregates, account metadata |
| Resend | Transactional email | Email address, message content |
| PCI Proxy / Datatrans | Card field tokenisation | Card data never touches our systems — it is captured inside PCI Proxy’s secure iframes and tokenised before our checkout Worker sees it |
We review sub-processors annually and notify customers before adding a new one.
How to reach us
Questions about security, data handling, or a data-processing addendum: hi@cloudsave.co.
Edited in the CMS at /admin; last reviewed 2026-09-18.