Security

You're trusting us with your clients' bills. Here's how we earn it.

We ask for the least access that lets us do the job, we make it easy to inspect, and we make it easy to take away.

Least-privilege access

We connect through a cross-account IAM role — never access keys. The role can read the billing export and AWS cost-optimisation recommendations, and nothing else. It has no write, delete or configuration permissions.

Protection against impersonation

Every connection has its own External ID, so no one else can trick our service into reading your data (the "confused deputy" problem). Only our ingest service can assume the role.

Encryption

Data is encrypted in transit with TLS and at rest in AWS. Buckets block all public access and reject unencrypted connections.

Separation between customers

Each agency's data is stored and queried separately from every other agency's, and each client sees only their own reports.

Transparent and revocable

The onboarding template is short and readable, and we share it before you deploy it. Deleting the stack removes our access immediately.

Your data, on request

When you leave, we delete the billing data we hold for your connections. You can ask for deletion at any time.

Reporting a vulnerability

If you believe you've found a security issue, please email security@gharama.cloud with the details. We'll acknowledge your report and keep you updated while we investigate. Please don't access other customers' data or disrupt the service while testing.