Security you can verify — not just badges.
OptCloud is built so finance and engineering can share cloud cost data without expanding your attack surface. Read-only connectors, encryption, audit trails, and clear access control.
How we earn trust
Customers feel safe when the architecture is clear. Here is what OptCloud does — and what we do not overclaim.
Least privilege by default
We only ask for the permissions required to read cost and usage metadata. Write access for automation is optional, explicit, and gated by human approval.
Your workloads stay yours
OptCloud does not install agents in your clusters or VMs. We never need application payloads, customer PII from your products, or production secrets to do FinOps.
Honest about compliance
We do not claim SOC 2 or ISO 27001 certification today. We design controls that support those frameworks and will pursue formal audits as the company matures — we will not put a badge on the site until it is earned.
Controls that matter in practice
Product and platform safeguards you can evaluate in a security review today.
Read-only cloud access
Connect via IAM roles / service principals scoped to billing and usage APIs. No agents. No workload introspection.
Encryption in transit and at rest
TLS for all traffic. Encrypted storage for cost data and configuration. Enterprise options for stricter key management as we grow.
SSO, RBAC, and workspace isolation
Invite-only workspaces, role-based access, and SSO/SAML on Business+. Tenant data is isolated by organization.
Audit logs
Who invited a user, rotated a connector, changed billing, or exported data — visible in-product and exportable as CSV.
Human approval for automation
Optimization actions that write to your cloud require an explicit approve step. Read paths stay separate from write paths.
Data minimization
We store cost, usage, tags, and inventory metadata needed for FinOps — not your application content or end-customer data.
Compliance posture
We align with privacy and security expectations without pretending we hold certificates we do not.
Privacy (GDPR / LGPD)
Account and workspace data are handled under our Privacy Policy. We design for data-subject rights and regional expectations. Formal DPAs are available for enterprise deals.
SOC 2 / ISO 27001
Not certified yet. Controls on this page are the foundation we will take into a formal audit program. When certification is complete, we will publish evidence — not before.
For your security review
Need a questionnaire, architecture diagram, or walkthrough of our connector permissions? We answer those directly — no marketing theater.