Security & data privacy
Security posture at a glance — see the Trust Center for the full picture.
- Read-only by design. The IAM role cannot create, modify, or delete anything, and has no data-plane access (it can list your S3 buckets, not read your objects).
- No stored AWS credentials. Access uses short-lived STS role assumption with a per-tenant External ID; deleting the CloudFormation stack revokes access instantly.
- Tenant isolation. Every piece of scan data is scoped to your workspace.
- Session security. Active sessions are listed (and revocable) on your Profile page; idle sessions expire automatically; sensitive settings require fresh re-authentication.
- Audit logging. Configuration changes (connections, SSO, exceptions, rules, membership) are recorded with actor and timestamp.
See also our Trust Center, Privacy Policy, and Terms of Service.