CloudPilot

What is stored

This service never reads your cloud. The open-source scanner runs where it always runs, in your own account, cluster, CloudShell or laptop, and you choose to upload its result. Everything known about your cloud comes from that file and nothing else; the rest of the list below is what signing in, inviting a teammate and uploading need in order to work.

Held

Resource IDs, evidence and warnings can contain names you chose (a volume's Name tag, a bucket, a namespace, a workload). If a name is sensitive, leave it out with the cloudpilot ignore tag or label before you scan.

Not held

What it does with it