What is stored
This service never reads your cloud. The open-source scanner runs where it always runs, in your own account, cluster, CloudShell or laptop, and you choose to upload its result. Everything known about your cloud comes from that file and nothing else; the rest of the list below is what signing in, inviting a teammate and uploading need in order to work.
Held
- For each finding: the title, the kind of waste, the region or namespace, the resource type and resource IDs, the evidence lines, the monthly cost and how it was worked out, the fix commands, their risk and the way back, and the rule confidence.
- For each scan: when it was taken, which regions or namespaces it covered, the scanner's own total, the checks that could not run (the error text, which can include the name of the role that was refused), the names of resources left out by the ignore tag, for an AWS scan made with the scanner's bill option the month it read, that month's total bill, whether AWS still marks it as an estimate and, if it could not be read, the reason, and for a cluster the context, the server address, the Prometheus it used and the unit prices.
- For each account or cluster: the AWS account ID, or the kubectl context name of a cluster.
- For people: an email address, a name and a role in the workspace, and for someone who signs in with GitHub the numeric GitHub account ID, which is what their sign-in is matched on.
- For upload tokens: a name, the first few characters, when it was made and last used, and a hash of it. Never the token itself.
- For signed-in browsers: a hash of the session ID and when the session ends. Never the ID itself. A sign-in that has been started but has not come back yet is a hash of its one-time value and an expiry, and is deleted the moment it is used.
- For invitation links: who the owner said the link is for, the first few characters, a hash of it, when it expires, and whether it was revoked or used and by whom. Never the link itself; it is shown to the owner once and no email is sent.
Resource IDs, evidence and warnings can contain names you chose (a volume's Name tag, a bucket, a namespace, a workload). If a name is sensitive, leave it out with the cloudpilot ignore tag or label before you scan.
Not held
- No cloud credentials. No AWS keys, no roles to assume, no kubeconfig, no tokens for your cluster. This service has no way to connect to your account or cluster.
- No object contents, no file contents, no secrets and no environment variables: the scanner does not read them.
- Nothing else from GitHub. Signing in asks GitHub for one thing, the verified primary email address. The token that comes back is used once to read the account ID and that address, then thrown away: it is never stored or written to a log. We also ask GitHub to revoke it straight away, so it stops working there too, where GitHub allows that. No avatar, and nothing about repositories or organisations. The account's login name is stored only when GitHub has no display name for it, in which case it stands in as the name.
- The scan file itself is not kept as a file. Its fields are stored as listed above. The scanner's own summary text and comparison are dropped, and so are two things it also sends: the scanner's own figure for the share of the bill that waste makes up (this service works out that share itself from the two totals it keeps) and each finding's own "new" flag, since this service works out what is new from your history.
- A warning longer than 4,000 characters is stored up to that length and ends with a note of how much was cut.
What it does with it
- It shows what is new and what was resolved since the last scan, one place for every source, and the trend of the monthly figures.
- It never runs a fix. The commands are shown for a person to copy and run themselves.
- A finding is only called resolved when the place it lives in was scanned again in full and it is gone. A scan that did not cover the place, or could not run a check there, resolves nothing.
- Every figure is the scanner's own. This service adds up the scanner's numbers; it does not price anything itself.
- Everything is visible only to the people in the workspace that uploaded it.