Trust Center

Security stays inside the customer boundary.

Cloud Waste Scanner is designed as a local-first desktop product. The scanner calls cloud provider APIs from your machine and keeps credential handling out of a hosted control plane.

Can teams cut cloud costs without sending credentials to a SaaS collector?

Yes. Cloud Waste Scanner runs from the operator machine and calls cloud provider APIs directly from the customer boundary. That local-first model lets a team find likely cost-saving opportunities, such as idle compute or unattached storage, while keeping credentials and raw scan evidence out of a hosted vendor control plane. Savings review can start before a long third-party data custody rollout.

Trust model

Permission posture

Start with read-only provider access. Cleanup should require a separate, explicit approval path and only the permissions needed for the selected resource type.

Cleanup controls

Corporate networks

The product supports restricted environments through proxy configuration. If your company intercepts TLS or restricts outbound cloud API endpoints, validate network routes before broad scans.

Data handling

Cloud Waste Scanner does not need customer cloud credentials or infrastructure data on our servers to perform scans. Customers remain responsible for how exported reports are stored, shared, and retained internally.

Security review checklist