Your cost data never leaves your account

Cloud-Vex is not a platform you send your cloud data to. The whole application — compute, database and interface — deploys inside your own cloud account and stays there. We hold no credentials to your environment, store none of your resource inventory, and run no shared database with other customers in it.

YOUR CLOUD ACCOUNT Cloud-Vex app Scanner · UI · API Serverless compute Your findings Database in your account Your keys · your retention Your resources Volumes, IPs, snapshots, instances, load balancers READ-ONLY ACCESS Cloud-Vex reports what is wasteful. You decide what to delete. YOUR OTHER CLOUDS Collectors Read inventory, report back to your own app CLOUD-VEX Licence and version checks. No resource data.
Inside your perimeter — never transmitted to us Crosses the perimeter — listed in full below

Everything that crosses the line

A security review usually starts by asking what data leaves the environment. Here is the complete list for Cloud-Vex, so you can confirm it against your own egress logs rather than taking our word for it.

Connection Direction What it carries
Licence validation Outbound to Cloud-Vex Your licence key, so the deployment can confirm the subscription is active and learn what it is entitled to. Checked daily. No account identifiers, no resource inventory, no cost figures. A deployment keeps running for seven days if it cannot reach us.
Version check Outbound to Cloud-Vex The deployed version string, so the app can tell you an update is available. Can be disabled; updates then become manual.
Marketplace entitlement Outbound to your cloud provider Licence validation against the marketplace you purchased through. This is a call to your provider, not to us. We see the subscription record the marketplace shows every seller — company name and subscription status — and nothing from inside your account.
Support email Outbound, only when you send it Whatever you choose to include when you contact support. If you attach a scan export to a support request, we see the contents of that attachment. Nothing is collected automatically.

There is no cross-account IAM role granting Cloud-Vex access to your environment, because there is no Cloud-Vex environment to grant it to. We cannot reach into your account, which means an incident on our side cannot expose your data.

What the scanner can and cannot do

What it can do

Read resource metadata: instances, volumes, snapshots, addresses, load balancers and their tags
Read cost and usage data for the accounts you connect
Write its own findings to its own database in your account
Run on a schedule you configure

What it cannot do

Delete, stop, resize or modify any resource — remediation is a recommendation, never an action
Read object contents, database rows, or anything stored inside your resources
Create, alter or escalate IAM permissions
Reach any account you have not explicitly connected

The deployment template requests read-only permissions. You can review the exact policy in the template before you deploy it, and scope it further to specific accounts, regions or organizational units.

You install it. We never touch it.

Cloud-Vex is delivered as an infrastructure template through your cloud marketplace. You review the template, deploy it into an account you choose, and create the first administrator during setup. From then on the instance is yours: you control who can log in, whether authentication is local or through your identity provider, how long findings are retained, and when to apply updates.

Because there is no shared infrastructure, one customer's deployment cannot affect another's. There is no multi-tenant database to isolate, no noisy-neighbour risk, and no blast radius beyond your own account.

Certifications, stated plainly

Cloud-Vex is an early-stage product from a small company. We would rather tell you exactly what we do and do not hold than let a badge wall imply otherwise.

SOC 2 Type II — not held

We have not completed an audit. For most buyers the relevant question is narrower than it looks: a SOC 2 report describes controls over data a vendor holds, and we hold none of your cloud data.

ISO 27001 — not held

Not certified.

GDPR and data residency — applies

Your data stays in the region you deploy into and never transits our systems, so residency is determined entirely by your own deployment choice. We are not a processor of your resource or cost data.

Restricted-egress environments — applies

Because the application runs entirely inside your account, it can operate in environments with tightly restricted egress. The version check can be disabled; licence validation still needs to reach us, and tolerates seven days without a connection.

Who else is involved

No third party processes your cloud data, because your cloud data does not reach us. The services below support the company itself, and only ever handle information you send us directly.

Service Purpose Data involved
Cloud marketplace Purchasing and billing Subscription and billing records held by your provider
Email provider All mail, in and out Messages you send to support, and anything we send you — licence keys, subscription notices, waitlist confirmations. Any address we write to passes through it.
Website hosting This site Standard web request logs

Found something?

Report a vulnerability

Send details to support@cloud-vex.com. We acknowledge reports within two business days and will keep you updated until the issue is resolved. We will not pursue legal action against researchers who report in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosing it.

Security questionnaires and architecture review requests go to the same address.

Last updated 12 August 2026  ·  Cloud-Vex LLC, Ohio, USA