The nine steps of a scan, and the exact API each one calls.
A scan is nine steps, and all nine are reads. The diagram names the exact API called in each cloud at each step, so the access you grant can be checked against it line by line rather than taken on trust.
Read-only, and provable. No step in the cycle writes. Cloud-Vex asks for zero write access, which is why nothing it finds is ever remediated automatically — every recommendation carries an estimated saving and a reversibility note, and you act on it.
Nothing external starts a scan. The scheduler lives in your account and fires on its own timer, in each cloud independently. There is no inbound trigger to expose.
No static keys. Collectors open the connection outbound and authenticate with short-lived credentials — IAM Roles Anywhere or OIDC, Entra workload identity federation, Google Workload Identity Federation. There is no long-lived secret to leak or rotate.
Effective cost, not list price. Enterprise discounts, savings plans, reserved instances and committed use discounts all mean list price isn't what you pay, so the billing APIs are read and the real rates amortized across their terms.
The scan path never leaves your boundary. All nine steps run on your own infrastructure. The vendor entitlement check is a separate call the hub makes on its own — see the architecture diagram for where it sits, and the compliance page for the full list of permissions requested.
Need this reviewed against your own security policy? Email support@cloud-vex.com.
Join the waitlist