Cloud Approver logo
Cloud Approver Cloud architecture, security, and risk guidance
Security

Security and Data Privacy

Cloud Approver is designed to make cloud account review safer to try. The default connection model is read-only, provider-specific, and visible to the customer before setup. Cloud Approver currently supports AWS accounts, Azure subscriptions, and Google Cloud projects using the same basic pattern: customer-approved access, limited scanner behavior, clear evidence, and no default remediation authority.

What customers grant

  • A supported cloud account is connected through a customer-approved provider setup flow.
  • AWS setup uses an AWS Role you can create with CloudFormation.
  • Azure setup uses customer-approved subscription role assignments for read-only review.
  • Google Cloud setup uses project-level IAM bindings for the Cloud Approver scanner service account.
  • Customers can remove access by deleting the provider role, role assignment, or IAM binding they created.

What Cloud Approver does not ask for by default

  • No administrator role.
  • No default permission to change, delete, resize, or remediate resources.
  • No agents installed in customer workloads.
  • No customer cloud access keys entered into Cloud Approver.
  • No default reading of S3 object bodies, database rows, secret values, private keys, or application data.

What data is used

Cloud Approver stores account metadata, connection status, scanner results, inventory records, recommendations, approval records, workload associations, reports, and customer-provided support content. Scanner evidence is intended to focus on metadata and configuration such as regions, tags, encryption state, public exposure, audit logging state, resource size, lifecycle settings, and aggregate metrics.

Transparency

Cloud Approver records scanner API call metadata so customers can understand which read-only provider calls supported a review. The log is designed to store service, action, region, scanner, timing, status, error code, and request ID, not raw response bodies, credentials, secret values, object contents, or database contents.

Demo privacy

The public demo uses masked data. Names, identifiers, inventory values, request details, account IDs, resource IDs, and ARNs are obscured where they can appear while the screens remain representative of the product.

Security review packet

Security teams can review each provider setup before connecting an account. The AWS packet covers the AWS role, CloudFormation resources, external ID, read-only policies, scanner usage, data handling, auditability, and removal path. Azure and Google Cloud packets cover their corresponding customer-approved read-only role assignments and IAM bindings.

Download the AWS security review PDF

Download the Azure security review PDF

Download the Google Cloud security review PDF

Security questions

Signed-in customers can use Support for questions or concerns about permissions, data handling, demo masking, scanner behavior, privacy, or the AWS setup packet. Public visitors can email Cloud Approver before connecting an account.

Email Cloud Approver security questions