Trust & security

You should not hand your environment to a stranger.

So the first thing worth saying is this: you don't have to give us access at all. Two of the three ways we run an audit involve no credentials of any kind. Everything below is written into the engagement contract, not just onto this page.

Three ways to run it

You choose the access level. Not us.

Findings are fastest at level three, but level one still surfaces most of the money. Plenty of organisations start at level one and never move — that's a perfectly good outcome.

1

You send standard reports

We tell you exactly which built-in reports to export — the AWS Cost and Usage Report, an Azure Cost Management export, Microsoft 365 usage reports, your Snowflake or Datadog usage summary. You generate them, you review them, you send them. We never touch your systems and hold no credentials.

Most common choice · no access
2

Screen-share session

Your engineer drives, we watch and ask questions. We walk the consoles together in a scheduled session. Nothing leaves your environment, nothing is recorded unless you record it, and your person sees everything we see.

Nothing leaves your network
3

Time-limited read-only role

You create a scoped role with the exact policy we send you in advance, valid for the engagement only. You can revoke it at any moment, and every action we take is in your own audit log.

Fastest · deepest findings

If you choose level three

Exactly what the role can do

Named policies, sent before you create anything. No custom permissions, no wildcards, nothing that can change state.

Data handling

What happens to what we see

Metadata, not your data

Cost audits read billing records, resource inventory, configuration and usage telemetry. They do not require the contents of your databases, object storage, documents or message logs, and we structure access so we couldn't read them if we wanted to.

Your data never leaves Australia

Exports you send are held in an encrypted, access-controlled workspace in an Australian region, and they stay there. No copy is transferred, replicated or processed offshore, whoever is working on the engagement. Nothing goes into a shared drive, a public AI tool, or a third-party analytics platform.

Deleted on a fixed schedule

Working data is destroyed within 30 days of delivering the report, or immediately on your request. You get written confirmation of deletion. Only the report itself is retained, and only because you may need it later.

Never sold, shared or aggregated

Your data is not sold, licensed, shared with any third party, pooled into a benchmarking product, or used to train any model. There is no version of this business where your spend data becomes an asset on our balance sheet.

Named people, disclosed team

The people working on your engagement are named in the agreement, wherever they are based. Adding anyone requires your written consent first — that's a clause, not a courtesy. What never moves is the data: it stays in Australia regardless of who is working on it.

No commercial interest in the outcome

No reseller agreements, referral fees or vendor sponsorship. Nobody pays us to recommend a product, and the contract says so. It's the only reason an independent report is worth anything.

Commitments

Things that will never happen

Stated plainly so you can hold us to them, and written into the engagement terms so you can enforce them.

NeverWrite, deploy or delete permissions during an assessment. Not once, not briefly, not to save time.
NeverAccess to production data contents — customer records, documents, email, message history.
NeverYour data pasted into a public AI tool or any third-party service outside the agreed workspace.
NeverYour data stored, replicated or processed outside Australia — residency is a contractual term, not a preference.
NeverYour name used as a reference, case study or logo without written permission, obtained separately.
NeverA commission, kickback or referral fee attached to anything we recommend you buy.
NeverWork started before an NDA is signed, if you want one — and most people should.

Paperwork

What's in the contract before anyone touches anything

Fair questions

The ones a good CISO asks

How do we know you'll actually delete our data?

You get a written deletion certificate, and the contract gives you a right to audit. More usefully: at level one there is nothing of yours on our side beyond the reports you chose to send, and at level two there is nothing at all.

What's your own security posture?

Hardware-backed MFA on every account, full-disk encryption, a password manager with unique credentials, patched and current OS, no shared accounts, and no client data on mobile devices. We hold ourselves to the same Essential Eight baseline we assess others against — it would be difficult to argue otherwise.

Can we watch what you're doing?

Yes, and it's a standard option — that's level two. Your engineer drives the session and sees every screen we do. At level three, everything lands in your own audit log in real time and you can review the whole engagement afterwards.

We're in financial services and APRA CPS 234 applies to us.

Then your material service provider obligations apply and you'll need specific contract terms around information security, notification and assurance. Send us your standard clauses; we'd rather work inside your framework than propose our own.

What if you find something embarrassing?

It goes in the report, privately, to you. Findings are not shared, published or referenced anywhere. If we find an active security problem while doing cost work, we'll tell you immediately rather than save it for the deliverable — and we won't quote you for fixing it in the same breath.

You're a small firm. What happens if your engineer is unavailable?

A fair question, and worth answering plainly rather than waving away. Engagements run two weeks, deliverables are documents rather than ongoing services, and nothing we do sits in the critical path of your operations. If an engagement is delayed, access is revoked and you've lost time, not capability — which is a very different risk profile to a managed service.

Next step

Send your security questionnaire first.

Plenty of people do, and it's a perfectly reasonable way to open. We'd rather clear the trust question before we discuss what an audit would find.

Start a conversation