So the first thing worth saying is this: you don't have to give us access at all. Two of the three ways we run an audit involve no credentials of any kind. Everything below is written into the engagement contract, not just onto this page.
Three ways to run it
Findings are fastest at level three, but level one still surfaces most of the money. Plenty of organisations start at level one and never move — that's a perfectly good outcome.
We tell you exactly which built-in reports to export — the AWS Cost and Usage Report, an Azure Cost Management export, Microsoft 365 usage reports, your Snowflake or Datadog usage summary. You generate them, you review them, you send them. We never touch your systems and hold no credentials.
Most common choice · no accessYour engineer drives, we watch and ask questions. We walk the consoles together in a scheduled session. Nothing leaves your environment, nothing is recorded unless you record it, and your person sees everything we see.
Nothing leaves your networkYou create a scoped role with the exact policy we send you in advance, valid for the engagement only. You can revoke it at any moment, and every action we take is in your own audit log.
Fastest · deepest findingsIf you choose level three
Named policies, sent before you create anything. No custom permissions, no wildcards, nothing that can change state.
ReadOnlyAccess policy plus Cost Explorer and CUR read. No s3:GetObject on your data buckets, which is excluded explicitlyReader and Cost Management Reader at the scope you nominate, and no higherroles/viewer plus roles/billing.viewerData handling
Cost audits read billing records, resource inventory, configuration and usage telemetry. They do not require the contents of your databases, object storage, documents or message logs, and we structure access so we couldn't read them if we wanted to.
Exports you send are held in an encrypted, access-controlled workspace in an Australian region, and they stay there. No copy is transferred, replicated or processed offshore, whoever is working on the engagement. Nothing goes into a shared drive, a public AI tool, or a third-party analytics platform.
Working data is destroyed within 30 days of delivering the report, or immediately on your request. You get written confirmation of deletion. Only the report itself is retained, and only because you may need it later.
Your data is not sold, licensed, shared with any third party, pooled into a benchmarking product, or used to train any model. There is no version of this business where your spend data becomes an asset on our balance sheet.
The people working on your engagement are named in the agreement, wherever they are based. Adding anyone requires your written consent first — that's a clause, not a courtesy. What never moves is the data: it stays in Australia regardless of who is working on it.
No reseller agreements, referral fees or vendor sponsorship. Nobody pays us to recommend a product, and the contract says so. It's the only reason an independent report is worth anything.
Commitments
Stated plainly so you can hold us to them, and written into the engagement terms so you can enforce them.
Paperwork
Fair questions
You get a written deletion certificate, and the contract gives you a right to audit. More usefully: at level one there is nothing of yours on our side beyond the reports you chose to send, and at level two there is nothing at all.
Hardware-backed MFA on every account, full-disk encryption, a password manager with unique credentials, patched and current OS, no shared accounts, and no client data on mobile devices. We hold ourselves to the same Essential Eight baseline we assess others against — it would be difficult to argue otherwise.
Yes, and it's a standard option — that's level two. Your engineer drives the session and sees every screen we do. At level three, everything lands in your own audit log in real time and you can review the whole engagement afterwards.
Then your material service provider obligations apply and you'll need specific contract terms around information security, notification and assurance. Send us your standard clauses; we'd rather work inside your framework than propose our own.
It goes in the report, privately, to you. Findings are not shared, published or referenced anywhere. If we find an active security problem while doing cost work, we'll tell you immediately rather than save it for the deliverable — and we won't quote you for fixing it in the same breath.
A fair question, and worth answering plainly rather than waving away. Engagements run two weeks, deliverables are documents rather than ongoing services, and nothing we do sits in the critical path of your operations. If an engagement is delayed, access is revoked and you've lost time, not capability — which is a very different risk profile to a managed service.
Next step
Plenty of people do, and it's a perfectly reasonable way to open. We'd rather clear the trust question before we discuss what an audit would find.
Start a conversation