Skip to content

Security & data

Data residency, the access model, and certifications. For the longer answers, see what data CloudMonitor can see and security and data isolation.

Does CloudMonitor follow least-privilege access?

Yes. Every permission CloudMonitor asks for is the minimal access needed to read your cost and usage data — read-only wherever Azure allows, scoped to the subscriptions and billing scope you choose. The only write or management access anywhere in setup is a single, tightly scoped role on the storage account that receives your cost exports, used only to create and run that export. Full detail is in the access guide.

Where is our data stored?

Azure Cost Management writes your raw FOCUS export to a storage account you own, and it stays there. CloudMonitor's ingest, cleansing and modeling run in the Azure and Microsoft Fabric region you choose during onboarding, in a dedicated environment we deploy for you there rather than in a single home region of ours. That holds in both arrangements, so choosing CloudMonitor-hosted does not move your cost processing to another region. Our shared management plane is separate and runs in Australia East.

The CloudMonitor app is a Microsoft Fabric App item, and Fabric Apps are still in preview and not offered in every region. Microsoft lists the current set in its Fabric region availability table. We confirm which regions are available with you at onboarding.

Where the finished data comes to rest is what your choice settles: in your own Fabric tenant we write the modeled cost tables into a lakehouse in your workspace, on your capacity, and deploy the semantic model and the CloudMonitor app there on top of them. Under CloudMonitor-hosted, those stay in the workspace we run for you inside our tenancy.

Your own capacity's region is yours to set and does not have to match the region your cost processing runs in. We recommend matching them, so the modeled cost tables are not written across regions.

See the current service-provider register for management-plane and supporting-service locations. Architecture and data flow sets out where each layer runs in both arrangements.

How does our Azure billing data reach CloudMonitor?

Set up a FOCUS cost export to an Azure Storage account in your tenant, then grant CloudMonitor the required scoped roles. Raw source files stay in that account. Billing and resource metadata access is read-only. One management role is limited to the export account so CloudMonitor can create and run the scheduled export. CloudMonitor reads it through a OneLake shortcut and does the ingest, cleansing and modeling in our own Fabric tenancy, in the Azure and Microsoft Fabric region you choose during onboarding. That much is the same in both arrangements. Where the finished data comes to rest is what your choice settles: in your own Fabric tenant we write the modeled cost tables into a lakehouse in your workspace, on your capacity, and deploy the semantic model and the CloudMonitor app there on top of them. Under CloudMonitor-hosted, those stay in the workspace we run for you inside our tenancy. CloudMonitor cannot read content inside your resources. See the Information Trust Center for the full data-flow detail. Architecture and data flow sets out where each layer runs in both arrangements.

How is our data isolated inside Microsoft Fabric and OneLake?

Where the finished data comes to rest is what your choice settles: in your own Fabric tenant we write the modeled cost tables into a lakehouse in your workspace, on your capacity, and deploy the semantic model and the CloudMonitor app there on top of them. Under CloudMonitor-hosted, those stay in the workspace we run for you inside our tenancy. Either way the workspace is the isolation boundary, so customer reporting environments are not co-mingled, and the raw FOCUS source files remain in customer-owned Azure Storage.

CloudMonitor holds a scoped workspace role in both arrangements so we can deploy, update and support the app. In your own Fabric tenant that role covers only the workspace you granted it on. It carries no visibility of any other workspace in your tenant and no rights over your Entra directory.

Authentication and authorization are handled entirely by native Microsoft Entra ID and Fabric workspace roles in both arrangements; we have not built a custom identity or permissions layer on top, so access is governed by the same Microsoft security model that protects the rest of your Azure estate. In your own Fabric tenant, your people sign in with their own accounts in your tenant, and your Entra directory and workspace permissions decide who can open cost data, so you can show an auditor exactly who can. Under CloudMonitor-hosted, we invite each of your users into our tenant as a B2B guest, and the workspace permissions that govern sharing sit with us. See the Information Trust Center for the full posture. Architecture and data flow sets out where each layer runs in both arrangements.

Can CloudMonitor see our application data?

No. CloudMonitor processes billing and resource metadata, its own setup data, and account profile fields used for sign-in. If you connect Fabric or AI features, it also processes Fabric capacity or AI token usage metrics. It cannot read secrets or content inside your VMs, databases, storage objects, or other workloads.

What level of Azure access do you need?

Least-privilege access scoped to the subscriptions and billing data you choose. Billing and resource metadata access is read-only, and you can revoke every role from the Azure portal. The one management-role exception is limited to the single storage account that receives your cost exports and is used only to create and run that export. CloudMonitor has no write access to your workloads or the data inside your services.

Why does CloudMonitor need a write role on the storage account if cost access is read-only?

CloudMonitor's access to your cost and usage data is read-only. The one management role is limited to the storage account that receives your cost exports. CloudMonitor uses it only to create and run the scheduled Azure Cost Management export. Azure requires write access on the destination account to set up the export. That role cannot access your other resources or workload data. CloudMonitor reads the exported files with a separate read-only role. See the access guide.

Which Microsoft Graph permission does CloudMonitor use?

The Marketplace SaaS app uses delegated User.Read during interactive sign-in to retrieve the signed-in user's own basic profile. It is not an application permission and does not provide directory-wide access to other users, mail, files, groups, or workload content. Background ingestion runs app-only and uses CloudMonitor's service principal with scoped Azure RBAC; it does not use Graph for cost ingestion.

Do we share a client secret or storage access keys with CloudMonitor?

No. CloudMonitor connects through a multi-tenant service principal that we provide and you authorize — you don't create or hand over a client secret, and no storage account access keys are shared. CloudMonitor authenticates to your storage and the Azure APIs over Microsoft Entra ID using the scoped Azure role assignments you grant, which you can revoke at any time.

Does the cost-export storage account cost us anything?

Very little. CloudMonitor's cost exports are small files and Azure Data Lake storage is inexpensive, but they accumulate over time. You can cap the cost by applying an Azure Blob Storage lifecycle-management policy that automatically deletes exports older than a retention window you choose — keeping enough history for the trends you rely on. In your own Fabric tenant you also provide the Fabric capacity your reports run on; under CloudMonitor-hosted, the export account is the only Azure resource you create for CloudMonitor.

Can we audit what CloudMonitor reads?

Azure Activity Log records control-plane management operations against your subscriptions, but not reads of blob contents. To audit storage data-plane access, enable Azure Storage resource logs through diagnostic settings. Route those logs to a destination you retain. Storage resource logs are not collected until that setting exists. See Microsoft's guidance on the Azure Activity Log and auditing Blob Storage activity.

Are you ISO certified?

CloudMonitor is certified to ISO/IEC 27001:2022 (Information Security) and ISO 9001:2015 (Quality Management). It holds an ISO/IEC 42001 Certificate of Verification from Equal Assurance. Current assurance documents are available under NDA through the Security Pack; see the certification statement for scope and audit cadence.

Can we get a SOC 2 report?

CloudMonitor does not currently have a SOC 2 report. We can share our current ISO/IEC 27001 certificate and available audit material under NDA through the Security Pack. See the ISO certification statement for scope, certifying body, and audit cadence.

How do you govern the AI and agentic features?

CloudMonitor holds an ISO/IEC 42001 Certificate of Verification from Equal Assurance. Its AI management system covers AI risk assessment, transparency, human oversight, and lifecycle controls. Ask Finn is user-initiated and works with the authorized user's question and relevant CloudMonitor cost context; see the Information Trust Center for data-handling details.

Which operational security controls protect CloudMonitor?

CloudMonitor supports TLS 1.2 or later, scans the app and supporting infrastructure for vulnerabilities each quarter, risk-ranks findings, and applies patches against documented targets. A second person reviews production code changes, secure coding practices cover the OWASP Top 10, and MFA protects code repositories, DNS management, and credential stores. System events are logged and reviewed, with security alerts routed for employee triage.

Does CloudMonitor have disaster recovery and incident response plans?

Yes. CloudMonitor maintains documented disaster recovery, backup and restore, and security incident response processes. The current Microsoft Marketplace compliance submission records these controls as vendor-attested. RPO and RTO targets are not published.

How do you handle a breach?

CloudMonitor maintains a documented incident response plan. Its systems process cost-management metadata, account profile data, service configuration, and connected-service usage metrics. Where Finn is used, they also process the submitted question, relevant cost context, generated answer, and associated audit data. CloudMonitor investigates suspected incidents and sends notices within the time required by applicable law and contract. It notifies affected customers, individuals, and authorities as required. Where CloudMonitor acts as a processor, it notifies and assists the relevant customer.

Can we run a penetration test?

Yes — coordinate via Customer Success. We support customer-initiated penetration tests against the CloudMonitor app and admin app surfaces, subject to an agreed scope, schedule, and rules of engagement.

Is CloudMonitor certified by Microsoft?

Yes — CloudMonitor is a Microsoft Solutions Partner with certified software for Azure. The designation confirms the platform has been technically reviewed for interoperability with Microsoft Azure and validated against Microsoft Marketplace customer-success criteria. Procurement teams can reference the Microsoft Learn overview of the designation and the Information Trust Center for CloudMonitor's ISO certifications, ISO/IEC 42001 verification, FinOps Specialty Solution, and Microsoft Solutions Partner status.

What happens to our data if we cancel?

Our current Microsoft Marketplace submission records a retention period of less than 30 days for user data after account termination. This statement covers user data within that submission; it is not a blanket retention period for transformed cost models, reports, configuration, audit records, backups, or support records. Ask us through the security contact form for the retention and deletion terms that apply to your deployment. The raw FOCUS export stays in your Azure Storage account until you delete it or apply a lifecycle policy. You can revoke CloudMonitor's Azure access immediately from the Azure portal; revocation stops future access but does not delete exports or derived data already processed.

How do we get a copy of the certificate?

Request the current assurance documents through our security contact form. The security, privacy, or compliance option is selected automatically. We will confirm any NDA or access requirements for the available documents.

How often are you audited?

ISO/IEC 27001 and ISO 9001 follow annual surveillance and three-year recertification cycles. CloudMonitor holds ISO/IEC 42001 as a Certificate of Verification. Request the current certificates and audit status through the Security Pack.

Who sees my cost information?

Only your authorized team and the CloudMonitor onboarding team helping you set up. Staff access is limited and audited, and ongoing support access is used only to respond to a request.

Does CloudMonitor process personal data?

Yes, in a limited way. For authentication and access control, CloudMonitor processes the signed-in user's user principal name, object ID, display name, email address, and tenant ID. The FOCUS export contains billing and resource metadata rather than mail, documents, or workload content. Customer-created resource names and tags may contain personal data if your organization enters it there. See what data CloudMonitor can see for the published cost-dataset schemas.

Live chat didn’t load

This browser blocked our chat widget, so the support button can’t open. A privacy shield or content blocker is the usual cause.

  1. Click the Brave Shields icon (the lion) beside the address bar.
  2. Turn Shields off for cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.
  1. Open your content blocker or privacy extension.
  2. Allow cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.

Rather leave the blocker on? Send us a message or search the help desk.