Skip to content

Information Trust Center

Your data stays in the region you choose.

Certifications, data residency, sub-processors, audit reports, and security contacts, reviewed every quarter.

ISO/IEC 27001 — Equal Assurance

ISO/IEC 27001

Information security

ISO 9001 — Equal Assurance

ISO 9001

Quality management

ISO/IEC 42001 — Equal Assurance

ISO/IEC 42001

AI management system

FinOps Certified Specialty Solution

FinOps Certified

Specialty Solution

Microsoft Solutions Partner

Certified software · Azure

Certifications & frameworks

Three ISO certifications, independently audited.

CloudMonitor holds ISO/IEC 27001, ISO 9001, and ISO/IEC 42001 (AI Management System) certifications, belongs to the FinOps Foundation, and is a Microsoft Solutions Partner with certified software for Azure.

Microsoft Solutions Partner with certified software for Azure — CloudMonitor Cost Analytics — FinOps Platform (FOCUS V1.0)

Microsoft reviews CloudMonitor's interoperability with Azure and the FOCUS billing schema against its Marketplace customer-success criteria. Read Microsoft's overview →

Data handling

CloudMonitor reads your data where it lives.

CloudMonitor is a hosted SaaS platform. Your billing data stays in the storage account you own, in the region you choose. CloudMonitor reads it there in place and never makes a second copy, keeping each customer's data isolated.

CloudMonitor follows the principle of least privilege: it asks only for the minimal access needed to read your cost and usage data, and nothing more. It stays read-only wherever Azure allows: no access to your workloads or the data inside your services, and no ability to change your configuration. The one exception is a single, tightly scoped management role on the storage account that receives your cost exports, used only to set up the export itself. You can revoke all of it from the Azure portal at any time.

  • Least-privilege access: only the roles needed to read your data
  • Read-only wherever Azure allows
  • No access to your workloads or in-service data
  • Encrypted in transit and at rest
  • Every read logged in your Azure Activity Log
  • Revocable from the Azure portal
How CloudMonitor ingests your Azure cost and usage data

Sub-processors

A named, audited list of sub-processors.

CloudMonitor uses audited sub-processors for hosting, security, source control, and authentication. The main ones are listed below; we keep the full, current list in the security pack and review it each quarter.

None of these sub-processors receive your billing or telemetry data. Your billing data never leaves the storage account you own, and the reports CloudMonitor builds stay isolated to you, in your chosen region.

  • Microsoft Azure (hosting CloudMonitor management plane)
  • Cloudflare (security and content delivery)
  • GitHub (source control)
  • Microsoft Entra ID (auth)

Data residency

Choose your data residency at sign-up.

At sign-up, you choose your data region: Australia, EU, US, or any other supported Azure region. CloudMonitor reads your billing data and keeps every report it builds inside that region. Your data never leaves it.

We run CloudMonitor's control plane from Australia East. Your billing data stays only in the region you chose.

FAQ

Trust & security questions

Do we host any infrastructure in our Azure tenancy?

Next to nothing. CloudMonitor's platform runs entirely in our Microsoft Fabric tenancy — no Fabric capacity for you to license, no Hubs deployment, no compute or managed app in your tenant. The only Azure resource you create is one storage account that receives your scheduled cost exports; CloudMonitor reads it in place and needs nothing else. The annual license covers the Fabric capacity we run for you, and your team just gets a hosted SaaS URL and a Fabric app.

Does CloudMonitor follow least-privilege access?

Yes. Every permission CloudMonitor asks for is the minimal access needed to read your cost and usage data — read-only wherever Azure allows, scoped to the subscriptions and billing scope you choose. The only write or management access anywhere in setup is a single, tightly scoped role on the storage account that receives your cost exports, used only to create and run that export. Full detail is in the access guide.

Where is our data stored?

CloudMonitor is a hosted SaaS platform running in our Microsoft Fabric tenancy. Your billing data stays in the storage account you own. CloudMonitor reads it in place through a OneLake shortcut, read-only, and never makes a second copy. The CloudMonitor environment that reads it and serves your reports runs in the data residency region you choose at sign-up — encrypted in transit and at rest. Every customer gets a dedicated Microsoft Fabric workspace, so your data lives in its own isolated workspace and is never co-mingled with another customer's. CloudMonitor staff access is restricted, audited, and gated by least-privilege controls, and only your authorized users see your reports.

How does our Azure billing data reach CloudMonitor?

You configure a FOCUS cost export to an Azure Storage account in your tenant and grant CloudMonitor scoped read-only access to it. CloudMonitor ingests that export into your dedicated Microsoft Fabric workspace, where it becomes your reports. Only billing and resource metadata moves — never the data inside your resources. See the Information Trust Center for the full data-flow detail.

How is our data isolated inside Microsoft Fabric and OneLake?

Every customer gets a dedicated Microsoft Fabric workspace, and your data lives in that workspace's own OneLake storage. The workspace is the isolation boundary, so your data is never co-mingled with another customer's. The CloudMonitor application is scoped to your workspace and has no path to read across workspaces. Authentication and authorization are handled entirely by native Microsoft Entra ID and Fabric workspace roles; we have not built a custom identity or permissions layer on top, so access is governed by the same Microsoft security model that protects the rest of your Azure estate. Only the Entra users you authorize can reach your data. See the Information Trust Center for the full posture.

Can CloudMonitor see our application data?

No. CloudMonitor reads only billing metadata and resource-level metadata (IDs, types, SKUs, tags). It has no access to data inside your resources.

What level of Azure access do you need?

Read-only, scoped to your billing data. You can limit it to specific subscriptions and revoke it from the Azure portal at any time. CloudMonitor has no write access to your workloads or the data inside your services. The one exception is a tightly scoped management role on the single storage account that receives your cost exports, used only to set up that export. Nothing else in your environment is writable by CloudMonitor.

CloudMonitor says it's read-only — why does it need a write role on the storage account?

CloudMonitor's access to your cost and usage data is read-only. The one management role it needs — on the single storage account that receives your cost exports — exists only so CloudMonitor can create and run the scheduled Azure Cost Management export that lands your billing data there. Azure requires write access on the destination account to set up an export; it gives CloudMonitor no access to your other resources or to the data inside your services, and reading the exported files back uses a separate read-only role. See the access guide.

Does CloudMonitor need any Microsoft Entra directory or Graph permissions?

No. Authorizing CloudMonitor provisions our application in your Microsoft Entra tenant, but it requests no directory or Microsoft Graph permissions — so consenting grants no access on its own. All of CloudMonitor's access comes from the read-only Azure role assignments you make, scoped to the subscriptions and billing data you choose. See the access guide.

Do we share a client secret or storage access keys with CloudMonitor?

No. CloudMonitor connects through a multi-tenant service principal that we provide and you authorize — you don't create or hand over a client secret, and no storage account access keys are shared. CloudMonitor authenticates to your storage and the Azure APIs over Microsoft Entra ID using the read-only role assignments you grant, which you can revoke at any time.

Does the cost-export storage account cost us anything?

Very little. CloudMonitor's cost exports are small files and Azure Data Lake storage is inexpensive, but they accumulate over time. You can cap the cost by applying an Azure Blob Storage lifecycle-management policy that automatically deletes exports older than a retention window you choose — keeping enough history for the trends you rely on. It's the only Azure resource you create for CloudMonitor.

Can we audit what CloudMonitor reads?

Yes — Azure Activity Log shows every read against your subscriptions. The reads originate from CloudMonitor's authorized identity and are logged like any other Azure action.

Are you ISO certified?

Yes — ISO/IEC 27001:2022 (Information Security), ISO 9001:2015 (Quality Management), and ISO/IEC 42001 (AI Management). Certificates available under NDA — see the certification statement.

Can we get a SOC 2 report?

CloudMonitor is ISO/IEC 27001 certified, which covers the same controls. We can share the certificate and a Stage 2 audit summary under NDA — request the Security Pack. See the full ISO 27001 + 9001 certification statement for scope, certifying body, and audit cadence.

How do you govern the AI and agentic features?

CloudMonitor operates a certified AI management system under ISO/IEC 42001 — covering AI risk assessment, transparency, human oversight, and lifecycle controls. Every agentic FinOps action runs against scoped permissions, an approval workflow, and a reversible audit trail.

How do you handle a breach?

CloudMonitor maintains an incident response plan aligned to ISO 27001 Annex A.16. Because CloudMonitor only ever holds billing and resource metadata — never the data inside your resources — a breach of CloudMonitor systems would not expose your application data. We notify affected customers within 24 hours of confirming any incident with potential impact.

Can we run a penetration test?

Yes — coordinate via Customer Success. We support customer-initiated pen tests against the CloudMonitor app and admin app surfaces.

Is CloudMonitor certified by Microsoft?

Yes — CloudMonitor is a Microsoft Solutions Partner with certified software for Azure. The designation confirms the platform has been technically reviewed for interoperability with Microsoft Azure and validated against Microsoft Marketplace customer-success criteria. Procurement teams can reference the Microsoft Learn overview of the designation and the Information Trust Center for the full certification stack (ISO 27001, ISO 9001, ISO 42001, FinOps Specialty Solution, and Microsoft Solutions Partner).

What happens to our data if we cancel?

When you cancel, revoke CloudMonitor's access from your Azure portal and request data deletion. We delete your data within 30 days; nothing is retained beyond contractual backup windows.

How do we get a copy of the certificate?

Certificates are available for download on request. Open a ticket via the Support Helpdesk and we'll send the current certificates within one business hour.

How often are you audited?

Annual surveillance audits, with full re-certification every 3 years. Our most recent surveillance was in February 2026.

How is each customer's data kept isolated?

Every customer gets a dedicated Microsoft Fabric workspace, and their data lives in that workspace's own OneLake storage — the workspace is the isolation boundary, so no two customers' data is ever co-mingled. As a partner you get a portfolio view across your book of business, but each of your customers only ever sees their own data. Full posture is on the Information Trust Center.

Browse all FAQs →

Need to brief your security team?

We provide NDAs, security questionnaires, and our ISO certification details on request.