Information Trust Center
Review CloudMonitor's security evidence and data controls.
Follow how Azure cost data enters CloudMonitor, what access we request, where processing runs, and which assurance documents are available. Last reviewed August 24, 2026.
Assurance evidence
Start with the document your reviewer needs.
Public statements cover the scope and status of our controls. Current certificates and supporting audit material are available through the Security Pack under NDA.
ISO assurance
CloudMonitor is certified to ISO/IEC 27001 and ISO 9001. Equal Assurance has issued an ISO/IEC 42001 Certificate of Verification.
Fabric workload attestation
Our published vendor self-attestation addresses the security, privacy, compliance, support, and design requirements in the Microsoft Fabric publishing template. It is a vendor statement, not Microsoft validation.
Customer Security Pack
Request current certificates, available audit material, questionnaire support, and deployment-specific retention and deletion terms.
Data security
Your raw export stays in your storage account.
For the current CloudMonitor Marketplace SaaS offering, Azure Cost Management writes the raw FOCUS export to customer-owned storage. CloudMonitor accesses the export through scoped permissions and a OneLake shortcut. It then creates cost models and reports in a dedicated customer environment within CloudMonitor's Microsoft Fabric tenancy.
Swipe the diagram to follow the full data flow.
What CloudMonitor processes
CloudMonitor processes the FOCUS billing export and related resource metadata, including subscription, resource group, resource and meter names, tags, quantities, and costs.
It also processes account profile fields and tenant identifiers. Service configuration includes cost groups, tag mappings, budgets, alert rules, and audit history. When enabled, connected features add Fabric-capacity or AI-usage metrics. Customer-defined names and tags may contain personal or confidential information.
What the product does not inspect
CloudMonitor reads the dedicated cost-export files. It does not use workload agents or inspect secrets, customer workload configuration files, VM contents, database records, unrelated storage objects, or application traffic.
Removing CloudMonitor's Azure roles stops future access. It does not delete the raw export or transformed models and reports already processed. Raw FOCUS files remain in customer-owned storage until the customer removes them or applies a lifecycle policy.
Identity and access
Azure permissions are scoped to selected billing, resource, and export-storage paths.
The current Marketplace and Fabric SaaS architecture uses a customer-authorized service principal for background ingestion. Interactive sign-in uses Microsoft Entra ID.
Billing and resource metadata
Reader covers resource metadata. At billing-account scope, MCA uses Billing account reader and EA uses EnrollmentReader. When billing-account access is unavailable, CloudMonitor uses Cost Management Contributor at the selected subscription scope as a cost-data fallback. Unlike the billing-account roles, this fallback is a contributor role.
Dedicated export storage
Storage Account Contributor creates and runs the export on one dedicated account. Storage Blob Data Reader reads the exported files. The management role can list account keys; a narrower custom role can omit that permission.
Interactive identity
The app requests delegated User.Read for the signed-in user's own profile, not directory-wide access. Background cost ingestion uses Azure RBAC and does not use Microsoft Graph.
Residency and providers
Regional cost processing and provider boundaries are not the same.
The region selected for the dedicated customer environment does not automatically apply to identity, support, security, AI-assisted analysis, or website services.
Customer cost processing: choose any region worldwide.
You choose any available Azure and Microsoft Fabric region worldwide during onboarding. We deploy a dedicated customer shard in that region. Fabric stores transformed cost models and reports inside the shard.
This regional commitment applies to customer cost processing. CloudMonitor's shared management plane operates in Australia East.
Other services have separate location boundaries.
These services do not all process the same data. A provider's legal role depends on the activity; not every listed provider is a subprocessor of customer application data.
The service-provider register records each provider's purpose, data categories, and location boundary. The privacy policy explains how CloudMonitor handles personal information.
Operational controls
Marketplace controls cover delivery, monitoring, and recovery.
These controls are vendor-attested in CloudMonitor's current Microsoft Marketplace compliance submission. They are not a SOC 2 report or a claim of annual penetration testing.
Secure delivery
CloudMonitor risk-ranks vulnerabilities, scans the app and supporting infrastructure each quarter, and tracks patches against documented targets. A second person reviews and approves production code changes.
Monitoring and recovery
Security events generate alerts for employee triage. CloudMonitor maintains documented incident response and disaster recovery plans, including a backup and restore strategy. RPO and RTO targets are not published.
Retention and deletion
The current Marketplace submission records less than 30 days after account termination for user data in that submission. It is not a blanket period for cost models, reports, configuration, audit records, backups, or support records.
FAQ
Trust and security questions
Can we audit what CloudMonitor reads?
Azure Activity Log records control-plane management operations against your subscriptions, but not reads of blob contents. To audit storage data-plane access, enable Azure Storage resource logs through diagnostic settings. Route those logs to a destination you retain. Storage resource logs are not collected until that setting exists. See Microsoft's guidance on the Azure Activity Log and auditing Blob Storage activity.
How do you handle a breach?
CloudMonitor maintains a documented incident response plan. Its systems process cost-management metadata, account profile data, service configuration, and connected-service usage metrics. Where Finn is used, they also process the submitted question, relevant cost context, generated answer, and associated audit data. CloudMonitor investigates suspected incidents and sends notices within the time required by applicable law and contract. It notifies affected customers, individuals, and authorities as required. Where CloudMonitor acts as a processor, it notifies and assists the relevant customer.
Can we run a penetration test?
Yes — coordinate via Customer Success. We support customer-initiated penetration tests against the CloudMonitor app and admin app surfaces, subject to an agreed scope, schedule, and rules of engagement.
How often are you audited?
ISO/IEC 27001 and ISO 9001 follow annual surveillance and three-year recertification cycles. CloudMonitor holds ISO/IEC 42001 as a Certificate of Verification. Request the current certificates and audit status through the Security Pack.
Give your security team the current evidence.
Request certificates, available audit material, questionnaire support, and deployment-specific terms under NDA.