ISO 27001 + ISO 9001 + ISO 42001
Independently certified to ISO 27001, ISO 9001, and ISO 42001.
CloudMonitor is certified by an accredited third-party auditor. Certificates are current and renewed annually.
Active certifications
What we're certified for, and what it covers.
ISO/IEC 27001:2022
Information Security Management System
ISO 9001:2015
Quality Management System
Annual surveillance
Audited yearly by accredited party
Statement of Applicability
Available on request
ISO/IEC 27001:2022
Information Security Management.
ISO 27001 is the international standard for information security management. It defines the requirements for an ISMS — a systematic approach to managing sensitive information so that it remains secure.
CloudMonitor's ISO 27001 certification covers the design, development, operation, and support of the CloudMonitor FinOps platform — including the FinOps reports, admin app, Teams bot, and supporting infrastructure.
- Annex A controls implemented and assured
- Annual Stage 2 audits since 2023
- Statement of Applicability available under NDA
- Continuous improvement of the ISMS
ISO 9001:2015
Quality Management.
ISO 9001 is the international standard for quality management. It demonstrates that CloudMonitor consistently meets customer requirements through process control, continuous improvement, and customer-focused operations.
In practice, this means our release management, support, and customer success processes are externally audited and held to international standards.
- Customer satisfaction tracked and reported
- Non-conformity management and root-cause analysis
- Process maps and SLAs available on request
FAQ
Trust & security questions
Do we host any infrastructure in our Azure tenancy?
Next to nothing. CloudMonitor's platform runs entirely in our Microsoft Fabric tenancy — no Fabric capacity for you to license, no Hubs deployment, no compute or managed app in your tenant. The only Azure resource you create is one storage account that receives your scheduled cost exports; CloudMonitor reads it in place and needs nothing else. The annual license covers the Fabric capacity we run for you, and your team just gets a hosted SaaS URL and a Fabric app.
Does CloudMonitor follow least-privilege access?
Yes. Every permission CloudMonitor asks for is the minimal access needed to read your cost and usage data — read-only wherever Azure allows, scoped to the subscriptions and billing scope you choose. The only write or management access anywhere in setup is a single, tightly scoped role on the storage account that receives your cost exports, used only to create and run that export. Full detail is in the access guide.
Where is our data stored?
CloudMonitor is a hosted SaaS platform running in our Microsoft Fabric tenancy. Your billing data stays in the storage account you own. CloudMonitor reads it in place through a OneLake shortcut, read-only, and never makes a second copy. The CloudMonitor environment that reads it and serves your reports runs in the data residency region you choose at sign-up — encrypted in transit and at rest. Every customer gets a dedicated Microsoft Fabric workspace, so your data lives in its own isolated workspace and is never co-mingled with another customer's. CloudMonitor staff access is restricted, audited, and gated by least-privilege controls, and only your authorized users see your reports.
How does our Azure billing data reach CloudMonitor?
You configure a FOCUS cost export to an Azure Storage account in your tenant and grant CloudMonitor scoped read-only access to it. CloudMonitor ingests that export into your dedicated Microsoft Fabric workspace, where it becomes your reports. Only billing and resource metadata moves — never the data inside your resources. See the Information Trust Center for the full data-flow detail.
How is our data isolated inside Microsoft Fabric and OneLake?
Every customer gets a dedicated Microsoft Fabric workspace, and your data lives in that workspace's own OneLake storage. The workspace is the isolation boundary, so your data is never co-mingled with another customer's. The CloudMonitor application is scoped to your workspace and has no path to read across workspaces. Authentication and authorization are handled entirely by native Microsoft Entra ID and Fabric workspace roles; we have not built a custom identity or permissions layer on top, so access is governed by the same Microsoft security model that protects the rest of your Azure estate. Only the Entra users you authorize can reach your data. See the Information Trust Center for the full posture.
Can CloudMonitor see our application data?
No. CloudMonitor reads only billing metadata and resource-level metadata (IDs, types, SKUs, tags). It has no access to data inside your resources.
What level of Azure access do you need?
Read-only, scoped to your billing data. You can limit it to specific subscriptions and revoke it from the Azure portal at any time. CloudMonitor has no write access to your workloads or the data inside your services. The one exception is a tightly scoped management role on the single storage account that receives your cost exports, used only to set up that export. Nothing else in your environment is writable by CloudMonitor.
CloudMonitor says it's read-only — why does it need a write role on the storage account?
CloudMonitor's access to your cost and usage data is read-only. The one management role it needs — on the single storage account that receives your cost exports — exists only so CloudMonitor can create and run the scheduled Azure Cost Management export that lands your billing data there. Azure requires write access on the destination account to set up an export; it gives CloudMonitor no access to your other resources or to the data inside your services, and reading the exported files back uses a separate read-only role. See the access guide.
Does CloudMonitor need any Microsoft Entra directory or Graph permissions?
No. Authorizing CloudMonitor provisions our application in your Microsoft Entra tenant, but it requests no directory or Microsoft Graph permissions — so consenting grants no access on its own. All of CloudMonitor's access comes from the read-only Azure role assignments you make, scoped to the subscriptions and billing data you choose. See the access guide.
Do we share a client secret or storage access keys with CloudMonitor?
No. CloudMonitor connects through a multi-tenant service principal that we provide and you authorize — you don't create or hand over a client secret, and no storage account access keys are shared. CloudMonitor authenticates to your storage and the Azure APIs over Microsoft Entra ID using the read-only role assignments you grant, which you can revoke at any time.
Does the cost-export storage account cost us anything?
Very little. CloudMonitor's cost exports are small files and Azure Data Lake storage is inexpensive, but they accumulate over time. You can cap the cost by applying an Azure Blob Storage lifecycle-management policy that automatically deletes exports older than a retention window you choose — keeping enough history for the trends you rely on. It's the only Azure resource you create for CloudMonitor.
Can we audit what CloudMonitor reads?
Yes — Azure Activity Log shows every read against your subscriptions. The reads originate from CloudMonitor's authorized identity and are logged like any other Azure action.
Are you ISO certified?
Yes — ISO/IEC 27001:2022 (Information Security), ISO 9001:2015 (Quality Management), and ISO/IEC 42001 (AI Management). Certificates available under NDA — see the certification statement.
Can we get a SOC 2 report?
CloudMonitor is ISO/IEC 27001 certified, which covers the same controls. We can share the certificate and a Stage 2 audit summary under NDA — request the Security Pack. See the full ISO 27001 + 9001 certification statement for scope, certifying body, and audit cadence.
How do you govern the AI and agentic features?
CloudMonitor operates a certified AI management system under ISO/IEC 42001 — covering AI risk assessment, transparency, human oversight, and lifecycle controls. Every agentic FinOps action runs against scoped permissions, an approval workflow, and a reversible audit trail.
How do you handle a breach?
CloudMonitor maintains an incident response plan aligned to ISO 27001 Annex A.16. Because CloudMonitor only ever holds billing and resource metadata — never the data inside your resources — a breach of CloudMonitor systems would not expose your application data. We notify affected customers within 24 hours of confirming any incident with potential impact.
Can we run a penetration test?
Yes — coordinate via Customer Success. We support customer-initiated pen tests against the CloudMonitor app and admin app surfaces.
Is CloudMonitor certified by Microsoft?
Yes — CloudMonitor is a Microsoft Solutions Partner with certified software for Azure. The designation confirms the platform has been technically reviewed for interoperability with Microsoft Azure and validated against Microsoft Marketplace customer-success criteria. Procurement teams can reference the Microsoft Learn overview of the designation and the Information Trust Center for the full certification stack (ISO 27001, ISO 9001, ISO 42001, FinOps Specialty Solution, and Microsoft Solutions Partner).
What happens to our data if we cancel?
When you cancel, revoke CloudMonitor's access from your Azure portal and request data deletion. We delete your data within 30 days; nothing is retained beyond contractual backup windows.
How do we get a copy of the certificate?
Certificates are available for download on request. Open a ticket via the Support Helpdesk and we'll send the current certificates within one business hour.
How often are you audited?
Annual surveillance audits, with full re-certification every 3 years. Our most recent surveillance was in February 2026.
How is each customer's data kept isolated?
Every customer gets a dedicated Microsoft Fabric workspace, and their data lives in that workspace's own OneLake storage — the workspace is the isolation boundary, so no two customers' data is ever co-mingled. As a partner you get a portfolio view across your book of business, but each of your customers only ever sees their own data. Full posture is on the Information Trust Center.
Need to brief your security team?
We provide NDAs, security questionnaires, and our ISO certification details on request.