Skip to content

Microsoft Fabric · Vendor attestation

Our Microsoft Fabric workload vendor attestation.

Section III of CloudMonitor's vendor self-attestation, published for customer reference under the Microsoft Fabric publishing requirements.

We, the vendor, Data-Driven AI, attest that this checklist records the current conformance and evidence status for the requirements outlined in the Microsoft Fabric Extensibility Toolkit, specifically the Publish Workload Requirements.

This page is Section III of our vendor self-attestation. It is the portion published for customer reference. The full attestation (Sections I–III) is provided to Microsoft. We will notify Microsoft promptly before any change that materially impacts this attestation regarding security, compliance, privacy, or a significant variance from the design / UX guidelines.

CloudMonitor can be hosted by us in our Microsoft Fabric tenancy, or deployed into a Fabric workspace on your own capacity. This attestation records the Fabric workload as distributed through the Workload Hub. Where a requirement turns on where the software runs, it describes the hosted arrangement.

Items marked In progress identify requirements where evidence or remediation remains outstanding.

Read our Privacy Policy, Terms & Conditions, and information security commitments.

Workload name
DataDrivenAI.CloudMonitor
Item type
DataDrivenAI.CloudMonitor.CloudMonitorApp
Workload version
1.0.0
Release date
23 June 2026
Publisher
Data-Driven AI
Distribution
Microsoft Fabric Workload Hub (cross-tenant)
Last updated
25 August 2026

Section III · 1

Business requirements

Value to customers

Attested

CloudMonitor is an Azure FinOps workload built on Microsoft Fabric. It reads FOCUS-formatted Azure billing exports and presents cost, allocation, budget, and optimization analysis.

  • Explore costs by subscription, resource group, resource, and CloudMonitor cost group.
  • Review estimated savings opportunities such as rightsizing, commitments, idle resources, and storage.
  • Track allocation, budgets, and audit history.

Published case studies report a 46% Azure spend reduction for Clinic to Cloud, a up to 32% reduction for one XContent customer, and a 22% data-lake OpEx reduction for Transport for NSW.

Trial

Attested
  • Selected: Yes
  • Not selected: No

CloudMonitor provides a trial experience that demonstrates the Fabric workload capability. A fully-functional, interactive immersive demo with realistic customer data is also available publicly without sign-in or provisioning.

Monetization

Attested

The workload is available on Microsoft Marketplace for customers to procure, with or without a trial, in accordance with the monetization guidelines.

  • Selected: Yes
  • Not selected: No

Customers purchase CloudMonitor through Microsoft Marketplace. After purchase, Marketplace redirects the buyer to CloudMonitor’s activation page. The buyer reviews the subscription, provides setup details, and selects Confirm and activate. CloudMonitor then activates the Marketplace subscription and starts or queues provisioning of the dedicated Fabric environment.

Section III · 2

Technical requirements

Microsoft Entra access

Attested

The workload uses Microsoft Entra authentication and authorization.

  • Selected: No other authentication and authorization mechanisms are used.
  • Not selected: Different authentication and authorization mechanisms are used for stored data in Fabric.

OneLake

Attested
  • Selected: All data and metadata is stored in OneLake or Fabric Data Stores.
  • Not selected: Not all data and metadata is stored in OneLake or Fabric Data Stores.

Microsoft Entra Conditional Access

Attested

CloudMonitor supports Microsoft Entra Conditional Access policies during Microsoft Entra ID provisioning.

Admin REST API

Attested
  • Not selected: Microsoft Fabric Admin APIs are being used (/admin/*).
  • Selected: No Microsoft Fabric Admin APIs are being used.

Customer-facing monitoring and diagnostic

Attested
  • Selected: Minimum 30-day retention requirement is adhered to.

B2B

Attested
  • Not selected: Cross-tenant B2B collaboration supported.
  • Selected: Workload item access only within the tenant.

Workload items are scoped to the customer’s Fabric tenant. Cross-tenant item sharing is not supported.

Business continuity and disaster recovery (BCDR)

Attested

Data-Driven AI maintains documented procedures for service incidents and unplanned outages affecting the hosted SaaS. For a material incident, we assess impact, restore service using documented recovery procedures, and communicate relevant status to affected customers. We review these procedures periodically. RPO/RTO are not published.

Performance

Attested
  • Selected: Performance tracking is not available to end users; vendor support monitors, tests, and tracks performance through internal instrumentation and monitoring systems.

CloudMonitor uses standard operational metrics, Fabric capacity monitoring, error handling, and alerting. Support personnel investigate performance and availability issues using this instrumentation. Capacity and supporting services are scaled in response to observed load and operational demand. Customer-facing performance metrics are not provided in this release.

Presence

Attested
  • Selected: Service availability and colocation/alignment in supported Fabric regions is confirmed.

During onboarding, each customer chooses the Azure and Microsoft Fabric region for their deployment. CloudMonitor deploys a dedicated customer shard in that region. The CloudMonitor app is a Fabric App item and Fabric Apps are still in preview, so the choice is limited to the regions in Microsoft’s Fabric region availability table.

Public APIs

Attested
  • Selected: The workload uses Fabric Public APIs.

Section III · 3

Design / UX requirements

Common UX

Attested

CloudMonitor uses Fabric UX System patterns. No variance or exception is requested.

Item creation experience

Attested
  • Selected: Yes
  • Not selected: No

The product manifest uses createItemDialogConfig and Fabric’s default naming experience.

Monitoring Hub — long-running operations

Not in this release

Read-only reporting with no user-initiated long-running jobs; data ingestion runs as a backend pipeline, not as a Fabric job surfaced to the user.

Trial experience

Attested
  • Selected: Trial Supported
  • Not selected: Trial Not Supported

The trial demonstrates the Fabric workload capability. We also provide a realistic immersive demo that needs no sign-in or provisioning.

Monetization experience

Attested
  • Selected: The monetization experience is integrated with Microsoft Marketplace and compliant with the guidelines.
  • Not selected: Bring Your Own License (BYOL)
  • Not selected: Free or Freemium
  • Not selected: Other

Accessibility

In progress

CloudMonitor targets WCAG 2.1 AA conformance. A formal accessibility assessment is in progress.

World readiness / internationalization

Attested
  • Not selected: English is the only supported language.
  • Selected: The following languages are supported: English, Spanish, Dutch, French.

Item settings

Not in this release

CloudMonitor is a read-only experience; no item settings panel is implemented.

Samples

Attested
  • Not selected: Samples not provided
  • Selected: Samples for preconfiguration of items provided

Preconfigured sample items are provided.

Custom actions

Not in this release

No custom item actions in this release.

Workspace settings

Not in this release

Not supported in this release.

Global search

Not in this release

Not supported in this release.

Section III · 4

Security and compliance requirements

General security

Attested

Protecting your data and metadata is paramount. CloudMonitor operates an ISO/IEC 27001-certified Information Security Management System, with security reviews and assessments performed periodically. Azure resource and billing access is scoped. Billing-account roles are read-only; the subscription fallback uses Cost Management Contributor for cost data. Data is encrypted in transit and at rest. ISO audit report issued 7 January 2026 (certification body Equal Assurance); available on request. See the Information Trust Center.

Privacy

Attested
  • Selected: Publisher attests that only essential HTTP-only cookies are used by the workload and only after positively authenticating the user.
  • Selected: Publisher attests that the workload does not use or rely on third-party cookies.
  • Selected: Publisher attests that any Microsoft Entra token is obtained using the JavaScript APIs provided by the Fabric Workload Client SDK.

The reviewed released application code does not set cookies. Browser-based authentication (MSAL) is used only in standalone sessions outside Microsoft Fabric. Fabric-hosted sessions never initialise it. Where MSAL is used, it is configured with storeAuthStateInCookie set to false and holds authentication state in browser storage. In Fabric-hosted sessions, Microsoft Entra tokens are obtained exclusively using the JavaScript APIs provided by the Fabric Workload Client SDK. There is no fallback path: a host relay failure surfaces as an error rather than falling back to browser-based authentication. Tokens are held in memory for the session and are not written to cookies or persistent browser storage. Browser storage is also used for user preferences. See the Privacy Policy.

Data residency

Attested

During onboarding, each customer chooses the Azure and Microsoft Fabric region for their deployment, from the regions where Fabric Apps are available (see Microsoft’s Fabric region availability table). CloudMonitor deploys a dedicated customer shard in that region and processes customer cost data and derived outputs there. The central management plane operates in Australia East; identity, Marketplace, website, support, and provider records follow separate boundaries.

Compliance

Attested

CloudMonitor aligns to the following certifications and standards:

  • ISO/IEC 27001: Information Security Management
  • ISO 9001: Quality Management
  • ISO/IEC 42001: AI Management System (Certificate of Verification)
  • FinOps Certified Specialty Solution (FinOps Foundation)
  • Microsoft Solutions Partner with Certified Software for Azure
  • Microsoft Fabric Featured Partner

Certification body: Equal Assurance. Certificate numbers available on request.

Section III · 5

Support

Live site

Attested

Microsoft can contact Data-Driven AI at support@cloudmonitor.ai. Customers can open CloudMonitor Support to raise a ticket.

Supportability

Attested
  • Selected: Support information is published to the marketplace offering and available to users via the workload.

Service Health and Availability

Attested

Service health, availability, and uptime are published on our live status dashboard at https://status.cloudmonitor.ai/.

Section III · 6

Fabric features

CloudMonitor is a read-only cost-visibility and Fabric-monitoring workload. The lifecycle and authoring features below are not applicable in this release.

Application lifecycle management (ALM)

Not in this release

Application Life Cycle Management (ALM) is not supported in this release. CloudMonitor is a read-only cost-visibility and Fabric-monitoring workload with no user-authored item definitions to deploy, so deployment pipelines and Git integration do not apply.

CI/CD

Not in this release

Not supported in this release; no CI/CD manifest section.

Item definition portability

Not in this release

Items cannot be restored with their definition in other workspaces.

Private Links

Not in this release

Not supported in this release.

Data Hub

Not in this release

Not supported in this release (not a Data item in this release).

Data lineage

Not in this release

Not supported in this release.

Sensitivity labels

Not in this release

Not supported in this release.

Need to brief your security team?

We provide NDAs, security questionnaires, and our ISO certification details on request.

Live chat didn’t load

This browser blocked our chat widget, so the support button can’t open. A privacy shield or content blocker is the usual cause.

  1. Click the Brave Shields icon (the lion) beside the address bar.
  2. Turn Shields off for cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.
  1. Open your content blocker or privacy extension.
  2. Allow cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.

Rather leave the blocker on? Send us a message or search the help desk.

Live demo Open in new tab