Security & Trust

Built for read-only cloud savings execution with least-privilege principles

SpendLens helps engineering and finance teams detect, assign, verify, and report cloud savings opportunities. Customer cloud data is processed securely, used only for the requested workflow, and never used to modify your cloud infrastructure.

Data protection

Encryption

Billing data is transmitted over TLS and encrypted at rest using industry-standard algorithms provided by our infrastructure providers.

Read-only cloud access

SpendLens uses least-privilege read-only cloud access for connected AWS accounts. It does not request write permissions and does not modify infrastructure.

Secure data handling

Connected account metadata, savings opportunities, verification records, and optional fallback billing files are processed only for the requested product workflow. Paid report history stores summaries and findings for the configured retention window, with cleanup support for expired report records and private PDF exports.

Access controls

Internal access to customer data follows least-privilege principles, with authentication required for any administrative operation.

AI processing transparency

SpendLens uses deterministic rules for calculations and findings. AI is used only to explain and summarize those findings, with minimized context shared when AI wording is requested.

Responsible disclosure

Found a security issue? Please report it privately to security@rajdharma.co.in. We acknowledge reports promptly and work to remediate confirmed issues quickly.

Operational controls

Data minimization

Connect only cloud accounts you are authorized to review. Do not store passwords, private keys, customer records, or secrets in cloud tags, names, or optional uploaded files. SpendLens does not need cloud account write access.

Data residency

SpendLens is operated by Rajdharma Technologies Pvt. Ltd. and currently uses managed cloud subprocessors including AWS/EC2, Vercel, Supabase, Paddle, Google Analytics, and optional AI providers. Enterprise customers with jurisdiction-specific residency requirements should request current hosting region details before onboarding.

See our subprocessor summary.

Incident response

We triage security reports, investigate confirmed issues, remediate affected systems, and notify impacted customers when legally or contractually required.

Compliance roadmap

We are honest about where we are today. The items below reflect our current posture, not certification claims.

  • SOC 2Roadmap; not certified
  • DPA / subprocessorsPublished summary; full terms on request
  • SSO / SAMLAvailable on request
  • Audit loggingRoadmap
  • Enterprise governance featuresRoadmap

Security review pack

Vendor reviewers can start with the Security & Compliance Pack, Subprocessors, and DPA. For security questions or to report a vulnerability, email security@rajdharma.co.in.

For general privacy questions see our Privacy Policy.