Read-only analysis
SpendLens uses least-privilege read-only cloud access for connected AWS accounts and optional fallback billing-file analysis. We do not request write permissions and do not modify infrastructure.
Vendor review
This page summarizes SpendLens controls for early enterprise reviews. It is designed to answer common vendor-security questions without overstating the current compliance posture.
SpendLens uses least-privilege read-only cloud access for connected AWS accounts and optional fallback billing-file analysis. We do not request write permissions and do not modify infrastructure.
Cost calculations and findings are deterministic. AI is limited to explanation and summarization, not calculation.
Customers should connect only authorized cloud accounts and avoid secrets, keys, passwords, or customer records in cloud resource metadata, tags, or optional uploaded files.
Traffic is protected by HTTPS/TLS. Stored data relies on provider-managed encryption at rest in Supabase and hosting infrastructure.
Administrative access is limited to operational need and follows least-privilege principles.
Paid report and opportunity history follows plan retention settings, with authenticated cleanup for expired analyses, findings, verification records, and private PDF exports. Users may delete account data from Settings.
Security issues are triaged, investigated, remediated, and communicated to affected customers when legally or contractually required.
SOC 2 and deeper enterprise controls are roadmap items. We do not claim certifications that are not yet complete.
Controls and roadmap.
Provider and data-purpose list.
Processing terms and request path.