← All notesCloud security
cloud-security

What a read-only review can and cannot see

The first question we get is what we are allowed to touch. The answer is nothing. A review runs on read-only access, and that is deliberate.

What read-only shows

Billing and usage data, resource configuration, access policies, network layout and retention settings. That is enough to price every idle resource, spot over-broad permissions and see where data is exposed.

What it does not show

Anything inside your data. We do not read database contents, object payloads or application logs beyond their volume and retention. If a finding needs that context, we ask you to check it rather than granting us more access.

Why the limit helps both sides

A review that cannot change anything cannot break anything, so it clears security approval quickly. It also keeps the output honest: every recommendation has to stand on evidence you can verify yourself.

You get a costed action plan and a risk list. Your team keeps the keys.

Written by
Cost Beacon
Aaditya Parashar
Co-founder

Aaditya works on cloud cost and platform engineering at Cost Beacon, mostly on AWS and Kubernetes estates that grew faster than anyone planned for.