Security
Security at Emnode
Emnode handles cost and security data for your entire cloud estate. Read-only by design, UK-hosted, and built around the controls below.
What we access in your cloud
When you connect AWS, you install a read-only IAM role that we assume using a unique External ID. For Azure, you deploy a read-only managed identity. Either way, our access is read-only.
We read
- Cost and usage data
- Security and compliance findings
- Resource metadata for sizing analysis
- Backup metadata
We don't ask for
- Write access of any kind
- Permission to change identities, roles or permissions
- Your application code, databases, or secrets
- Personal data stored inside your cloud services
How we protect it
UK-hosted
All infrastructure runs in AWS London. Customer data is stored in the UK, with backups replicated within the EU, and delivered through Cloudflare with TLS end to end.
Encrypted everywhere
Data is encrypted in transit and at rest. Public access to storage is fully blocked.
Tenant isolation
Every request is tied to your tenant. Data is partitioned per customer and access is checked on every request.
Multi-factor authentication
Password plus a second factor: authenticator apps or passkeys. MFA can be enforced for your whole organization.
Audit logging
User and admin actions are recorded to an in-app audit log that customer admins can review at any time.
Your data, your rules
Revoke access at any time: remove the IAM role or managed identity you granted us, and no new access is possible from that moment. Any session already open expires within the hour on AWS, and within a day on Azure.
GDPR rights: see our Privacy Notice. Registered with the UK Information Commissioner's Office (ZC129144).
Need more detail?
Happy to share documentation, complete security questionnaires, or sign a Data Processing Agreement.