Your cost data, handled with care

FINSIMUL is built around a simple principle: we ask for the least access we need, we never change anything in your accounts, and we keep your data isolated and encrypted.

Confirm before publishing. The platform safeguards below reflect the current build. Certification claims (SOC 2, ISO 27001) and published retention defaults must be confirmed by Chris before this page goes public.

Read-only access

FINSIMUL connects to your cloud billing exports using least-privilege, read-only access. For AWS this is a cross-account IAM role you create and control, scoped to billing and usage data — we cannot create, modify or delete resources in your accounts.

Encryption in transit & at rest

All connections to FINSIMUL use TLS. Data is encrypted at rest in our hosting environment. The customer portal is served over HTTPS only, with HSTS enforced.

Strict tenant isolation

Every customer's data is logically isolated. Access is enforced at the database layer with row-level security so that one customer can never see another's data — isolation does not depend on application code alone.

Secrets, not keys in files

Credentials and connection secrets are held in a managed secrets store and referenced at runtime — never hard-coded and never committed to source control.

Authentication

Portal sign-in uses Google OAuth via the secure server-side authorization-code flow. Access is limited to users your organisation has authorised, and sessions use secure, HTTP-only cookies.

Audit logging

Changes to managed data are recorded in an append-only audit log capturing who did what and when, supporting accountability and investigation.

Questions from your security team?

We're happy to walk through our controls and data handling. Reach out and we'll help your review.

Contact Us