Read-only, cost-scoped access
Every connector uses read-only credentials scoped to billing and usage data. CostMon reads invoices and cost reports, never your workloads, source code, or production systems.
Security
Connecting billing credentials is the biggest ask CostMon makes of you. Access is read-only and cost-scoped, credentials never leave the server, and every organization is strictly isolated from every other.
Trust, by design
This section covers how access is scoped, credentials are stored, and every organization stays isolated from every other.
Every connector uses read-only credentials scoped to billing and usage data. CostMon reads invoices and cost reports, never your workloads, source code, or production systems.
Stored connector credentials are never serialized back to your browser or into any API response. Only whether a credential is set gets exposed. Update a connector without re-entering it and the secret stays as it was.
We request the narrowest scope each provider offers: AWS Cost Explorer read access, Anthropic's Admin cost report. Nothing more.
Every read and write is scoped to your organization. A request for another org's data returns 404. CostMon won't even confirm that org exists, let alone what it spends.
Sign-in runs entirely on AWS Cognito. CostMon never stores or sees a password. Every plan gives your team admin and viewer roles on the same identity layer.
We aggregate cost numbers, not customer PII or workloads. Disconnect a provider and its historical cost rows detach from the credential rather than staying tied to it.
Scope of access
Connectors are scoped to billing and usage APIs only. Below is the exact line between what that access covers and what it doesn't.
This page describes the model in general terms. For the literal policy JSON and form fields behind each connector, see the connector docs.
FAQ
What CostMon can see, what it can't, and what happens to your credentials.
No. Connectors are scoped to billing and usage APIs only. CostMon reads invoices and cost reports. It has no access to your source code, application data, or production systems.
Credentials are stored server-side and never serialized back to your browser or into any API response. The API only reports whether a credential is set. Editing a connector without resupplying the credential keeps the one already stored.
No. Every read and write is scoped to your organization. A request for another org's data returns a 404, so CostMon won't even confirm that org exists, let alone reveal what it spends.
No. Authentication runs entirely on AWS Cognito. CostMon never stores or sees a password. Every plan gives your team admin and viewer roles on the same identity layer.
The connector and its credential are removed immediately. Historical cost rows it produced detach from the connector rather than being deleted or staying tied to a live credential.
Not yet. CostMon is pre-launch. SOC 2 Type II, configurable data-retention controls, and audit logs are on our roadmap; we'll update this page the moment any of them ship rather than claim them early.
CostMon charges a flat rate, not a cut of what you spend or save. Access is read-only, so nothing you connect can be changed from our side.