CostMonStart free

Security

Built to be trusted with your bills

Connecting billing credentials is the biggest ask CostMon makes of you. Access is read-only and cost-scoped, credentials never leave the server, and every organization is strictly isolated from every other.

Trust, by design

Scoped, stored, and isolated on purpose

Here's exactly how access is scoped, credentials are stored, and every organization stays isolated from every other.

Read-only, cost-scoped access

Every connector uses read-only credentials scoped to billing and usage data. CostMon reads invoices and cost reports — never your workloads, source code, or production systems.

Credentials never leave the server

Stored connector credentials are never serialized back to your browser or into any API response — only whether a credential is set. Update a connector without re-entering it and the secret stays exactly as it was.

Least privilege by design

We request the narrowest scope each provider offers — AWS Cost Explorer read access, Anthropic's Admin cost report — and nothing more.

Strict per-organization isolation

Every read and write is scoped to your organization. A request for another org's data returns 404 — CostMon won't even confirm that org exists, let alone what it spends.

Modern, delegated identity

Sign-in runs entirely on AWS Cognito. CostMon never stores or sees a password. Enterprise adds SSO and role-based access control on top of the same identity layer.

Your data stays yours

We aggregate cost numbers, not customer PII or workloads. Disconnect a provider and its historical cost rows detach from the credential rather than staying tied to it.

Scope of access

What CostMon reads vs. what it can never reach

Connectors are scoped to billing and usage APIs only — here's the exact line between what that access covers and what it doesn't.

What CostMon reads

  • Invoices, line items, and usage totals from each connected provider
  • Cost by service, project, tag, and time period, as reported by that provider's billing API
  • Currency and billing metadata needed to normalize costs into one view

What it can never reach

  • Your source code, repositories, or build systems
  • Application data, databases, or customer records
  • Production infrastructure, servers, or the ability to change anything
  • Your password — sign-in runs entirely through AWS Cognito

FAQ

Security questions, answered

What CostMon can see, what it can't, and what happens to your credentials.

Can CostMon see my source code or data?

No. Connectors are scoped to billing and usage APIs only. CostMon reads invoices and cost reports — it has no access to your source code, application data, or production systems.

What happens to my connector credentials?

Credentials are stored server-side and never serialized back to your browser or into any API response — the API only ever reports whether a credential is set. Editing a connector without resupplying the credential keeps the one already stored.

Can another customer see my spend?

No. Every read and write is scoped to your organization. A request for another org's data returns a 404, so CostMon won't even confirm that org exists — let alone reveal what it spends.

Do you store my password?

No. Authentication runs entirely on AWS Cognito. CostMon never stores or sees a password, and Enterprise adds SSO and role-based access control on the same identity layer.

What happens when I disconnect a provider?

The connector and its credential are removed immediately. Historical cost rows it produced detach from the connector rather than being deleted or staying tied to a live credential.

Is CostMon SOC 2 certified?

Not yet — CostMon is pre-launch. SOC 2 Type II, configurable data-retention controls, and audit logs are on our roadmap; we'll update this page the moment any of them ship rather than claim them early.

See what your stack really costs.

Connect your first providers in minutes and give finance and engineering one number they both trust. Flat pricing — never a percentage of your bill or your savings.

Esc