Skip to content

Information Trust Center

Review CloudMonitor's security evidence and data controls.

Follow how Azure cost data enters CloudMonitor, what access we request, where processing runs, and which assurance documents are available. Last reviewed September 4, 2026.

Assurance evidence

Start with the document your reviewer needs.

Public statements cover the scope and status of our controls. Current certificates and supporting audit material are available through the Security Pack under NDA.

ISO assurance

CloudMonitor is certified to ISO/IEC 27001 and ISO 9001. Equal Assurance has issued an ISO/IEC 42001 Certificate of Verification.

Fabric workload attestation

Our published vendor self-attestation addresses the security, privacy, compliance, support, and design requirements in the Microsoft Fabric publishing template. It is a vendor statement, not Microsoft validation.

Customer Security Pack

Request current certificates, available audit material, questionnaire support, and deployment-specific retention and deletion terms.

Data security

Your raw export stays in your storage account.

Azure Cost Management writes your raw FOCUS export to a storage account you own, and it stays there. CloudMonitor reads it through a OneLake shortcut and does the ingest, cleansing and modeling in our own Fabric tenancy, in the Azure and Microsoft Fabric region you choose during onboarding. That much is the same in both arrangements. Where the finished data comes to rest is what your choice settles: in your own Fabric tenant we write the modeled cost tables into a lakehouse in your workspace, on your capacity, and deploy the semantic model and the CloudMonitor app there on top of them. Under CloudMonitor-hosted, those stay in the workspace we run for you inside our tenancy.

Swipe the diagram to follow the full data flow.

How your Azure cost data reaches a CloudMonitor workspace in your own tenant Your Azure Cost Management writes a scheduled FOCUS export into a storage account in a resource group you own, inside your own Azure tenancy. CloudMonitor's shared processing engine, in our tenancy and in the Azure and Microsoft Fabric region you choose during onboarding, reads that export through a OneLake shortcut and cleanses it, holding the raw and cleansed data in a workspace we operate. It then writes the finished, modeled cost tables across the tenancy boundary into a Microsoft Fabric workspace on your own capacity. That workspace holds the modeled data, the semantic model, the CloudMonitor app and Ask Finn, so your people sign in with their own accounts in your own tenant rather than as guests in ours. CloudMonitor keeps a scoped admin role on that one workspace to deploy the solution, update it, support it, and check your license. YOUR AZURE TENANCY Azure Cost Management scheduled FOCUS export CLOUDMONITOR RESOURCE GROUP Storage account ADLS Gen2 · exports landing zone raw FOCUS export remains here Scoped service principal least-privilege roles OneLake shortcut least-privilege access OUR AZURE TENANCY CloudMonitor · in the region you choose Shared processing engine pipelines & notebooks · holds no cost data YOUR DATA, IN A WORKSPACE WE RUN Raw as exported Cleansed typed & deduplicated cleansing and enrichment run here modeled cost tables written into your lakehouse deploy · update · support · license YOUR AZURE TENANCY Your Fabric workspace · your capacity Modeled cost data Delta tables in your OneLake your data lives here Semantic model Direct Lake your team can build on it too CloudMonitor app reports, governance & settings your people sign in here Workspace access CloudMonitor app as Admin on this one workspace Ask Finn · role-gated agent licensed organization admins · verified support · Support mode your people sign in with their own accounts — no guest access to our tenant YOUR PEOPLE IT / FinOps team monitor & optimize Business unit owners cost accountability Licensed org admins Ask Finn investigations
In your own Fabric tenant. Azure Cost Management writes the raw FOCUS export to your storage account. CloudMonitor reads it through a OneLake shortcut and cleanses it in our tenancy, then writes the modeled cost tables into a Fabric workspace on your own capacity — where the semantic model, the CloudMonitor app and Ask Finn run, and your people sign in with their own accounts.
How your Azure cost data reaches CloudMonitor Your Azure Cost Management writes a scheduled FOCUS export into a storage account in a resource group you own, inside your own Azure tenancy. CloudMonitor's managed SaaS on Microsoft Fabric processes that cost data in our tenancy, in the Azure and Microsoft Fabric region you choose during onboarding, using scoped, least-privilege access, then serves the CloudMonitor apps and Ask Finn. The apps use the governed cost model for role-based reports. Ask Finn uses organization-wide governed cost data and is limited to active, licensed organization administrators and verified support staff using Support mode. YOUR AZURE TENANCY Azure Cost Management scheduled FOCUS export CLOUDMONITOR RESOURCE GROUP Storage account ADLS Gen2 · hierarchical namespace exports landing zone raw FOCUS export remains here Scoped service principal least-privilege roles Scoped connection least-privilege access OUR AZURE TENANCY CloudMonitor · in the region you choose Microsoft Fabric dedicated customer environment processes your cost data CloudMonitor apps reports, governance & recommendations Ask Finn · role-gated agent licensed organization admins verified support · Support mode YOUR PEOPLE IT / FinOps team monitor & optimize Business unit owners cost accountability Licensed org admins Ask Finn investigations
CloudMonitor-hosted. Azure Cost Management writes the raw FOCUS export to your storage account. CloudMonitor processes the cost data in our Microsoft Fabric tenancy using scoped, least-privilege access. The CloudMonitor apps and Ask Finn read the same governed cost model, each through its own role gate.

What CloudMonitor processes

CloudMonitor processes the FOCUS billing export and related resource metadata, including subscription, resource group, resource and meter names, tags, quantities, and costs.

It also processes account profile fields and tenant identifiers. Service configuration includes cost groups, tag mappings, budgets, alert rules, and audit history. When enabled, connected features add Fabric-capacity or AI-usage metrics. Customer-defined names and tags may contain personal or confidential information.

What the product does not inspect

CloudMonitor reads the dedicated cost-export files. It does not use workload agents or inspect secrets, customer workload configuration files, VM contents, database records, unrelated storage objects, or application traffic.

Removing CloudMonitor's Azure roles stops future access. It does not delete the raw export or transformed models and reports already processed. Raw FOCUS files remain in customer-owned storage until the customer removes them or applies a lifecycle policy.

Identity and access

Azure permissions are scoped to selected billing, resource, and export-storage paths.

In both arrangements, the current Marketplace and Fabric SaaS architecture uses a customer-authorized service principal for background ingestion, and interactive sign-in uses Microsoft Entra ID.

Billing and resource metadata

Reader covers resource metadata. At billing-account scope, MCA uses Billing account reader and EA uses EnrollmentReader. When billing-account access is unavailable, CloudMonitor uses Cost Management Contributor at the selected subscription scope as a cost-data fallback. Unlike the billing-account roles, this fallback is a contributor role.

Dedicated export storage

Storage Account Contributor creates and runs the export on one dedicated account. Storage Blob Data Reader reads the exported files. The management role can list account keys; a narrower custom role can omit that permission.

Interactive identity

The app requests delegated User.Read for the signed-in user's own profile, not directory-wide access. Background cost ingestion uses Azure RBAC and does not use Microsoft Graph. In your own Fabric tenant, your people sign in with their own accounts in your Microsoft Entra directory; under CloudMonitor-hosted, we invite each of your users into our tenant as a B2B guest.

Residency and providers

Regional cost processing and provider boundaries are not the same.

The region you choose for cost processing does not automatically apply to identity, support, security, AI-assisted analysis, or website services.

Customer cost processing: you choose the region.

CloudMonitor's ingest, cleansing and modeling run in the Azure and Microsoft Fabric region you choose during onboarding, in a dedicated environment we deploy for you there rather than in a single home region of ours. That holds in both arrangements, so choosing CloudMonitor-hosted does not move your cost processing to another region. Our shared management plane is separate and runs in Australia East.

The CloudMonitor app is a Microsoft Fabric App item, and Fabric Apps are still in preview and not offered in every region. Microsoft lists the current set in its Fabric region availability table. We confirm which regions are available with you at onboarding.

In your own Fabric tenant, the modeled cost tables and the reports built on them rest on your own capacity, in the region you set for that capacity. Under CloudMonitor-hosted, they rest in the Fabric workspace we run for you, in the processing region you chose.

Other services have separate location boundaries.

These services do not all process the same data. A provider's legal role depends on the activity; not every listed provider is a subprocessor of customer application data.

The service-provider register records each provider's purpose, data categories, and location boundary. The privacy policy explains how CloudMonitor handles personal information.

Operational controls

Marketplace controls cover delivery, monitoring, and recovery.

These controls are vendor-attested in CloudMonitor's current Microsoft Marketplace compliance submission. They are not a SOC 2 report or a claim of annual penetration testing.

Secure delivery

CloudMonitor risk-ranks vulnerabilities, scans the app and supporting infrastructure each quarter, and tracks patches against documented targets. A second person reviews and approves production code changes.

Monitoring and recovery

Security events generate alerts for employee triage. CloudMonitor maintains documented incident response and disaster recovery plans, including a backup and restore strategy. RPO and RTO targets are not published.

Retention and deletion

The current Marketplace submission records less than 30 days after account termination for user data in that submission. It is not a blanket period for cost models, reports, configuration, audit records, backups, or support records.

FAQ

Trust and security questions

Can we audit what CloudMonitor reads?

Azure Activity Log records control-plane management operations against your subscriptions, but not reads of blob contents. To audit storage data-plane access, enable Azure Storage resource logs through diagnostic settings. Route those logs to a destination you retain. Storage resource logs are not collected until that setting exists. See Microsoft's guidance on the Azure Activity Log and auditing Blob Storage activity.

How do you handle a breach?

CloudMonitor maintains a documented incident response plan. Its systems process cost-management metadata, account profile data, service configuration, and connected-service usage metrics. Where Finn is used, they also process the submitted question, relevant cost context, generated answer, and associated audit data. CloudMonitor investigates suspected incidents and sends notices within the time required by applicable law and contract. It notifies affected customers, individuals, and authorities as required. Where CloudMonitor acts as a processor, it notifies and assists the relevant customer.

Can we run a penetration test?

Yes — coordinate via Customer Success. We support customer-initiated penetration tests against the CloudMonitor app and admin app surfaces, subject to an agreed scope, schedule, and rules of engagement.

How often are you audited?

ISO/IEC 27001 and ISO 9001 follow annual surveillance and three-year recertification cycles. CloudMonitor holds ISO/IEC 42001 as a Certificate of Verification. Request the current certificates and audit status through the Security Pack.

Give your security team the current evidence.

Request certificates, available audit material, questionnaire support, and deployment-specific terms under NDA.

Live chat didn’t load

This browser blocked our chat widget, so the support button can’t open. A privacy shield or content blocker is the usual cause.

  1. Click the Brave Shields icon (the lion) beside the address bar.
  2. Turn Shields off for cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.
  1. Open your content blocker or privacy extension.
  2. Allow cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.

Rather leave the blocker on? Send us a message or search the help desk.

Live demo Open in new tab