Skip to content
StrinoSoftStrinoSoft
Security

Our security approach

These are the principles that guide how we design and operate our products, particularly GetInfraDesk's access to your AWS environment.

Least-privilege access

Our products and services request only the permissions required to perform their function, and no more.

Customer-controlled AWS roles

Access to your AWS account is granted through a role you control, secured with an External ID that you can revoke at any time.

Read-only analysis where applicable

GetInfraDesk performs read-only analysis of your AWS environment. It does not require write access to identify findings.

Evidence before action

Every finding is presented with supporting evidence, so decisions are grounded in facts about your environment.

Human approval before remediation

No cleanup action is taken automatically. A person on your team must explicitly review and approve any change.

No hidden infrastructure changes

We do not make undisclosed changes to your infrastructure. Every recommended action is visible before it happens.

Audit and ownership context

Findings include ownership and tagging context, so the right person can review and act with full information.

Secure handling of customer data

Customer data is handled with care, using access controls appropriate to the sensitivity of the information involved.

Responsible disclosure

If you believe you have found a security vulnerability in any StrinoSoft product or service, please report it to us at support@getinfradesk.com. Please include enough detail for us to reproduce and assess the issue. We ask that you avoid accessing or modifying data that does not belong to you, and give us reasonable time to investigate and respond before any public disclosure.