Our security approach
These are the principles that guide how we design and operate our products, particularly GetInfraDesk's access to your AWS environment.
Least-privilege access
Our products and services request only the permissions required to perform their function, and no more.
Customer-controlled AWS roles
Access to your AWS account is granted through a role you control, secured with an External ID that you can revoke at any time.
Read-only analysis where applicable
GetInfraDesk performs read-only analysis of your AWS environment. It does not require write access to identify findings.
Evidence before action
Every finding is presented with supporting evidence, so decisions are grounded in facts about your environment.
Human approval before remediation
No cleanup action is taken automatically. A person on your team must explicitly review and approve any change.
No hidden infrastructure changes
We do not make undisclosed changes to your infrastructure. Every recommended action is visible before it happens.
Audit and ownership context
Findings include ownership and tagging context, so the right person can review and act with full information.
Secure handling of customer data
Customer data is handled with care, using access controls appropriate to the sensitivity of the information involved.
Responsible disclosure
If you believe you have found a security vulnerability in any StrinoSoft product or service, please report it to us at support@getinfradesk.com. Please include enough detail for us to reproduce and assess the issue. We ask that you avoid accessing or modifying data that does not belong to you, and give us reasonable time to investigate and respond before any public disclosure.
