mission-finops --trust

Trust & Enterprise Readiness

Understand exactly how Mission FinOps accesses, processes, and protects customer data. The default operating model is local-first, read-only, and customer-controlled.

controls --summary

Control summary

default-controls ACTIVE
AWS access

Read-only. Published IAM policy.

execution

Customer-controlled execution supported and preferred.

billing-data upload

Not required.

SaaS ingestion

None.

telemetry

None.

write actions

None.

source visibility

Open-source tooling. Inspectable before execution.

credentials stored

No. Customer-managed credentials only.

engagement --model

How an engagement works

I do not require customers to forward their AWS billing estate into a Mission FinOps SaaS platform. Investigation tooling can execute within the customer's controlled environment using approved read-only permissions.

  CUSTOMER CONTROL BOUNDARY
  ──────────────────────────────────────────────
  AWS Billing / CUR / CE / Resource Metadata
                    │
                    ▼
          Kulshan / Read-only queries
                    │
                    ▼
           Evidence / Findings
  ──────────────────────────────────────────────
                    │
                    │ selected findings /
                    │ customer-approved output
                    ▼
            Mission FinOps report

  No mandatory raw billing-data upload.

Customers choose the operating model appropriate to their security requirements:

customer-operated

Customer runs Kulshan and provides selected outputs. Mission FinOps never touches the AWS environment.

supervised investigation

Mission FinOps works in a customer-provided workstation, VDI, or account with approved read-only access.

export-based

Customer provides specific billing exports or reports. No AWS access granted to Mission FinOps.

access --policy

AWS access

Mission FinOps does not require AWS write permissions for a standard Cost Investigation. The published IAM policy contains read-style actions only.

no IAM administration

No IAM policy changes. No role creation.

no credential persistence

Temporary, customer-managed credentials preferred.

customer-restrictable

Customers may further restrict the published policy to the agreed investigation scope.

The full IAM policy is published, SHA256-attested, and downloadable.

data --handling

Data handling

Data I may process

billing

AWS billing and cost records, CUR line items, Cost Explorer outputs.

resource

Resource identifiers, account metadata, tags, usage information.

context

Architecture context supplied by the customer during the engagement.

Data I do not require

credentials

Customer passwords or long-lived access keys.

production data

Database contents, application payloads, end-user PII.

source code

Customer source-code repositories.

write access

Write access to production resources.

Where data goes

The default architecture does not require customer AWS billing data to be copied into Mission FinOps infrastructure. Customer data does not cross a new SaaS boundary. Your billing data stays under your control.

data --retention

Retention

Customer evidence remains in the customer environment whenever practical. Any customer-supplied working files retained by Mission FinOps are limited to the engagement scope and deleted according to the agreed retention period.

Specific retention terms are documented in the engagement scope confirmation before work begins.

ai --policy

AI and model use

deterministic analysis

Cost calculations, evidence extraction, reconciliation, and variance identification are performed by deterministic code. The model never decides the number.

AI-assisted analysis

Where AI assists investigation, customer-controlled model execution is supported. Customer data does not need to be submitted to a third-party model provider.

model training

Customer data is never used for model training.

human review

All findings require human review before delivery.

kulshan --trust

Software supply chain

You do not have to trust a black-box agent with unrestricted cloud access. The core investigation tooling and permissions are inspectable before execution.

license

Apache 2.0

IAM policy

Published, SHA256-attested, downloadable JSON.

telemetry

None. No phone-home. No usage tracking.

design

Read-only by construction. No write path exists.

access --human

Human access

personnel

Named personnel only. Currently the founder.

privilege

Least privilege. Customer-approved access scope.

identity

Customer-controlled identity where possible. MFA required.

duration

Access removed at engagement conclusion.

subcontractors

No access extended to any third party without explicit customer approval.

vendor --readiness

Enterprise documents

Available during vendor review:

Available now

IAM policy

Published at /policy/ with SHA256 hash and downloadable JSON.

source code

Open-source at github.com/MissionFinOps/kulshan.

data-flow diagram

Shown above. Available as a standalone document on request.

security architecture

Engagement-specific architecture and data-flow documentation available during review.

Available during contracting

NDA

Mutual NDA available.

data handling statement

Engagement-specific data handling and retention terms.

corporate documentation

Canadian corporate documentation and W-8BEN-E where required.

security questionnaires

Completed on request.

contact --security

Security contact

Security or vulnerability disclosure: [email protected]

Enterprise review or procurement questions: [email protected]

Controls described here are the default Mission FinOps operating model. Engagement-specific requirements are documented and agreed before access to customer data or systems.

Last updated: August 2026