AWS assessment controls
Security and data handling
The assessment is designed to minimize both access and copied data.
The exact account scope, permissions, optional data sources, retention periods, and processing providers are documented in a countersigned data-handling schedule before access is granted.
Access model
- Access uses a customer-created cross-account IAM role or Identity Center permission set with temporary credentials, a unique external ID, a per-engagement source identity recorded in CloudTrail, an agreed expiration timestamp, and service-specific metadata allowlists approved for the scope.
- The assessment role has no production-change, permission-management, commitment-purchase, or resource-deletion permissions.
- Shared IAM users, long-lived access keys, administrator access, and credentials sent over email or chat are not accepted.
- The client controls the role and may revoke it at any time. Revocation is confirmed in writing after delivery.
- Implementation uses a separate agreement, permission set, and written approval process.
Standard assessment data
The standard assessment uses billing and resource-configuration metadata:
- Cost Explorer, Cost Optimization Hub, Compute Optimizer, Savings Plans, and Reserved Instance information.
- CUR or Data Exports where they already exist, including only the agreed accounts and billing periods.
- Resource inventory and configuration metadata needed to validate cost findings.
- Organization and account structure for the agreed scope.
No application customer data, application secrets, database contents, object contents, or application source code is required.
Optional data sources
Some findings need evidence that billing metadata cannot provide. Each optional source is separately explained and approved. Declining it does not expand any other permission.
- CloudWatch, Container Insights, or existing Kubernetes metrics for requests-versus-usage analysis.
- A read-only Datadog, Grafana, Kubecost, or OpenCost view.
- A client-produced sanitized Bedrock invocation aggregate limited to model identifiers, timestamps, token counts, latency, and cache usage. Direct access to raw invocation logs is not requested.
- A short, consented VPC flow-log sample for NAT traffic attribution.
- Infrastructure-as-code repository read access to improve effort estimates and implementation guidance.
The report states when a declined or unavailable source limits attribution, confidence, or resolution.
Storage and retention
- Raw billing exports and consented flow-log samples are stored only on encrypted, operator-controlled systems.
- Raw exports and flow-log samples are deleted within 30 days of report delivery.
- Derived working artifacts are deleted within 90 days after the later of report delivery or completion of contracted verification work, unless the client requests an earlier deletion.
- The final report, contract, and minimum delivery records may be retained where required for legal, accounting, or dispute-resolution purposes.
- Local AI transcripts and subscription or API conversations containing permitted derived artifacts are treated as derived working artifacts and included in the deletion record.
- Provider-side retention is separate from local retention. Deleting local artifacts does not shorten a provider's stated retention period, which is documented before model-assisted review is approved.
- Client engagement data is separated by client and never reused in another client's report. Model providers are configured not to use submitted engagement data for general model training. Provider safety, misuse, and legal-retention exceptions remain governed by the applicable service terms.
Model-assisted review
Model-assisted review may be used to challenge findings, look for omissions, and improve report clarity. Raw CUR files, account IDs, resource IDs, secrets, customer data, raw logs, application prompts, and application responses are not submitted to a model provider.
Model-facing material is limited to derived spend tables, de-identified resource counts, assumptions, and finding summaries. Resource references are pseudonymized before model use.
Model-assisted review may use a disclosed subscription service or commercial API. Before access is granted, the data-handling schedule names the provider, product and account type, subscription or API path, training setting, default retention period, processing location where known, and relevant safety, misuse, or legal-retention exceptions.
Incident and access lifecycle
- MFA is required on the operator side.
- Unexpected or excess permissions are reported and not used.
- A suspected incident reasonably likely to involve client data is reported in writing without undue delay and no later than 24 hours after awareness. Initial notice may precede full confirmation or investigation.
- The delivery record documents access grant, optional consents, revocation, and scheduled deletion dates.
Vendor and contracting information
Justin Henderiks performs the assessment directly and is the registered director of JPH PixelByte Labs Ltd., a Republic of Cyprus company incorporated on 9 October 2025 under company number HE 481685. The proposal and order form provide the registered office, tax information where applicable, bank beneficiary, governing law, and the entity responsible for data processing before signature.
No part of an engagement is subcontracted without prior written disclosure and approval.