Skip to content
CloudFixTrust Centercloudfix.com
Menu

Menu expanded. The navigation follows.

Data processing

Where your data lives, who processes it, and for how long.

CloudFix processes and stores all AWS cost, usage and resource metadata in one AWS region, us-east-1. You are the controller; CloudFix is the processor, under a Data Processing Addendum you can read now.

Read the DPASub-processors

Data residency

AWS us-east-1

N. Virginia. The single region where all customer data is processed and stored. For specific residency or transfer requirements, including UK and EEA, talk to us.

Data residency and hosting

One region, on AWS.

ComponentLocationProvider
Application and APIsAWS us-east-1 (N. Virginia)Amazon Web Services
Customer data storageAWS us-east-1 (N. Virginia)Amazon Web Services
Cost and Usage Report analysisAWS us-east-1 (N. Virginia): Athena and GlueAmazon Web Services
CDN and edge (dashboard only)AWS global edge network (origin: us-east-1)Amazon CloudFront: HTTP metadata only, no AWS cost data
Support platformUnited StatesKayako: support ticket content only

Data Processing Addendum

The DPA, in summary.

The DPA governs how CloudFix processes customer data. A standard version is published; an enterprise-specific version can be negotiated.

View the DPATerms of service

TermDetail
ControllerCustomer (you)
ProcessorCloudFix (Aurea, Inc.)
Data categoriesAWS cost and usage metadata, account configuration data, resource metadata
Processing purposesCost analysis, optimization recommendations, approved fix implementation
Data locationUS East: AWS us-east-1
Retention periodDuration of contract + 30 days
DeletionAutomated within 30 days of contract termination

Sub-processors

Who processes customer data, and what they see.

Notification policy: CloudFix notifies customers at least 30 days before engaging any new sub-processor, with the opportunity to object.

  • Amazon Web Services (AWS)

    Infrastructure for the CloudFix application, data storage and compute. Also processes AWS Marketplace billing for customer subscriptions.

    Data processed
    AWS cost and usage metadata, resource configuration data, billing data
    Location
    US East (us-east-1)
    Certifications
    SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, CSA STAR, FedRAMP
  • Amazon CloudFront

    CDN and TLS termination for the CloudFix dashboard. Part of AWS infrastructure, not a separate third party.

    Data processed
    HTTP request metadata (does not see customer AWS data)
    Location
    AWS global edge network (origin: us-east-1)
    Certifications
    SOC 1/2/3, ISO 27001, PCI DSS (inherited from AWS)
  • Amazon Route 53

    DNS resolution for the CloudFix dashboard. Part of AWS infrastructure, not a separate third party.

    Data processed
    DNS query metadata (does not see customer AWS data)
    Location
    AWS global anycast network
    Certifications
    SOC 1/2/3, ISO 27001, PCI DSS (inherited from AWS)
  • AWS Shield

    DDoS protection at the AWS edge. Part of AWS infrastructure, not a separate third party.

    Data processed
    Network and HTTP request metadata (does not see customer AWS data)
    Location
    AWS global edge network
    Certifications
    SOC 1/2/3, ISO 27001, PCI DSS (inherited from AWS)
  • PostHog

    Product analytics: understanding feature usage and improving the CloudFix experience.

    Data processed
    Anonymized usage events and page views. No customer AWS data or cost data.
    Location
    US
    Certifications
    SOC 2 Type 2
  • Kayako

    Customer support: managing support tickets and customer communications.

    Data processed
    Support ticket content, email correspondence, customer name and email
    Location
    US
    Certifications
    SOC 2 Type 2, ISO 27001

Integrations

Data transferred in integrations.

What CloudFix exchanges with an external platform (a service desk or ITSM tool) connected by webhook or API. The ITSM diagram shows the flow.

CloudFix sends (outbound, to the ITSM platform)

Data typeDescriptionPersonal data?
Recommendation metadataAWS resource IDs, service type, estimated savings, statusNo
Account and org identifiersAWS account ID, account name as configured in CloudFixNo
Approval status updatesApproved or rejected, timestamp, approver username within CloudFixPotentially (username)
Fix execution resultsSuccess or failure status, completion timestampNo

CloudFix receives (inbound, from the ITSM platform through the API)

Data typeDescriptionPersonal data?
Approval decisionsApproved or rejected signal for a specific recommendation IDNo
Approver identity (optional)Name or user ID of the approver in the ITSM platform, if passedPotentially (if a name is included)

No application or business data is transferred to the ITSM platform. Outbound payloads carry recommendation metadata only. Inside your AWS account, CloudFix reads primarily infrastructure metadata (resource IDs, configuration, cost and usage metrics); a few finders need targeted reads beyond that, each granted only when the finder is enabled. See the finder role permission model.

How data is processed

From collection to deletion.

  1. Collection

    Through IAM roles created by a CloudFormation StackSet you deploy. The finder role is read-oriented: overwhelmingly Describe, List and Get, plus tagging, query execution and a few finder-specific actions (such as s3:PutObject and ssm:SendCommand) present only when the finder needing them is entitled. All are enumerated on the security page and in the CloudFormation templates.

  2. Analysis

    Cost and Usage Reports are queried through Amazon Athena and processed in memory. Results (optimization recommendations) are stored in CloudFix's database. Raw CUR data is not stored long-term.

  3. Fix execution

    When you approve a fix, CloudFix starts it as an AWS Systems Manager Automation runbook inside your AWS account, under cloudfix-ssm-update-role. The change happens within your account boundary, and every execution is logged.

  4. Deletion

    On contract termination all customer data is deleted automatically within 30 days: account metadata and configuration, analysis results and recommendations, fix history and audit logs. You can remove the CloudFormation stacks at any time.

Need the full DPA?

Read the standard DPA, print it to PDF, or ask for a version for your organization.