Data Residency & Hosting

CloudFix is hosted on Amazon Web Services (AWS) in the United States East (us-east-1) region. This is the single region where all customer data is processed and stored.

ComponentLocationProvider
Application & APIs AWS us-east-1 (N. Virginia) Amazon Web Services
Customer Data Storage AWS us-east-1 (N. Virginia) Amazon Web Services
Cost & Usage Report analysis AWS us-east-1 (N. Virginia) — Athena/Glue Amazon Web Services
CDN / Edge (dashboard only) AWS global edge network (origin: us-east-1) Amazon CloudFront (AWS — HTTP metadata only, no AWS cost data)
Support platform United States Kayako (support ticket content only)
Data residency: CloudFix processes and stores all AWS cost, usage, and resource metadata in AWS us-east-1. For organisations with specific data residency or transfer requirements, please contact us to discuss your needs.

Data Processing Addendum (DPA)

Our Data Processing Addendum governs how CloudFix processes customer data. Below is a summary of key terms.

Term Details
Controller Customer (you)
Processor CloudFix (Aurea, Inc.)
Data Categories AWS cost and usage metadata, account configuration data, resource metadata
Processing Purposes Cost analysis, optimization recommendations, approved fix implementation
Data Location US-East — AWS us-east-1 region
Retention Period Duration of contract + 30 days
Deletion Automated within 30 days of contract termination

Sub-Processors

CloudFix uses the following sub-processors to process customer data:

Purpose: Infrastructure provider for CloudFix application, data storage, and compute. Also processes AWS Marketplace billing for customer subscriptions.

Data processed: AWS cost and usage metadata, resource configuration data, billing data

Location: US-East (us-east-1)

Certifications: SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, CSA STAR, FedRAMP

Purpose: CDN and SSL termination for the CloudFix dashboard. Served via AWS CloudFront — part of the AWS infrastructure, not a separate third-party.

Data processed: HTTP request metadata (does not see customer AWS data)

Location: AWS global edge network (origin: us-east-1)

Certifications: SOC 1/2/3, ISO 27001, PCI DSS (inherited from AWS)

Purpose: Product analytics — understanding feature usage and improving the CloudFix experience.

Data processed: Anonymized usage events, page views. No customer AWS data or cost data.

Location: US

Certifications: SOC 2 Type 2

Purpose: Customer support platform — managing support tickets and customer communications.

Data processed: Support ticket content, email correspondence, customer name and email

Location: US

Certifications: SOC 2 Type 2, ISO 27001

Notification policy: CloudFix will notify customers at least 30 days before engaging any new sub-processor, providing an opportunity to object.

Data Transferred in Integrations

When CloudFix is integrated with an external platform via webhook or API, the following describes what data is exchanged:

Data CloudFix sends outbound (to ITSM platform)

Data TypeDescriptionPersonal Data?
Recommendation metadata AWS resource IDs, service type, estimated savings, status No
Account/org identifiers AWS account ID, account name as configured in CloudFix No
Approval status updates Approved/rejected, timestamp, approver username within CloudFix Potentially (username)
Fix execution results Success/failure status, completion timestamp No

Data CloudFix receives inbound (from ITSM platform via API)

Data TypeDescriptionPersonal Data?
Approval decisions Approved/rejected signal for a specific recommendation ID No
Approver identity (optional) Name or user ID of the approver in the ITSM platform, if passed Potentially (if name included)
No application data, S3 object contents, database records, or business data is accessed or transferred by CloudFix. CloudFix reads only AWS infrastructure metadata (resource IDs, configuration, cost/usage metrics).

How Data Is Processed

Data Collection

CloudFix accesses your AWS data through a read-only IAM role created by a CloudFormation StackSet that you deploy. The finder role performs only Describe, List, and Get actions — no write operations.

Data Analysis

Cost and Usage Reports are queried via Amazon Athena and processed in-memory for analysis. Results (optimization recommendations) are stored in CloudFix's database. Raw CUR data is not stored long-term.

Fix Execution

When you approve a fix, CloudFix executes it through AWS Systems Manager (Change Manager and Automation runbooks) within your AWS account. The actual fix is executed by a role in your account (cloudfix-ssm-assumed-role) that CloudFix creates but cannot itself directly assume — execution is orchestrated by SSM within your account boundary.

Data Deletion

Upon contract termination, all customer data is automatically deleted within 30 days. This includes:

  • Account metadata and configuration
  • Analysis results and recommendations
  • Fix history and audit logs
  • CloudFormation stacks can be removed by the customer at any time

Need the full DPA?

Download our standard DPA or request a customized version for your organization.