A finance system touches every billing line in your business. We built InstantViewAI to the standard your auditors will eventually hold it to — read-only cloud access, isolated tenants, KMS envelope encryption, EU/US data residency, and an append-only audit trail by default.
InstantViewAI never needs write access to your cloud accounts. Read-only billing, inventory, and utilization access is enough — so InstantViewAI cannot start, stop, or modify resources in your environment.
No agents to install. No write permissions. The total ask on your side is roughly 2 – 3 hours of your team's time in week 1, then about 30 minutes a week thereafter.
InstantViewAI is an early-stage company. We don't yet hold formal certifications such as SOC 2 or ISO 27001, and we won't imply we do. What we can show you today is how the product is built — read-only, isolated per tenant, encrypted, and auditable — plus a Data Processing Agreement and a current subprocessor list when we take you through contracting. When certification is real, we'll publish it here with dates, not before.
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Google Cloud Platform | Hosting, compute, BigQuery, KMS | All customer data | EU (europe-west4) / US (us-central1) |
| Keycloak (self-hosted on GCP) | Identity & SSO | User identity | EU / US |
| Mailjet | Transactional email + scheduled reports | Email, attachments | EU (France) |
| Sentry | Error monitoring | Application errors (no customer PII) | EU |
We give 30-day advance notice of any subprocessor change under your DPA. Request the current list at security@instantview.ai.
Found something? Email security@instantview.ai and we'll work with you to confirm and fix it. We don't run a paid bounty programme yet, and we won't pretend otherwise. If a confirmed incident affects your data, we'll notify you.
An architecture overview, our DPA, the current subprocessor list, and answers to your security questionnaire — sent within one business day.