Security & trust

Read-only by design. Isolated per tenant. Encrypted throughout.

A finance system touches every billing line in your business. We built InstantViewAI to the standard your auditors will eventually hold it to — read-only cloud access, isolated tenants, KMS envelope encryption, EU/US data residency, and an append-only audit trail by default.

Trust at a glance
  • Read-only cloud access · no write permissions, ever
  • Per-tenant isolation · Keycloak realm + dataset
  • TLS 1.3 + AES-256 · GCP KMS envelope encryption
  • EU data residency · standard, US optional
  • GDPR-aligned · EU-first by design
Architecture

Read-only by default. Multi-tenant, isolated.

InstantViewAI never needs write access to your cloud accounts. Read-only billing, inventory, and utilization access is enough — so InstantViewAI cannot start, stop, or modify resources in your environment.

  • Read-only IAM scoped to billing & inventory APIs
  • Per-customer Keycloak realm — no shared identity
  • Per-customer dataset in BigQuery + isolated PostgreSQL schema
  • Dedicated environment option (Enterprise plan)
Data flow
Your cloud / AI providers GCP · AWS · Azure · OpenAI · Anthropic
↓ Read-only billing & inventory
InstantViewAI ingestion (TLS 1.3) Encrypted at rest · KMS
↓ Per-tenant isolation
Your tenant (EU / US) Keycloak realm + dataset
↓ SSO + RBAC
Your users SAML / OIDC
Onboarding effort

What we'll need from your team — exactly.

No agents to install. No write permissions. The total ask on your side is roughly 2 – 3 hours of your team's time in week 1, then about 30 minutes a week thereafter.

WEEK 1 ~ 2 – 3 hours, your team
  • 30 min: grant read-only role to billing exports (GCP / AWS / Azure)
  • 30 min: provide API keys for OpenAI / Anthropic (or skip if not used)
  • 60 min: walk us through your org chart and BUs once
  • 30 min: configure SSO (SAML or OIDC) with your IdP
Delivered by end of week 2: your first attributed cost report.
ONGOING ~ 30 min / week
  • Approve flagged budget variances in the inbox
  • Review the scheduled report we send before your board pack
  • Update the org chart if a team or BU moves
  • Nothing else. No daily babysitting.
All other config tweaks come from us — you focus on decisions, not maintenance.
NEVER What we don't ask for
  • Write permissions in your cloud accounts
  • Agents installed inside your environments
  • Access to production data, code, or secrets
  • Your engineering team's roadmap time
Read-only access means InstantViewAI cannot start, stop, or modify resources in your environment.
Pillars

Security across the stack.

Encryption

  • · TLS 1.3 in transit
  • · AES-256 at rest
  • · GCP KMS envelope encryption for secrets
  • · BYOK supported on Enterprise

Identity & access

  • · Keycloak realm per customer
  • · SAML 2.0 + OIDC SSO
  • · Role-based access control (RBAC)
  • · MFA enforced for admin roles

Audit trail

  • · Append-only, write-once events
  • · Every material state change recorded
  • · Audit-log export to S3 / GCS
  • · Exportable for your auditors

Data residency

  • · EU (Netherlands · europe-west4) standard
  • · US (us-central1) optional
  • · No cross-region replication of customer data
Compliance

Where we honestly stand.

InstantViewAI is an early-stage company. We don't yet hold formal certifications such as SOC 2 or ISO 27001, and we won't imply we do. What we can show you today is how the product is built — read-only, isolated per tenant, encrypted, and auditable — plus a Data Processing Agreement and a current subprocessor list when we take you through contracting. When certification is real, we'll publish it here with dates, not before.

Subprocessors

The third parties we use, what they process, and where.

ProviderPurposeDataRegion
Google Cloud PlatformHosting, compute, BigQuery, KMSAll customer dataEU (europe-west4) / US (us-central1)
Keycloak (self-hosted on GCP)Identity & SSOUser identityEU / US
MailjetTransactional email + scheduled reportsEmail, attachmentsEU (France)
SentryError monitoringApplication errors (no customer PII)EU

We give 30-day advance notice of any subprocessor change under your DPA. Request the current list at security@instantview.ai.

Responsible disclosure

Found a vulnerability? Tell us.

Found something? Email security@instantview.ai and we'll work with you to confirm and fix it. We don't run a paid bounty programme yet, and we won't pretend otherwise. If a confirmed incident affects your data, we'll notify you.

Contact
Security & vulnerabilities: security@instantview.ai
Privacy / GDPR: privacy@instantview.ai
DPA & subprocessor list (at contracting): trust@instantview.ai

Need documentation for procurement?

An architecture overview, our DPA, the current subprocessor list, and answers to your security questionnaire — sent within one business day.