ENTERPRISE TRUST CENTER
Designed for technical evaluations & security reviews. Zero stored cloud access keys, read-only IAM connectors across AWS, Azure, GCP, and Kubernetes, and sovereign AP-SOUTH-1 data residency.
Explicitly discriminates current implementation facts from roadmap items.
| Capability | Category | Current Status | Technical & Compliance Scope |
|---|---|---|---|
| AWS STS AssumeRole Cross-Account Integration | Security | OK Available | Read-only IAM AssumeRole delegation with external ID validation. |
| AES-256 KMS Envelope Encryption | Security | OK Available | AWS KMS customer-managed key envelope encryption at rest. |
| TLS 1.3 In-Transit Encryption | Infrastructure | OK Available | HTTPS TLS 1.3 enforced across all API routes and websocket streams. |
| AP-SOUTH-1 Mumbai Infrastructure Hosting | Infrastructure | OK Available | Hosted strictly in AWS AP-SOUTH-1 regional infrastructure. |
| DPDPA 2023 & GDPR Data Minimization Architecture | Compliance | OK Available | Architected for privacy alignment via zero credential storage & minimal metadata ingestion. |
| Immutable Cryptographic Audit Ledger | Governance | OK Available | Hash-chained append-only event ledger logging all detection and execution steps. |
| SOC 2 Type II Certification | Compliance | Planned | Independent third-party SOC 2 Type II audit planned for Q4 2026. |
| ISO 27001 Certification | Compliance | Planned | Information security management system certification roadmap. |
Every permission requested is bound strictly to a specific waste detector feature.
sts:AssumeRoleFeature: Cross-Account Integrationec2:DescribeVolumesFeature: Detector #102 (Unattached EBS Volume)rds:DescribeDBInstancesFeature: Detector #104 (Idle RDS Instance)cloudwatch:GetMetricDataFeature: Resource Utilization TelemetryTechnical evidence artifacts with explicit representation metadata.
Demonstrates executive summary layout, spend breakdown, and monthly waste recovery roadmap across AWS, Azure, GCP, and K8s.
Illustrates JSON structure of hash-chained audit events, actor sign-offs, and state transitions.
CloudFormation / Terraform template defining exact AssumeRole read-only permissions.
Bicep / Terraform definition granting read-only inspection across Azure Subscriptions and Management Groups.
Terraform template configuring short-lived credential exchange for GCP Resource Manager and Compute viewer.
Standard Kubernetes YAML manifest defining read-only ClusterRole for pods, PVCs, nodes, and daemonsets.
Visualizes network boundaries, AWS STS, Azure ARM, GCP Workload Identity, K8s RBAC, and AP-SOUTH-1 hosting.