Read-only credentials, defined retention, no resale.
Tallywyrm is a 24/7 FinOps agent for multi-cloud spend. This page codifies what we already promise on the landing page: how we get into your cloud, what we keep, and what we will not do with it.
Bring-your-own credential scope.
Authentication uses an OIDC trust you already operate; the agent never holds long-lived cloud keys. The credential we ask for is read-only and tightly scoped.
Read-only cloud credentials via your existing OIDC trust.
- No write surface — inventory and billing reads only.
- No organisation-admin or account-break-glass role.
- No role escalation, no IAM user creation, no console access.
- No cross-account assume-role into resources you have not already federated.
What data we collect.
Only what the agent needs to compute a recommendation, ship a PR, and prove the audit window. No browsing history, no employee telemetry, no marketing pixels.
Hourly multi-cloud resource records across AWS, GCP and Azure — instance types, attached storage, network attachments, tag taxonomy, region, and account/tenant lineage.
Computed candidates, the PR diff opened against your Terraform, Pulumi or Crossplane repo, the trace linking the recommendation back to the inventory snapshot it was derived from, and the approval state at each review.
Every action the agent takes — credential access, inventory reads, recommendation writes, PR opens, schedule changes — recorded with timestamp, actor, request payload and outcome for the compliance frameworks in the badge row below.
The savings number, the PRs applied within the audit window, the credit applied to the invoice, and the recipient list. Kept so each invoice can be reconstructed from the report that produced it.
How long we keep it.
The agent runs on a weekly audit-pass cadence — retention windows below are sized to that, and to the SOC 2 Type II / ISO 27001 control norms the audit trail must satisfy.
No resale of customer data or telemetry.
We do not sell, rent, or barter your inventory, audit events, or cost data. We do not share it with third parties beyond payment and billing counterparties required to raise an invoice.
The telemetry categories above — cost data, inventory snapshots, audit events, recommendation and PR traces — are processed only to deliver the service to you.
Aggregated, fully de-identified service-health metrics (queue latency, scheduler success rate) are the only data used outside a customer tenancy, and only to keep the platform operating.
Your rights.
The rights below apply to every customer regardless of jurisdiction; GDPR-style requests are honoured globally.
- Access — request a copy of every record we hold against your tenancy.
- Correction — flag any inventory record or audit entry you believe is wrong; we re-pull from the cloud source of truth on the next hourly snapshot.
- Deletion — close your workspace and we delete tenancy-scoped data within the same retention window we publish below.
- Export — receive the audit trail and report metadata in a portable format on request.
- Objection — opt specific resource classes or regions out of inventory at any time; the agent downscopes on the next cycle.
Aligned with the frameworks finance and platform teams already audit against.
Same badges as the landing page. The audit trail we keep above is what these frameworks demand.
- SOC 2 Type II
- ISO 27001
- FedRAMP Moderate
- EU CSRD
- SEC climate disclosure
- GDPR