Read-only IAM role
No access keys
Security & Trust
Read-only IAM role. Encryption at rest and in transit. Your data deletable at any time. Hosted entirely on AWS — the same trust boundary as your own infrastructure.
Read-only IAM role
No access keys
TLS 1.2+ in transit
Encrypted at rest
Delete your data anytime
Self-service or by written request
Built 100% on AWS
No third-party hosts
Five stages. Every stage is in AWS — yours or ours. Your raw data never leaves the AWS network boundary.
Refine reads from CUR, Cost Explorer, IAM, EC2, S3, CloudTrail, GuardDuty, and 20+ other read-only APIs.
The Refine connector stack creates a read-only IAM role in your account that only Refine's AWS account can assume, and only with your External ID: billing, security-audit, Savings Plans and CloudWatch-metrics read, plus read access to the export bucket. No write or admin permissions, and no access keys.
Refine assumes your role from our AWS-hosted infrastructure, pulls the data, and writes aggregates to DynamoDB and S3 in our account.
Customer data in Refine's database tables, file storage and backups is encrypted at rest: DynamoDB tables with AWS-owned keys, S3 with S3-managed keys (SSE-S3). Webhook URLs, and the access key of any connection made before roles until it moves to one, are encrypted separately with a dedicated AWS KMS key. Every database table is backed up daily with AWS Backup; each backup is KMS-encrypted and kept 10 days.
You see narrative reports and dashboards. Your raw data never leaves AWS — it just moves between your account and ours.
The connector stack creates a read-only IAM role in your account. Its trust policy lets exactly one principal assume it — Refine’s AWS account — and only when the request carries your External ID, so no other Refine customer can point us at your role. Sessions last at most an hour, and no access keys are created. Revoke access at any time by deleting the role, or the stack, in your AWS console — Refine immediately loses the ability to read. The policies are below.
Two AWS-managed read-only policies — job-function/Billing (the cost views) and SecurityAudit (the security views) — plus three inline ones: read on the export bucket alone; one Savings Plans read, so the commitments page can show when each plan ends; and one CloudWatch read — fourteen days of a database’s connections or a cache’s commands, numbers only — so an “idle” recommendation is one CloudWatch confirms, not one the bill guesses:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "S3Access",
"Effect": "Allow",
"Action": ["s3:ListBucket"],
"Resource": "arn:aws:s3:::<your-focus-export-bucket>"
},
{
"Sid": "S3ObjectAccess",
"Effect": "Allow",
"Action": ["s3:GetObject"],
"Resource": "arn:aws:s3:::<your-focus-export-bucket>/*"
}
]
}{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "SavingsPlansTerms",
"Effect": "Allow",
"Action": ["savingsplans:DescribeSavingsPlans"],
"Resource": "*"
}
]
}{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "UsageMetrics",
"Effect": "Allow",
"Action": ["cloudwatch:GetMetricData"],
"Resource": "*"
}
]
}Refine’s AWS account, with the External ID generated for your connection — nothing else. The ID is a value only you and Refine hold, which is AWS’s documented guard against a third party naming your role (the “confused deputy”).
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::<refine-account-id>:root" },
"Action": "sts:AssumeRole",
"Condition": { "StringEquals": { "sts:ExternalId": "<your-external-id>" } }
}
]
}Connected before roles? Accounts connected with an access key keep working: the key is encrypted with a dedicated AWS KMS key and decrypted only inside the ingestion pipeline. Move the connection to a role from Settings → Accounts and the key is deleted from Refine.
We do not request any write, delete, or modify permissions — not for this role, and not for any other. Nothing in Refine changes your AWS account. "Fix Available" means a finding carries the AWS Console steps that close it and a link to the official AWS documentation; you make the change yourself.
What we keep, for how long, and how to make us forget it.
| Data category | Retention | Notes |
|---|---|---|
| Connected AWS — cost and usage data | Life of the account | Kept so trends stay comparable. Remove a connection from Settings → AWS Accounts, or delete the whole customer from Settings → General Settings. |
| Security findings | 90 days | Rolling window from the latest scan, expired automatically. |
| Upload Bill — uploaded files | Deleted in 3 days | Typically within minutes. No long-term storage of upload contents. |
| Account metadata (email, org name) | Until account deletion | Required for authentication and notifications. |
| Audit log (admin actions, exports) | 400 days | Rolling window, enforced automatically. |
| Anonymized aggregate stats | Indefinite | No PII or customer-identifying data. Used to improve recommendation quality. |
Need different retention? Email info@habilelabs.io or delete the customer from Settings → General Settings in the dashboard.
All client and server-to-server traffic uses TLS 1.2 or higher. AWS service calls flow over AWS-managed VPC endpoints where available; cross-region traffic stays on the AWS backbone.
Customer data in Refine’s database tables, file storage and backups is encrypted at rest: DynamoDB tables with AWS-owned keys, S3 with S3-managed keys (SSE-S3), and table backups with AWS KMS. Webhook URLs, and the access key of a connection made before roles, are encrypted separately, with a dedicated customer-managed KMS key.
Third parties that may process customer data on our behalf. AWS hosts everything, and Gen-AI narratives are generated by Amazon Bedrock in the same region your data is stored in — nothing outside AWS processes it.
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, compute, storage, database, analytics | Multi-region (primary: ap-south-1) |
| Amazon Cognito | User authentication | ap-south-1 |
| Amazon SES | Transactional + newsletter email (when enabled) | ap-south-1 |
| Amazon Bedrock | Gen-AI narrative report generation | ap-south-1 |
See the canonical list at /sub-processors — updated when sub-processors change.
Honest current state. Frameworks marked "On roadmap" are not yet audited — we will not claim them until they are.
| Framework | Status | Notes |
|---|---|---|
| GDPR-compatible posture | In place | DPA available, self-service and on-request data deletion, sub-processors disclosed. |
| AWS Advanced Tier Services Partner | In place | AWS-vetted; partnership renewed annually. AWS AI Services Competency designation also in place. |
| SOC 2 Type II | On roadmap | On the roadmap. We have not yet completed a SOC 2 audit. Honest disclosure intentional. |
| ISO 27001 | On roadmap | On the roadmap alongside SOC 2. |
| HIPAA | Not applicable | Refine does not process PHI. Healthcare customers see only AWS billing and security metadata. |
| PCI DSS | Not applicable | Refine does not handle payment card data. |
No third-party hosting providers. Your data and ours sit inside AWS the entire time.
Edge / CDN
Amazon CloudFront
Web hosting
AWS Amplify Hosting + S3
Authentication
Amazon Cognito
API + compute
AWS Lambda + API Gateway
Database
Amazon DynamoDB (daily AWS Backup)
Object storage
Amazon S3 (SSE-S3 encrypted)
Analytics
Amazon Athena + Glue
Amazon SES
Observability
Amazon CloudWatch
Found a security issue? Email info@habilelabs.io with reproduction steps. We acknowledge within 48 hours and assign severity. We do not require a CVE to engage and we will not pursue legal action against good-faith researchers acting under responsible-disclosure norms.
Talk to a human. We respond to security@ within 48 hours.
Refine is built and supported by HabileLabs, an AWS Advanced Tier Services Partner.