Skip to content
Refine

Security & Trust

Your AWS data, handled the way you'd handle it yourself.

Read-only IAM role. Encryption at rest and in transit. Your data deletable at any time. Hosted entirely on AWS — the same trust boundary as your own infrastructure.

  • Read-only IAM role

    No access keys

  • TLS 1.2+ in transit

    Encrypted at rest

  • Delete your data anytime

    Self-service or by written request

  • Built 100% on AWS

    No third-party hosts

How your data flows through Refine

Five stages. Every stage is in AWS — yours or ours. Your raw data never leaves the AWS network boundary.

  1. 1Your AWS

    AWS Cost & Security APIs

    Refine reads from CUR, Cost Explorer, IAM, EC2, S3, CloudTrail, GuardDuty, and 20+ other read-only APIs.

  2. 2IAM

    Read-only IAM role

    The Refine connector stack creates a read-only IAM role in your account that only Refine's AWS account can assume, and only with your External ID: billing, security-audit, Savings Plans and CloudWatch-metrics read, plus read access to the export bucket. No write or admin permissions, and no access keys.

  3. 3Refine — AWS

    Ingestion (in our AWS account)

    Refine assumes your role from our AWS-hosted infrastructure, pulls the data, and writes aggregates to DynamoDB and S3 in our account.

  4. 4Refine — AWS

    Storage and encryption

    Customer data in Refine's database tables, file storage and backups is encrypted at rest: DynamoDB tables with AWS-owned keys, S3 with S3-managed keys (SSE-S3). Webhook URLs, and the access key of any connection made before roles until it moves to one, are encrypted separately with a dedicated AWS KMS key. Every database table is backed up daily with AWS Backup; each backup is KMS-encrypted and kept 10 days.

  5. 5Refine — AWS

    Dashboard served via CloudFront + Amplify

    You see narrative reports and dashboards. Your raw data never leaves AWS — it just moves between your account and ours.

Read-Only IAM Role

The connector stack creates a read-only IAM role in your account. Its trust policy lets exactly one principal assume it — Refine’s AWS account — and only when the request carries your External ID, so no other Refine customer can point us at your role. Sessions last at most an hour, and no access keys are created. Revoke access at any time by deleting the role, or the stack, in your AWS console — Refine immediately loses the ability to read. The policies are below.

What the connector stack attaches

Two AWS-managed read-only policies — job-function/Billing (the cost views) and SecurityAudit (the security views) — plus three inline ones: read on the export bucket alone; one Savings Plans read, so the commitments page can show when each plan ends; and one CloudWatch read — fourteen days of a database’s connections or a cache’s commands, numbers only — so an “idle” recommendation is one CloudWatch confirms, not one the bill guesses:

json
Inline S3 policy — read access to the export bucket only
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "S3Access",
      "Effect": "Allow",
      "Action": ["s3:ListBucket"],
      "Resource": "arn:aws:s3:::<your-focus-export-bucket>"
    },
    {
      "Sid": "S3ObjectAccess",
      "Effect": "Allow",
      "Action": ["s3:GetObject"],
      "Resource": "arn:aws:s3:::<your-focus-export-bucket>/*"
    }
  ]
}
json
Inline Savings Plans policy — one read, the plans' terms
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "SavingsPlansTerms",
      "Effect": "Allow",
      "Action": ["savingsplans:DescribeSavingsPlans"],
      "Resource": "*"
    }
  ]
}
json
Inline CloudWatch policy — one read, usage metrics
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "UsageMetrics",
      "Effect": "Allow",
      "Action": ["cloudwatch:GetMetricData"],
      "Resource": "*"
    }
  ]
}

Who can assume it

Refine’s AWS account, with the External ID generated for your connection — nothing else. The ID is a value only you and Refine hold, which is AWS’s documented guard against a third party naming your role (the “confused deputy”).

json
Trust policy — Refine's account, only with your External ID
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": { "AWS": "arn:aws:iam::<refine-account-id>:root" },
      "Action": "sts:AssumeRole",
      "Condition": { "StringEquals": { "sts:ExternalId": "<your-external-id>" } }
    }
  ]
}

Connected before roles? Accounts connected with an access key keep working: the key is encrypted with a dedicated AWS KMS key and decrypted only inside the ingestion pipeline. Move the connection to a role from Settings → Accounts and the key is deleted from Refine.

We do not request any write, delete, or modify permissions — not for this role, and not for any other. Nothing in Refine changes your AWS account. "Fix Available" means a finding carries the AWS Console steps that close it and a link to the official AWS documentation; you make the change yourself.

Data Retention

What we keep, for how long, and how to make us forget it.

Data categoryRetentionNotes
Connected AWS — cost and usage dataLife of the accountKept so trends stay comparable. Remove a connection from Settings → AWS Accounts, or delete the whole customer from Settings → General Settings.
Security findings90 daysRolling window from the latest scan, expired automatically.
Upload Bill — uploaded filesDeleted in 3 daysTypically within minutes. No long-term storage of upload contents.
Account metadata (email, org name)Until account deletionRequired for authentication and notifications.
Audit log (admin actions, exports)400 daysRolling window, enforced automatically.
Anonymized aggregate statsIndefiniteNo PII or customer-identifying data. Used to improve recommendation quality.

Need different retention? Email info@habilelabs.io or delete the customer from Settings → General Settings in the dashboard.

Encryption

In transit

All client and server-to-server traffic uses TLS 1.2 or higher. AWS service calls flow over AWS-managed VPC endpoints where available; cross-region traffic stays on the AWS backbone.

At rest

Customer data in Refine’s database tables, file storage and backups is encrypted at rest: DynamoDB tables with AWS-owned keys, S3 with S3-managed keys (SSE-S3), and table backups with AWS KMS. Webhook URLs, and the access key of a connection made before roles, are encrypted separately, with a dedicated customer-managed KMS key.

Sub-Processors

Third parties that may process customer data on our behalf. AWS hosts everything, and Gen-AI narratives are generated by Amazon Bedrock in the same region your data is stored in — nothing outside AWS processes it.

Sub-processorPurposeRegion
Amazon Web Services (AWS)Hosting, compute, storage, database, analyticsMulti-region (primary: ap-south-1)
Amazon CognitoUser authenticationap-south-1
Amazon SESTransactional + newsletter email (when enabled)ap-south-1
Amazon BedrockGen-AI narrative report generationap-south-1

See the canonical list at /sub-processors — updated when sub-processors change.

Compliance Posture

Honest current state. Frameworks marked "On roadmap" are not yet audited — we will not claim them until they are.

FrameworkStatusNotes
GDPR-compatible postureIn placeDPA available, self-service and on-request data deletion, sub-processors disclosed.
AWS Advanced Tier Services PartnerIn placeAWS-vetted; partnership renewed annually. AWS AI Services Competency designation also in place.
SOC 2 Type IIOn roadmapOn the roadmap. We have not yet completed a SOC 2 audit. Honest disclosure intentional.
ISO 27001On roadmapOn the roadmap alongside SOC 2.
HIPAANot applicableRefine does not process PHI. Healthcare customers see only AWS billing and security metadata.
PCI DSSNot applicableRefine does not handle payment card data.

Architecture — Every Component is on AWS

No third-party hosting providers. Your data and ours sit inside AWS the entire time.

Edge / CDN

Amazon CloudFront

Web hosting

AWS Amplify Hosting + S3

Authentication

Amazon Cognito

API + compute

AWS Lambda + API Gateway

Database

Amazon DynamoDB (daily AWS Backup)

Object storage

Amazon S3 (SSE-S3 encrypted)

Analytics

Amazon Athena + Glue

Email

Amazon SES

Observability

Amazon CloudWatch

Vulnerability Disclosure

Found a security issue? Email info@habilelabs.io with reproduction steps. We acknowledge within 48 hours and assign severity. We do not require a CVE to engage and we will not pursue legal action against good-faith researchers acting under responsible-disclosure norms.

  • Initial response: within 48 hours
  • Triage and severity assignment: within 5 business days
  • Coordinated disclosure timeline negotiated with the reporter

Frequently Asked Questions

  • No. The IAM role the connector stack creates is strictly read-only — billing, security-audit, Savings Plans and CloudWatch-metrics read, plus read access to your export bucket — and there is no second, elevated path. "Fix Available" on a security finding means we hold a vetted remediation guide for that check and will show you the AWS Console steps and the official AWS doc. For a tag violation, Refine generates an AWS CLI script or a Terraform patch that you run with your own credentials. Either way the change is made by you, in your account.

Have security questions we haven't answered?

Talk to a human. We respond to security@ within 48 hours.

Refine is built and supported by HabileLabs, an AWS Advanced Tier Services Partner.