Security & compliance
Enterprise-grade
trust & security
The Varcio platform is built with security at every layer — from credential encryption to immutable audit trails and SOC 2 readiness.
All database volumes, snapshots, and backups are encrypted at rest using KMS.
Controls aligned to CC1–CC9, certification in progress
Core principles
Security by design, not afterthought
Four foundational principles guide every architectural and product decision.
Zero trust by default
No implicit access. Every API call is authenticated, authorized, and rate-limited.
No plaintext secrets
AWS uses AssumeRole, while Azure, GCP, and OCI credentials are encrypted at rest and never exposed in logs, API responses, or the UI.
Immutable audit trail
Every action, decision, and data access is logged with actor, timestamp, payload, and outcome. Logs cannot be modified or deleted.
Defense in depth
Multiple independent security layers — authentication, authorization, execution safety, rate limiting, and protected resources.
Defense in depth
Four layers around every cost action
Credentials never sit in plaintext, permissions are scoped twice, and no write reaches a resource without a human approving it.
Approval pipeline
From finding to action, fully audited
Detection is automated. Action never is — every remediation clears policy and a named approver first.
Data flow
How your data moves through the platform
From connection to action — every step is encrypted, audited, and gated.
Connect
Provider-native trust models with no plaintext credential exposure
AWS: AssumeRole with ExternalID. Azure: encrypted Service Principal. GCP: encrypted Service Account JWT. OCI: native credential flow.
Ingest
Cost data pulled via official cloud APIs
AWS Cost Explorer, Azure Cost Management API, GCP BigQuery billing export — always read-only.
Process
Data normalized, analyzed, and stored encrypted
Cost metadata is encrypted at rest, encrypted in transit, and processed inside isolated application environments.
Act
Remediation requires human approval
Write operations gated by approval workflow. Protected tags exclude critical resources. Rate limited to 10 actions/min.
Controls
9 security control layers
Every layer of the platform is designed with defense-in-depth principles.
Authentication
JWT sessions, OAuth (Google, GitHub, Azure AD), SSO via OIDC and SAML 2.0, SCIM provisioning (Enterprise)
Authorization
Dual-layer RBAC: page permissions (navigation) + action permissions (operations)
Credential storage
Fernet symmetric encryption (AES-128-CBC + HMAC-SHA256) — zero plaintext persistence
API tokens
SHA-256 hashed, show-once creation, configurable expiry, instant revocation
Execution safety
Single-use JTI tokens, replay prevention, approval gates for all write operations
Webhook signing
HMAC-SHA256 per-subscription signing secrets
Rate limiting
Per-IP and per-route limits with elevated thresholds for compute-heavy endpoints
Audit trail
Immutable action and decision logging with actor, timestamp, and payload details
Compliance
Control-mapped findings across SOC 2, CIS, NIST, and ISO 27001 with one-click evidence export
Encryption
Encryption at every layer
Credential handling
Provider-specific trust models
AWS, Azure, GCP, and OCI are handled differently, but every path avoids plaintext exposure and keeps execution behind approval gates.
Access control
Dual-layer RBAC
Page-level visibility and action-level permissions — independently configurable per role.
Compliance
SOC 2 readiness framework
Coverage across all 9 Common Criteria (CC1–CC9) with built-in compliance controls.
Control Environment
RBAC, role definitions, organizational policies
Communication & Information
Audit trails, user notifications, system alerts
Risk Assessment
Risk scoring, anomaly detection, policy evaluation
Monitoring Activities
Real-time monitoring, health checks, uptime tracking
Control Activities
Approval gates, execution safety, rate limiting
Logical Access
JWT auth, OAuth, API token hashing, credential encryption
System Operations
Event bus, webhook delivery, outbox pattern
Change Management
PR analysis, policy enforcement, configuration auditing
Risk Mitigation
Protected tags, dry-run mode, dead-letter queues
Vs. alternatives
How we compare
The only option in this comparison that combines AI operations, commitment purchasing, policy enforcement, and governed remediation in one product.
Scroll sideways to see every column.
| Capability | CloudHealth | Infracost | Kubecost | Varcio |
|---|---|---|---|---|
| Multi-Cloud Spend | — | — | ||
| Pre-Merge PR Analysis | — | — | ||
| K8s Cost Attribution | — | — | ||
| AI Conversational Interface | — | — | — | |
| Automated Remediation | limited | — | — | |
| Commitment Purchasing | — | — | — | |
| Predictive Forecasting | basic | — | basic | |
| ChatOps Approvals | — | — | — | |
| Event Bus / Webhooks | limited | — | — | |
| Policy Engine | basic | basic | — | |
| Starting Price | $$$$ | Free (limited) | Free (limited) | $49/mo |
Security FAQs
Does Varcio store our cloud credentials?
AWS uses IAM AssumeRole, so no static access keys are stored. Azure and GCP credentials are stored encrypted at rest using Fernet and are never exposed in logs, API responses, or the UI.
What data do you access?
Only cost and usage metadata. We read from Cost Explorer, Cost Management API, and BigQuery billing exports. We never access your application data, logs, or secrets.
Can auto-remediation break production?
We have multiple safety layers: protected-tag exclusion, human approval gates, rate limiting (10 actions/min), and dry-run mode. Critical resources tagged as protected are never touched.
Are you SOC 2 certified?
We built the platform for SOC 2 readiness from day one, with controls mapped to all 9 Common Criteria (CC1–CC9). The Compliance module maps findings across SOC 2, CIS, NIST, and ISO 27001 with one-click evidence export. Formal certification is in progress.
How do you handle data residency?
Cost data is processed and stored in the region you choose during onboarding. Enterprise plans support custom data residency requirements.
What happens if you have a breach?
Because AWS uses AssumeRole and Azure/GCP credentials are encrypted with strict exposure controls, the blast radius is limited to cost metadata and approved execution paths. Incident response, notification, and immutable audit trails support forensic review.
Secure. Compliant. Ready.
Start your free trial with enterprise-grade security from day one.