Security
How CloudOpsGPT handles your AWS environment, access, and data boundaries.
- Runtime runs in your AWS account.
- Portal authentication uses Amazon Cognito (email and password).
- The Portal does not ask for your AWS access keys.
- AWS access uses IAM roles, ExternalId, and STS AssumeRole that you control.
- The Control Plane receives metadata required to operate the service (workspace, entitlement, Runtime connectivity, account inventory).
Full security details
1. Where CloudOpsGPT runs
- Runtime: Deployed into the customer’s AWS account using AWS CloudFormation.
- Commercial Portal: Hosted by CloudOpsGPT (authentication, workspace, trial/subscription status, activation, Runtime registry).
- Scope: Current product is AWS-only. Multi-cloud Runtime deployment is not part of the current release.
2. Portal authentication
- The Commercial Portal authenticates users with Amazon Cognito (email and password).
- Portal sessions use Cognito-issued tokens verified by CloudOpsGPT APIs.
- Multi-factor authentication (MFA) for portal login is not enabled in the current release.
3. Runtime activation
- After you deploy Runtime in your AWS account, you activate it with a one-time activation token from the Commercial Portal.
- Successful activation binds that Runtime to your workspace and issues a Runtime credential used for Control Plane registration and heartbeats.
- CloudOpsGPT does not use customer-managed “license keys” as the access model.
4. How AWS access is granted
- The Commercial Portal does not ask for your AWS access keys or secret keys.
- Managed AWS accounts are onboarded using IAM roles, typically with an ExternalId, and accessed via STS AssumeRole from Runtime in your environment.
- Temporary credentials used for AWS API calls are obtained and used inside the customer Runtime environment.
- You control which roles and permissions are created and which AWS accounts are connected.
5. What stays in your AWS environment
- Runtime application services and local Runtime data (including chat/execution activity stored by Runtime).
- AWS API calls performed by Runtime against accounts you have onboarded.
- AI-assisted operations executed through Kiro from the Runtime host (customer-controlled authentication to the AI provider).
6. What the Control Plane receives
The Control Plane receives the operational and commercial metadata required to operate the service, for example:
- Portal account and workspace identity
- Trial / subscription / entitlement status and AWS account capacity limits
- Runtime registration, connectivity/heartbeat status, and activation state
- Managed AWS account inventory metadata reported by Runtime (account identifiers and related registry fields)
Absolute statements such as “data never leaves your cloud” are not accurate for this architecture, because Control Plane metadata is required for commercial and connectivity management.
7. AI operations
- Runtime uses Kiro for AI-assisted AWS operations.
- Kiro authentication (for example IAM Identity Center / device flow) is performed in the customer Runtime context.
- CloudOpsGPT does not operate a separate “Azure OpenAI” product path in the current release.
- We do not claim that customer prompts are used—or not used—for third-party model training beyond what the AI provider’s own terms cover. See the Privacy Policy.
8. Permissions and customer control
- You control the AWS account where Runtime is deployed and the IAM roles used for managed accounts.
- Runtime enforces application roles (for example Admin / Engineer) for Runtime users.
- Changing actions should be reviewed according to your own operating procedures; CloudOpsGPT is an operations assistant, not a substitute for your change control.
9. Execution and activity auditing
- Runtime records application-level execution / activity audit for operations performed through CloudOpsGPT.
- Your AWS account may also produce native AWS logs (for example CloudTrail) based on your AWS configuration; that is separate from CloudOpsGPT’s product audit trail.
- CloudOpsGPT does not claim that every product action is mirrored into CloudWatch/CloudTrail by the product itself, or that automatic rollback is provided.
10. Transport and hosting notes
- Commercial Portal and Control Plane APIs are served over HTTPS.
- Customer Runtime deployments use an Application Load Balancer with HTTPS (TLS 1.2+) for the Runtime URL. Direct EC2 access is restricted to the ALB; host administration uses AWS Systems Manager Session Manager.
- We do not claim universal TLS 1.3, private-only networking, or hybrid multi-cloud deployment in the current release.
11. What we do not claim today
- SOC 2, ISO 27001, or HIPAA certification
- Guaranteed 24/7 security monitoring or fixed incident-notification SLAs
- Quarterly third-party penetration testing as a committed control
- Azure / Google Cloud Runtime support
Contact
Security questions: info@cloudopsgpt.com