Access model
Standard Cloudryption onboarding uses customer-created, scoped, read-only access. Write permissions are not required for standard inventory, graph building, attack path analysis, reporting, or CID recommendations.
| Provider | Access type | Purpose | Write access? |
|---|---|---|---|
| AWS | Read-only IAM role or equivalent scoped role | Inventory, IAM, network, storage, compute, security findings, and relationship metadata | No for standard discovery |
| Azure | Reader-style scoped access plus security-reader style permissions where approved | Subscriptions, resources, identities, role assignments, NSGs, data stores, posture signals | No for standard discovery |
| GCP | Viewer/security-reviewer style scoped service account where approved | Projects, IAM bindings, compute, storage, networks, logging/security posture signals | No for standard discovery |
| Kubernetes | Read-only cluster role where enabled | Cluster inventory, namespaces, workloads, service exposure, RBAC, and configuration context | No for standard discovery |
Collection categories
- Asset inventory — resources, regions, accounts/projects/subscriptions, tags, states, and ownership metadata.
- Identity and access — users, roles, service accounts, policies, bindings, group relationships, and privilege indicators.
- Network reachability — VPC/VNet/VPC Network topology, subnets, routes, public exposure, firewall and security-group rules.
- Data posture — buckets, databases, warehouses, encryption posture, public access, backup/logging signals, and sensitivity hints.
- Security findings — provider-native security findings and vulnerability metadata where available and authorized.
What Cloudryption does not need for standard discovery
- Administrative write access.
- Access to raw customer database records.
- Access to application source code.
- Access to secrets or private keys.
- Packet capture or runtime process telemetry.
Customer control
Customers can limit Cloudryption by provider, account, project, subscription, region, environment, and module. Permission scope can be reviewed before onboarding and reduced when a module is not required.
Need this in your enterprise security review?
Cloudryption can provide a security packet, technical walkthrough, and pilot evidence pack for your evaluation process.