How access is granted
Three ways to connect a cloud account, depending on how much standing access you want to grant.
Tier 1 — direct connection
The platform is granted a strictly read-only, narrowly-scoped role in your account (AWS AssumeRole, an Azure Service Principal, a GCP Service Account impersonation grant, or a Kubernetes ServiceAccount token) and scans on your schedule. Fastest to set up.
Tier 2 — in-account collector
A small container runs inside your own environment, on your own schedule, using an identity that exists only in your account and trusts nothing outside it. It sends only the scan results — findings and recommendations — back to the platform, never raw resource configuration, unless you explicitly opt in to sending that too.
Tier 3 — fully self-hosted
Run the entire platform, not just the collector, inside your own infrastructure. Nothing about your environment ever leaves it.
Revoking access
Delete the connection in the app and remove the role/service account it created in your cloud account — both take effect immediately, for every tier.