Read-only. Infrastructure and billing only. Nothing proprietary.
Cloud cost analysis does not need your code, your data, or your secrets. So we do not ask for them.
What we access.
Read-only visibility into infrastructure and billing. The metadata that describes how resources are configured and what they cost. Nothing more.
What we never touch.
Your application data. Your databases. Your source code. Your customer records. None of it is in scope, and the access we use cannot reach it. The analysis works entirely from configuration and billing signals.
Security is the founder's background, not an afterthought.
Koritsu is led by an engineer who has spent a career inside environments where security is not optional. Background includes Moody's Analytics and FTSE 100 financial services, building under the controls those environments demand. Holds Stanford's Software Security Foundations certification. The access model reflects that. Least-privilege by default, read-only by design.
An independent security layer.
We run Aikido as our security provider for SAST, DAST, and continuous environment monitoring. Our own platform is held to the same standard we would expect of anyone we gave access to. SOC 2 in progress.