Privacy & TermsLast updated September 27, 2026

Your data, in plain English.

What VeriKost collects, what it never touches, who else sees it, and the simple rules for using the service. No legal fog — if something here is unclear, email us and we will fix the page.

The short version

Read-only. We read your cloud setup and costs. We cannot change or delete anything.

No keys. We never store your AWS access keys or passwords.

Never sold. No ads, no data brokers, no analytics trackers.

Yours to delete. Remove the role and ask us — your data is deleted.

§ 01Privacy

What we collect

Early-access request
Your name, work email, company, which cloud you use, and a rough monthly spend band.
WHYTo send your invite and set up your account.
Your account
Your login email and your password, stored only as a one-way hash (bcrypt). We cannot read your password.
WHYTo sign you in.
Your cloud setup
Resource IDs and settings (for example an instance type or a volume size), tags, usage metrics from CloudWatch, and cost figures.
WHYTo find waste and price each saving.
Results we create
Findings, evidence, realized savings and the reports you generate.
WHYSo you can track what you fixed.

02What we never collect

  • Your AWS keys or passwords. You create a role in your own account. Each scan borrows short-lived credentials that expire on their own.
  • What is inside your systems. We see that a database or a bucket exists and what it costs — not the records, files or objects in it.
  • Anything for advertising. No ad networks, no data brokers, no analytics trackers.

03How we use it

Only to run VeriKost for you: scan your account, show findings and savings, build your reports, write plain-English explanations of findings, and email you about your account or early access. We never sell your data.

04Who else handles it

A few companies run parts of VeriKost for us. They only process data to provide that service.

Amazon Web ServicesServers that run the VeriKost app.
SupabaseOur database (managed Postgres, hosted on AWS).
CloudflareDNS, network protection, and delivery of the website and app.
Google (Gemini API)Writes the plain-English explanation of a finding. It receives that finding's details — resource ID, metrics and cost figures — never your credentials. It does not calculate any number you see.

05How we protect it

  • Encrypted in transit (TLS) on every connection — browser, app and AWS.
  • Encrypted at rest in the database, which only our own server can reach.
  • Access to your cloud is read-only and ends the moment you delete the role. Full details are on the security page.

06Your choices

  • Stop access: delete the IAM role in your AWS account. We can no longer read anything.
  • See or export your data: email us and we will send it to you.
  • Delete everything: email us. During early access a person deletes it and confirms to you when it is done.

07Cookies

We only keep what is needed to keep you signed in. No advertising or tracking cookies.

§ 02Terms

Using VeriKost

  • Only connect cloud accounts you are allowed to connect.
  • Keep your login safe. You are responsible for activity on your account.
  • Your data stays yours. You give us permission to process it only to run VeriKost for you.

09Findings are advice

VeriKost never changes your cloud. You decide what to fix and you make the change yourself, so please check a finding before you delete anything. Savings are estimated from AWS list prices at scan time; your actual bill can differ because of discounts, credits or usage changes.

10Fair use

Please don’t try to break into VeriKost, reach other customers’ data, overload the service, or copy the product. Found a security issue? Tell us at security@verikost.com — good-faith research is welcome.

11Early access

VeriKost is in invite-only early access. Features may change, and we may pause the service to fix things. We will tell you before we ever start charging — nothing is billed without your agreement.

12Liability

During early access VeriKost is provided “as is”. As far as the law allows, we are not liable for changes you make to your cloud based on a finding, or for indirect losses.

13Changes & contact

If we change this page we update the date at the top, and we email you about any important change before it applies. Questions or requests: security@verikost.com.