Security and data handling

What access an engagement needs

The default is read-only billing and usage metadata: invoices, usage exports, and whatever request-level metadata already carries ownership tags. That is sufficient for baseline attribution and for identifying which workloads are worth optimizing. It does not require prompt content, output content, or production database access, and an engagement that asks for those on day one is asking for more than the work needs.

When content access is required

Some optimizations cannot be evaluated from metadata alone — semantic caching and prompt compression both depend on what is actually being sent. Where that applies, the scope is named in advance for the specific optimization, approved separately, and limited to sampled traffic rather than a standing feed. Approval for one optimization is not approval for the next.

Credential handling

Reporting a vulnerability

If you find a security issue on this site or in anything we operate, email the address below with enough detail to reproduce it. We will confirm receipt, and we do not pursue researchers who report in good faith and do not access or retain other people's data while doing so.

Security contact: hello@finopsllm.com.

Back to FinOps LLM