Security

Read-only, by design.

PicketPin finds waste by reading billing and usage data. It doesn't need permission to change anything, so it never asks for it. Here's exactly what we read from each service, and why.

Read-only connections

Every connection uses the narrowest read-only access the service offers. Nothing in your accounts changes because you connected PicketPin.

You stay in control

You choose which accounts to connect, and you can remove any connection from your settings at any time.

Actions will be opt-in

When one-click actions arrive after launch, you'll turn them on yourself. Every action will be logged and can be undone for 30 days.

What we read, service by service

We'll publish the exact permission list for each service here before launch.

Service How you connect What we read Why
AWS A read-only IAM role with an external ID, created by a CloudFormation template you review and run Your billing data export; an inventory of EC2, EBS, RDS, load balancers, S3 and snapshots; CloudWatch usage metrics To match each charge to the resource behind it and spot idle or unattached resources
Google Workspace Sign in with Google as an admin, with read-only access Users, license assignments, third-party app access and login events To find seats for people who left and apps nobody has opened in 60 days. Only admins can see licenses and login events, so admin sign-in is needed.
Vercel The Vercel integration, or an API token Projects, deployments, usage and team members To find preview deployments and projects that cost money but aren't used
Fly.io An API token you create Apps, machines, volumes and usage Stopped machines with volumes still attached are a common leak
Stripe A restricted key with read-only permissions Stripe fees and your own revenue To show spend as a share of revenue, and cost against revenue per client
Bank or card Plaid's own sign-in window. PicketPin never sees your bank password. Transactions To find recurring charges, including software with no API. PicketPin can't move money.
CSV upload You upload a bank or card statement file The rows in that file Same as the bank or card feed, without connecting a bank

How we store your data

[To be written with the infrastructure plan: how credentials are stored, encryption, data retention, and what's deleted when you disconnect or close your account.]

Found a security issue? Email [SECURITY CONTACT].