Security
Read-only, by design.
PicketPin finds waste by reading billing and usage data. It doesn't need permission to change anything, so it never asks for it. Here's exactly what we read from each service, and why.
Read-only connections
Every connection uses the narrowest read-only access the service offers. Nothing in your accounts changes because you connected PicketPin.
You stay in control
You choose which accounts to connect, and you can remove any connection from your settings at any time.
Actions will be opt-in
When one-click actions arrive after launch, you'll turn them on yourself. Every action will be logged and can be undone for 30 days.
What we read, service by service
We'll publish the exact permission list for each service here before launch.
| Service | How you connect | What we read | Why |
|---|---|---|---|
| AWS | A read-only IAM role with an external ID, created by a CloudFormation template you review and run | Your billing data export; an inventory of EC2, EBS, RDS, load balancers, S3 and snapshots; CloudWatch usage metrics | To match each charge to the resource behind it and spot idle or unattached resources |
| Google Workspace | Sign in with Google as an admin, with read-only access | Users, license assignments, third-party app access and login events | To find seats for people who left and apps nobody has opened in 60 days. Only admins can see licenses and login events, so admin sign-in is needed. |
| Vercel | The Vercel integration, or an API token | Projects, deployments, usage and team members | To find preview deployments and projects that cost money but aren't used |
| Fly.io | An API token you create | Apps, machines, volumes and usage | Stopped machines with volumes still attached are a common leak |
| Stripe | A restricted key with read-only permissions | Stripe fees and your own revenue | To show spend as a share of revenue, and cost against revenue per client |
| Bank or card | Plaid's own sign-in window. PicketPin never sees your bank password. | Transactions | To find recurring charges, including software with no API. PicketPin can't move money. |
| CSV upload | You upload a bank or card statement file | The rows in that file | Same as the bank or card feed, without connecting a bank |
How we store your data
[To be written with the infrastructure plan: how credentials are stored, encryption, data retention, and what's deleted when you disconnect or close your account.]
Found a security issue? Email [SECURITY CONTACT].