WasteRadar Security & Trust Center

WasteRadar Trust Center

Security and transparency built into the WasteRadar architecture. Comprehensive disclosures regarding tenant isolation, read-only IAM scopes, encryption at rest, and infrastructure subprocessors by Odinext.

Verified Security Controls Status

Designed for enterprise security requirements
Cloud AccessImplemented

Read-Only Azure Architecture

Operates exclusively under Reader and Cost Management Reader IAM roles. Zero write, start, stop, or delete capabilities.

Standard: WasteRadar ProtocolVerified
Multi-TenancyImplemented

PostgreSQL Row-Level Security (RLS)

Hardware and logical separation enforced at database level with org_id context filtering on all queries.

Standard: WasteRadar ProtocolVerified
Data EncryptionImplemented

AES-256-GCM & TLS 1.3

Credentials, OAuth tokens, and backups encrypted at rest with AES-256-GCM. All transit encrypted via TLS 1.3.

Standard: WasteRadar ProtocolVerified
Access ControlImplemented

Role-Based Access Control (RBAC)

Strict separation of Owner, Admin, Member, and Viewer permissions across all workspaces and billing settings.

Standard: WasteRadar ProtocolVerified
AI SafetyImplemented

Context Minimization & Secret Redaction

All secrets, access credentials, and Azure tokens are stripped prior to LLM inference. Calculations remain deterministic.

Standard: WasteRadar ProtocolVerified
Application DefenseImplemented

Formula Injection & XSS Sanitization

CSV exports sanitize formula triggers (=, +, -, @). React JSX encoding and Zod schema validations active.

Standard: WasteRadar ProtocolVerified
Audit & GovernanceMonitored

Immutable Security Audit Trail

All authentication events, scans, exports, and permission mutations logged to dedicated audit tables.

Standard: WasteRadar ProtocolVerified
InfrastructureMonitored

Sliding-Window Rate Limiting & Bot Defense

Google reCAPTCHA Enterprise and IP-based rate limiting protect public and sensitive endpoints.

Standard: WasteRadar ProtocolVerified

Azure Access: Read-Only Architecture

WasteRadar is built on a strict read-only security contract. We analyze cloud waste without the ability to modify, delete, or disrupt your production infrastructure.

Built-In Azure Roles

We only request Reader and Cost Management Reader roles. We reject Contributor, Owner, or custom write permissions.

Zero Mutation Guarantee

Our codebase contains zero ARM write, delete, patch, or restart API calls. WasteRadar performs only read and query operations to discovery endpoints.

Data Isolation: PostgreSQL RLS & Multi-Tenancy

PostgreSQL Row Level Security (RLS)

Every customer table in our PostgreSQL database enforces cryptographic and kernel-level RLS policies. Queries automatically evaluate user organization context, preventing data co-mingling.

Server-Side Organization Resolution

Tenant context is resolved server-side through signed session tokens. Organization IDs cannot be spoofed or overridden by client request parameters.

Encryption: Credentials & Transit

AES-256-GCM Credential Encryption

Azure Service Principal client secrets are encrypted at rest using authenticated symmetric AES-256-GCM encryption before database persistence. Secrets are never exposed to browser clients.

TLS 1.3 Transport Security

All communications between your browser, WasteRadar edge servers, and Microsoft Azure ARM endpoints enforce strict TLS 1.3 with HSTS preloading.

Access Control: Role-Based Permissions (RBAC)

RoleDescriptionPermissions
OwnerFull administrative ownershipBilling, member management, Azure connections, rule creation, exports
AdminFinOps team administratorTrigger scans, manage rules, invite members, export reports
MemberDevOps & Engineering teamView findings, inspect inventory, view dashboards, trigger manual scans
ViewerFinance & Executive auditRead-only view of dashboards, cost reports, and spend summaries

AI & Data Protection Architecture

Microsoft Azure AI data, privacy and security
AI ProviderMicrosoft Azure OpenAI

Customer-facing WasteRadar AI runs through Microsoft Azure's hosted AI infrastructure.

Model Training PolicyZero Customer Training

Microsoft states that prompts and completions for Models sold by Azure are not used to train generative AI foundation models without your permission or instruction.

Tenant & Data BoundaryServer-Side Isolation

Server-side organization resolution, RBAC authorization, and PostgreSQL RLS ensure AI context is strictly isolated per tenant.

Enterprise AI Protection Invariants

  • Credentials Stay Outside AI: Azure client secrets, access tokens, database passwords, and encryption keys are NEVER provided to any AI model.
  • AI Explains. WasteRadar Calculates: Financial calculations, waste run-rates, forecasts, and realized savings remain 100% deterministic and server-side.
  • Zero Direct Azure Mutations: WasteRadar AI operates strictly read-only and cannot stop, delete, or alter customer cloud resources.
  • Prompt Injection Protection: Customer metadata and tags are wrapped as passive untrusted data, preventing instruction overrides.

Auditability: Immutable Activity & Governance Logs

WasteRadar maintains an immutable audit trail of all organization events:

Authentication EventsLogins, invite accepts, password changes
Governance ChangesRule creations, alert threshold updates
Subscription AuditsConnection adds/deletes, manual scan triggers

Third-Party Subprocessors

WasteRadar engages trusted third-party infrastructure providers to deliver our service:

SubprocessorPurpose / RoleLocationData Transferred
Microsoft Azure (Azure OpenAI & ARM)Customer FinOps AI Copilot (Azure OpenAI) & Target Cloud Infrastructure / Cost Management APIsUnited States / Customer Selected Azure RegionsRead-only resource metadata, cost telemetry, and minimized FinOps AI context (zero Azure credentials or secrets)
Supabase Inc.Managed PostgreSQL Database, Auth Engine & PostgreSQL RLSUnited States / AWS Multi-AZEncrypted account profiles, organization memberships, finding records
Cloudflare Inc.Edge Network, DDoS Mitigation, WAF & Encrypted R2 StorageGlobal Edge NetworkTransient HTTPS web traffic & encrypted audit archives
Resend Inc.Transactional System Alerts, Digests & Authentication EmailsUnited StatesCustomer email addresses & system notification text
Google LLCreCAPTCHA Enterprise Bot Defense & Abuse MitigationGlobalInteraction risk assessment telemetry (zero customer data)
DeepSeekIsolated Public Landing-Page Sales Assistant Chatbot (Anonymous Visitors Only)Secure API EndpointAnonymous website visitor sales and FAQ inquiries only (zero customer data, zero Azure metadata, zero tenant context)
Razorpay Software Pvt. Ltd.PCI-DSS Level 1 Compliant Payment Processing (Paid Subscription Tiers)India / GlobalCustomer billing identifiers (zero credit card or CVV data stored on WasteRadar)

Legal & Security Documents

Responsible Disclosure & Incident Response

Odinext values responsible security disclosures. If you discover a potential vulnerability, please report it to our security team immediately:

Security Incident Contact: security@odinext.com

Technical Support: support@odinext.com

RFC 9116 Policy: /.well-known/security.txt

Please include a description of the vulnerability, reproduction steps, and relevant request/response samples. We ask that researchers allow reasonable time for remediation prior to public disclosure.