WasteRadar Trust Center
Security and transparency built into the WasteRadar architecture. Comprehensive disclosures regarding tenant isolation, read-only IAM scopes, encryption at rest, and infrastructure subprocessors by Odinext.
Verified Security Controls Status
Designed for enterprise security requirementsRead-Only Azure Architecture
Operates exclusively under Reader and Cost Management Reader IAM roles. Zero write, start, stop, or delete capabilities.
PostgreSQL Row-Level Security (RLS)
Hardware and logical separation enforced at database level with org_id context filtering on all queries.
AES-256-GCM & TLS 1.3
Credentials, OAuth tokens, and backups encrypted at rest with AES-256-GCM. All transit encrypted via TLS 1.3.
Role-Based Access Control (RBAC)
Strict separation of Owner, Admin, Member, and Viewer permissions across all workspaces and billing settings.
Context Minimization & Secret Redaction
All secrets, access credentials, and Azure tokens are stripped prior to LLM inference. Calculations remain deterministic.
Formula Injection & XSS Sanitization
CSV exports sanitize formula triggers (=, +, -, @). React JSX encoding and Zod schema validations active.
Immutable Security Audit Trail
All authentication events, scans, exports, and permission mutations logged to dedicated audit tables.
Sliding-Window Rate Limiting & Bot Defense
Google reCAPTCHA Enterprise and IP-based rate limiting protect public and sensitive endpoints.
Azure Access: Read-Only Architecture
WasteRadar is built on a strict read-only security contract. We analyze cloud waste without the ability to modify, delete, or disrupt your production infrastructure.
Built-In Azure Roles
We only request Reader and Cost Management Reader roles. We reject Contributor, Owner, or custom write permissions.
Zero Mutation Guarantee
Our codebase contains zero ARM write, delete, patch, or restart API calls. WasteRadar performs only read and query operations to discovery endpoints.
Data Isolation: PostgreSQL RLS & Multi-Tenancy
PostgreSQL Row Level Security (RLS)
Every customer table in our PostgreSQL database enforces cryptographic and kernel-level RLS policies. Queries automatically evaluate user organization context, preventing data co-mingling.
Server-Side Organization Resolution
Tenant context is resolved server-side through signed session tokens. Organization IDs cannot be spoofed or overridden by client request parameters.
Encryption: Credentials & Transit
AES-256-GCM Credential Encryption
Azure Service Principal client secrets are encrypted at rest using authenticated symmetric AES-256-GCM encryption before database persistence. Secrets are never exposed to browser clients.
TLS 1.3 Transport Security
All communications between your browser, WasteRadar edge servers, and Microsoft Azure ARM endpoints enforce strict TLS 1.3 with HSTS preloading.
Access Control: Role-Based Permissions (RBAC)
| Role | Description | Permissions |
|---|---|---|
| Owner | Full administrative ownership | Billing, member management, Azure connections, rule creation, exports |
| Admin | FinOps team administrator | Trigger scans, manage rules, invite members, export reports |
| Member | DevOps & Engineering team | View findings, inspect inventory, view dashboards, trigger manual scans |
| Viewer | Finance & Executive audit | Read-only view of dashboards, cost reports, and spend summaries |
AI & Data Protection Architecture
Microsoft Azure AI data, privacy and security↗Customer-facing WasteRadar AI runs through Microsoft Azure's hosted AI infrastructure.
Microsoft states that prompts and completions for Models sold by Azure are not used to train generative AI foundation models without your permission or instruction.
Server-side organization resolution, RBAC authorization, and PostgreSQL RLS ensure AI context is strictly isolated per tenant.
Enterprise AI Protection Invariants
- ✓Credentials Stay Outside AI: Azure client secrets, access tokens, database passwords, and encryption keys are NEVER provided to any AI model.
- ✓AI Explains. WasteRadar Calculates: Financial calculations, waste run-rates, forecasts, and realized savings remain 100% deterministic and server-side.
- ✓Zero Direct Azure Mutations: WasteRadar AI operates strictly read-only and cannot stop, delete, or alter customer cloud resources.
- ✓Prompt Injection Protection: Customer metadata and tags are wrapped as passive untrusted data, preventing instruction overrides.
Auditability: Immutable Activity & Governance Logs
WasteRadar maintains an immutable audit trail of all organization events:
Third-Party Subprocessors
WasteRadar engages trusted third-party infrastructure providers to deliver our service:
| Subprocessor | Purpose / Role | Location | Data Transferred |
|---|---|---|---|
| Microsoft Azure (Azure OpenAI & ARM) | Customer FinOps AI Copilot (Azure OpenAI) & Target Cloud Infrastructure / Cost Management APIs | United States / Customer Selected Azure Regions | Read-only resource metadata, cost telemetry, and minimized FinOps AI context (zero Azure credentials or secrets) |
| Supabase Inc. | Managed PostgreSQL Database, Auth Engine & PostgreSQL RLS | United States / AWS Multi-AZ | Encrypted account profiles, organization memberships, finding records |
| Cloudflare Inc. | Edge Network, DDoS Mitigation, WAF & Encrypted R2 Storage | Global Edge Network | Transient HTTPS web traffic & encrypted audit archives |
| Resend Inc. | Transactional System Alerts, Digests & Authentication Emails | United States | Customer email addresses & system notification text |
| Google LLC | reCAPTCHA Enterprise Bot Defense & Abuse Mitigation | Global | Interaction risk assessment telemetry (zero customer data) |
| DeepSeek | Isolated Public Landing-Page Sales Assistant Chatbot (Anonymous Visitors Only) | Secure API Endpoint | Anonymous website visitor sales and FAQ inquiries only (zero customer data, zero Azure metadata, zero tenant context) |
| Razorpay Software Pvt. Ltd. | PCI-DSS Level 1 Compliant Payment Processing (Paid Subscription Tiers) | India / Global | Customer billing identifiers (zero credit card or CVV data stored on WasteRadar) |
Legal & Security Documents
Privacy Policy
How Odinext and WasteRadar collect, process, and protect customer data.
Terms of Service
Commercial and operational service terms, SLAs, and usage policies.
Azure Permissions & IAM Architecture
Detailed specification of Reader and Cost Management Reader IAM roles.
RFC 9116 Security Disclosure (security.txt)
Standardized vulnerability disclosure policy, PGP keys, and contacts.
Responsible Disclosure & Incident Response
Odinext values responsible security disclosures. If you discover a potential vulnerability, please report it to our security team immediately:
Security Incident Contact: security@odinext.com
Technical Support: support@odinext.com
RFC 9116 Policy: /.well-known/security.txt