Skip to content
MarginMeter

Security and data handling

How MarginMeter protects your data: read-only provider access, KMS-encrypted credentials, AWS cross-account roles, PostgreSQL row-level security, export and deletion.

Provider access is read-only

  • Stripe: a restricted key with read permissions.
  • OpenAI and Anthropic: admin keys used only to read usage and cost reports.
  • AWS: a cross-account IAM role with a unique external ID that can only read Cost Explorer. No access keys are stored.

Credentials are encrypted

Provider secrets are encrypted with AWS KMS envelope encryption, bound to your workspace and connection, and decrypted only in background workers when a sync runs. They are never logged or sent to the browser.

Workspaces are isolated

Every tenant-owned table in our database enforces PostgreSQL row-level security keyed on the workspace, and automated cross-tenant isolation tests block every release. Raw provider payloads are stored in S3 under per-workspace prefixes with lifecycle expiry.

Your data, your control

Export your data as CSV at any time. Deleting a workspace revokes credentials, purges stored payloads and removes database rows in stages; deleting your account removes your identity and memberships.

Numbers are deterministic

Financial figures are calculated by code from provider data — never generated by AI.