Customer-authorised
Customers choose the cloud accounts, identities and permission scope available to Acumy. Access can be changed or revoked from the customer's own cloud control plane.
Trust & security
Acumy is built for a sensitive position between infrastructure intent and cloud action. Customers control the connection, the permission scope and the workflows Acumy is authorised to operate.
Security principles
Acumy does not require a shared human administrator account. Cloud access is established through provider-native identities and roles configured by the customer for the capabilities being enabled.
Customers choose the cloud accounts, identities and permission scope available to Acumy. Access can be changed or revoked from the customer's own cloud control plane.
Read-only discovery and authorised lifecycle actions are separate permission paths. Enabling visibility does not automatically grant Acumy permission to change infrastructure.
The core governance model uses cloud resource metadata and Acumy operating records. It does not require access to application payloads to evaluate ownership, policy, budget or lifecycle.
Data boundaries
Acumy needs enough context to identify infrastructure, apply policy, assign accountability and interpret its lifecycle. The core platform does not need to inspect the business information processed inside a customer workload.
Exact data categories, retention requirements and enabled actions are documented during technical evaluation and reflected in the customer's connection scope.
Resource and configuration metadata
Ownership, purpose and tag context
Budget and relevant cost signals
Requests, policy decisions and approvals
Application payloads
Customer database contents
End-user business records
Shared human administrator passwords
Auditability
A cloud event alone rarely explains why an environment was allowed to exist. Acumy retains the governance context around the decision so technical and financial reviewers can follow the Workspace lifecycle.
The initiating person, pipeline, workflow or AI agent.
The controls evaluated and the allow, approval or block outcome.
Who approved a request, what changed and why an exception was granted.
Provisioning, schedule changes, extensions, expiry and retirement activity.
AI workflow / Data Platform
Approval required
Platform owner / 12-hour lease
Automatic lifecycle action
Acumy is currently in beta. Connection scope, permissions and data flows are reviewed with each design partner before access is established. We will not describe a certification or independent control assessment as complete until it has been completed and verified.
Start a security conversationFormal control design, evidence collection and independent examination are part of the assurance roadmap. Acumy is not currently presented as SOC 2 certified.
Security testing, vulnerability management, incident response and customer notification processes form part of production readiness.
Data-processing terms, subprocessor information, retention and deletion commitments will be made available for production security review.
See Acumy in operation