Security & connection access
Connecting your infrastructure to a compliance tool is an act of trust. Here is exactly what WardBee collects, which permissions it requests, and how you stay in control — in plain language.
Read-only collection
The documented integration setup requests read permissions for collecting configurations and running checks. Scanning does not apply configuration changes. Review the generated policy and avoid granting broader permissions than the connector needs.
Least privilege
Review the permissions of each connection: AWS uses SecurityAudit, ViewOnlyAccess and an explicit Prowler read-only policy; repository connections use scoped read permissions. The Azure preview uses built-in Reader, which allows broader configuration reads than the evidence WardBee collects. GCP is coming soon.
Dedicated, revocable identities
The recommended AWS setup uses a cross-account role with a unique External ID and temporary STS credentials. GitHub and GitLab use dedicated credentials scoped to selected repositories or projects. Stored integration secrets are encrypted with AES-256-GCM and are not returned by integration APIs.
Provable, not just asserted
AWS setup includes reviewable CloudFormation and Terraform. The generated role grants the documented read-only collector and Prowler permissions and requires your unique External ID before WardBee can assume it.
You stay in control
You choose which accounts, regions, and repositories are in scope. Disconnecting removes the integration and its stored secrets. Revoke the provider token or role as well; already-issued temporary credentials and in-flight work can remain valid until expiry or provider-side revocation. Disconnecting is not a promise to erase historical evidence.
Isolated per tenant
Connections are isolated per tenant and enforced server-side — one customer's connection can never be used to read another's account. Provider credentials are stored only for that integration, and authorization is checked again before connection management and sync actions.
Access model by provider
| Provider | Availability | Runtime access | Scope | Provider-side revocation |
|---|---|---|---|---|
| AWS | Available | Cross-account role + External ID | Account and selected regions | Delete role |
| Azure | Preview — activation pending | Azure Lighthouse + built-in Reader; no customer secret keys | One subscription or selected resource groups | Remove the Lighthouse assignment in Azure |
| GCP | Coming soon | No credentials requested | — | — |
| GitHub | Available | GitHub App where configured; fine-grained PAT fallback. Metadata and Administration read; Contents optional. Opt-in Software Delivery additionally requests Deployments read for its approved repository. | Selected repositories | Uninstall App or revoke token |
| GitLab | Available | Fine-grained project read permissions; Reporter + read_api fallback. Source reads optional. | Selected projects | Revoke token |
GitHub App connections verify the installation and issue repository-scoped tokens that expire within one hour. GitHub personal token permissions are confirmed by you because GitHub does not expose the complete grant to WardBee. GitLab token scopes and expiry are checked with the provider. Legacy read_api grants can read more data than WardBee collects; prefer fine-grained project permissions. Source scanning is off until you opt in.
Preview — not generally available
Azure read-only preview
Azure support is prepared for a limited preview. Activation requires provider-side validation before a workspace can connect. The setup uses Azure Lighthouse: your administrator reviews an ARM or Terraform template naming WardBee’s identity and grants Reader on one subscription or selected resource groups. You do not share customer passwords, application secrets or storage keys with WardBee.
- What the preview checks
- Storage account encryption settings and subscription activity log export configuration. Resource-group-only access leaves subscription log checks unavailable. A configured export does not prove log delivery or retention.
- Access boundaries
- Reader permits broad resource configuration reads within your approved scope. The collector reads configuration, not blob or file contents, Key Vault secret values or log bodies. It requests no Entra directory consent. Entra MFA enforcement and wider Azure scanner coverage are outside this preview.
- Evidence and revocation
- Incomplete or unreadable evidence cannot produce a passing result. Disconnecting stops new collection and excludes the connection’s evidence from current checks. Remove the WardBee Lighthouse assignment under Service providers in Azure to revoke the grant; Azure propagation and in-flight requests can delay effective revocation.
What is collected and retained
- — Cloud configuration and repository settings become timestamped evidence snapshots.
- — Findings, evidence digests, and decision history support reports and later review.
- — Source scanning is opt-in. Repository scans can inspect selected source code for insecure patterns, exposed credentials, and infrastructure configuration. Access is not limited to Terraform files.
- — Product workflows accept release information, SBOMs, and supporting evidence you upload.
Explore your framework priorities before connecting anything with the compliance advisor . This self-reported exercise does not inspect your infrastructure or verify controls.
AI provider and data handling
WardBee’s AI features send text to Anthropic Claude through Amazon Bedrock. AI explains findings, suggests remediation, drafts text, and reviews CRA questionnaire consistency. Deterministic checks determine control states; AI cannot mark a control as passed.
What each AI request contains
- Finding explanations and remediation
- The workspace identifier, framework and control or integration type, and the evidence summary or failure context submitted with the request. Remediation context can include finding text and framework guidance.
- Policy drafts and custom control mapping
- The organization profile and policy type, or the custom control text and target framework you submit.
- CRA questionnaire review
- Product key, name, scope and classification; questions, answers and explanations; related control identifiers and evidence states; and approved document sections, titles and digests. This request includes document references, not document bodies, raw SBOM files or repository contents.
Free-text inputs are sent as supplied. Do not include secrets, credentials, source code or sensitive personal data in AI inputs; automatic removal is not guaranteed. AI processing locations, provider retention and model-training terms still need to be confirmed for your workspace before you submit sensitive data.
Hosting, retention, and subprocessors
A verified production hosting region, complete subprocessor list, and fixed data retention schedule are not published on this page. Before connecting production data, request these details for your workspace: hosting and backup regions, the full provider list (including AI, payments and email), evidence and backup retention periods, and the deletion turnaround. The AI request contents above describe the application’s behavior; they do not establish production residency or contractual retention terms.
Scan-pack validity is not a data deletion deadline. Disconnecting an integration removes its stored credentials; historical evidence, reports, and decision records are separate. Contact us to agree the retention and deletion requirements for that data.
Request data-handling detailsBefore granting access
Review the IAM template or token scopes in the connection flow. AWS, GitHub, and GitLab are supported today. Azure preview requires activation and is not generally available; GCP is coming soon. We do not publish an independent ISO 27001 certificate or SOC 2 report for WardBee on this site. Supporting a framework in the product does not certify WardBee or your organization against it.
For data handling and deletion requests, read our privacy policy. To discuss security requirements or report a concern, contact the WardBee team. Do not send credentials or raw sensitive evidence in an initial message.