Held in your environment
Provider credentials, the connector’s policy and the authority to approve actions.
Security & deployment
Administrative access deserves a clear trust model. SpendAssure’s architecture separates the service that proposes a change from the connector authorised to carry it out.
The connector resolves provider credentials from environment variables or mounted files on the customer’s host. Its wire protocol has no credential field. Usage observations and control proposals are separate from provider secrets.
The connector initiates outbound connections; it does not open an inbound listening port. SpendAssure is outside the inference path, so prompts and completions do not pass through it.
Provider credentials, the connector’s policy and the authority to approve actions.
Resource identifiers, usage quantities, time windows, observed control state, connector health and proposal outcomes.
Usage metadata can still be sensitive. Per-user identifiers and data-minimisation requirements must be reviewed for the proposed deployment. Production pseudonymisation is not yet implemented.
The connector evaluates each proposal against a policy file on its host. Reductions respect configured floors. Increases require local authorisation. Destructive actions require local approval or a locally pre-authorised emergency rule. Irreversible actions are denied.
A compromised service could still propose harmful actions within a permissive local policy. A compromised connector host could expose the privileges of its provider credentials. Least privilege, host security and careful policy review remain necessary.
Policy signing and a complete local approval workflow are not yet available. The current foundations check policy rules and retain proposals that need approval.
The planned first delivery puts both the core service and the connector on customer infrastructure. In that setup, SpendAssure does not need to hold customer usage data.
A hosted core with a customer-side connector is a later option, subject to customer demand and production readiness. It would receive usage metadata, while credentials remain local. The same local approval boundary applies to both designs.
Provider controls already configured remain with the provider if SpendAssure is unavailable. New observations, reviews and control changes depend on the management service being reachable. Incorrect control writes can still disrupt service.
We do not claim certification, DORA exemption or general regulatory compliance. Security and procurement requirements are part of the scope agreed with each founding customer.
This marketing site uses Google Analytics to understand visits and page usage. The Google tag sends website measurement data to Google. See how Google uses information from sites that use its services. Fonts are self-hosted, and there is no contact-form database. Ordinary hosting access logs may contain connection information such as an IP address and requested URL.
Contact links open your email application. If you choose to email us, your message and contact details are shared through email so we can respond to your enquiry. Please do not send credentials, prompts or other sensitive production data.
For questions about your enquiry or to request its deletion, contact hello@spendassure.com.
Let’s start with your AI estate
Help shape SpendAssure around the spending controls, approvals and reporting your team actually needs.
Talk about early access For finance, FinOps and platform teams.