Security & Access

Start with the least access needed to produce useful evidence

Revenue Opportunity Radar begins with scoped, read-only evidence collection where the connected system supports it. Agencies and customers choose the sources and resources in scope, and people review the results before they become customer-facing work.

Default Posture

Visibility for review—not standing production control

Read-Only First

Radar evidence workflows are designed to inspect configured sources without modifying code, cloud resources, or production systems.

Selected Scope

Prefer selected repositories, projects, resource groups, and other bounded evidence scopes instead of broad organization-wide access.

Human Review

Findings do not automatically become customer messages, tickets, proposals, or approved delivery work.

Revocable Access

Connected-provider access can be narrowed, rotated, disconnected, or revoked using the controls supported by that provider.
Provider Examples

Access is explicit and source-specific

SourceStarting AccessScope Control
GitHubGitHub App with Contents and Metadata read-only permissionsSelected repositories are the preferred installation mode
Microsoft AzureService principal using the Reader roleMonitor only the subscriptions or resource groups approved for the pilot
Google CloudRead-only service-account accessConnect only approved projects and monitored resources
Azure DevOps PilotTime-bounded personal access token with Code Read permissionSelected repositories in one connected organization

Exact permissions vary by evidence source and enabled workflow. Pilot scope should document the requested permission, selected resources, approver, expiration or rotation plan, and revocation path before activation.

What Radar does

  • Reads the evidence sources and resources explicitly configured for the customer
  • Produces reports, findings, limitations, and opportunity candidates for review
  • Preserves source context so reviewers can understand why a candidate exists
  • Limits application access to the agency and customer scopes authorized for each user

What Radar does not do by default

  • Modify source code, repositories, cloud resources, or production infrastructure
  • Request blanket administrative access as the normal discovery model
  • Send an agent finding directly to a customer without a human-controlled workflow
  • Turn a security signal into proof of exploitation, compliance failure, or guaranteed work

Analysis processing and customer review

InfraSteady stores the connection metadata, selected resource scope, reports, findings, opportunities, and audit records needed to operate the configured workflow. Do not put passwords, tokens, private keys, or other secrets into free-text notes or instructions.

Some enabled workflows use third-party analysis or model tooling. For example, selected repository-analysis workflows use Cursor CLI inside dedicated task containers. The applicable providers, data handling, retention, hosting requirements, and deletion plan should be confirmed for the configured pilot before customer approval.

InfraSteady does not use this page to claim a certification, universal zero-retention policy, or data residency commitment. Those requirements should be handled through the customer security-review and contracting process for the deployment being considered.

Review security before connecting a client

Tell us which evidence sources are in scope and which customer security, processing, retention, or revocation requirements the pilot must satisfy.