Deplium pays your bills. It does not touch your systems.

The security model follows from the billing model: Deplium holds payer and billing-owner roles, receives usage metadata, and nothing else.

Access to your accounts.

What Deplium sees

Billing and usage metadata from each provider: line items, quantities, regions, tags. Deplium does not receive application data, logs or database contents.

What Deplium cannot do

Deploy, change, read or delete resources in your accounts. Payer and billing-owner roles carry billing permissions only. Any review that needs more is a separate, time-boxed, read-only grant you approve.

Credentials

Where a provider requires an API token for usage export, it is scoped to billing read, encrypted at rest with a key held outside the database, and can be revoked from your dashboard or the provider at any time.

The Deplium dashboard.

Sign-in

Passwords are hashed with bcrypt; SAML and OIDC single sign-on on Managed and Enterprise. Sessions are short-lived and revocable.

Audit log

Every billing change, budget edit, provider connection and sign-in is recorded with actor, time and origin. Retained ninety days on Pooled, two years on Managed and Enterprise.

Hosting

The Deplium dashboard runs on Vercel with a Neon Postgres database in the United States. Sub-processors are listed on the legal page and customers are notified of changes.

Payments

Card details never reach Deplium; Stripe handles them. Bank transfer customers pay against the statement.

Compliance and paperwork.

Provider documents

SOC 2 reports, ISO certificates and DPAs from each provider are collected under Deplium's agreements and available to Managed and Enterprise customers from the dashboard.

Data residency

Deplium documents, per provider and region, where your data sits and under which legal basis it is processed. EU-only footprints are supported via Hetzner, Scaleway, OVHcloud and EU regions of the hyperscalers.

Deplium's own posture

Deplium is preparing its SOC 2 Type I report. Penetration test summaries and the security questionnaire are available under NDA on request.

Data processing agreementSub-processorsEnterprise access

Deplium