Security review pack
Everything your security review asks.
One page, one answer per question. Access, data handling, transport, logging, and where Reserver stands honestly today, so your review does not stall waiting on an email.
Paste this straight into your own questionnaire: the plain-text version →
Access to your AWS account
What the read-only role can do, and how you stay in control of it.
- What can the read-only role do?
Reserver's read-only role uses 9 named actions, covering RDS, ElastiCache, and EC2. It can read instance shapes, regions, tags, and reservation terms. It cannot start, stop, modify, or delete anything.
- How do you stop another party from assuming our role?
The trust policy requires an ExternalId built from your stack's own GUID. No other party can assume the role, even if they learn its ARN.
- Do you install anything inside our network?
No. Reserver calls AWS APIs from outside your network, using the role you grant. Nothing runs inside your VPC.
- How do we revoke access?
Delete the role from your AWS console. Access ends right away, with no support ticket needed.
- Can we connect one account, or a whole AWS Organization?
Connect each AWS account with its own read-only stack. The same read-only model applies to every account. One-stack AWS Organizations enumeration is planned.
What data Reserver holds
The line between infrastructure metadata and your own data, and where Reserver sits on it.
- What data does Reserver store about our AWS estate?
Reserver stores fleet and reservation metadata only. This covers instance classes, regions, engines, and reservation terms.
- Can Reserver read our databases or cache values?
No. Reserver's read-only role cannot read database contents, cache values, or any application data.
- Do you ever see or store our AWS access keys?
No. Cross-account access goes through the role you grant, using assume-role only. Reserver never sees or stores an AWS access key.
- What happens to the data we paste into a free tool?
Parsing, matching, and pricing all run in your browser. Nothing you paste into a free tool is ever sent to Reserver.
Where it runs
The region Reserver runs in, how organizations stay separate, and who else touches the data.
- Which AWS region does Reserver run in?
Reserver runs in us-west-2, in the United States.
- Is our data isolated from other customers?
Yes. Every record is scoped to your organization. A cross-organization read returns not found, not a permission error.
- Who else can see our data?
Amazon Web Services hosts Reserver and holds your fleet and reservation metadata. No other party touches that data. Google runs analytics on the marketing site only, and never sees fleet or reservation data. The privacy page lists what the site itself collects.
Transport and application security
How traffic is protected in transit, and the security headers every API response carries.
- Is traffic encrypted in transit?
Yes. Every endpoint on api.reserver.io serves over TLS. Caddy terminates TLS in front of the API.
- What security headers does the API send?
Every API response carries five security headers: Strict-Transport-Security (max-age=63072000; includeSubDomains), X-Frame-Options (DENY), Content-Security-Policy (default-src 'none'; frame-ancestors 'none'), X-Content-Type-Options (nosniff), and Referrer-Policy (no-referrer).
- Do you rate limit API requests?
Yes. Every organization is rate limited independently, so one noisy tenant cannot slow the service for another.
Authentication and people
How your team signs in, the three roles they can hold, and what happens when someone leaves.
- What identity provider handles sign-in?
Amazon Cognito. There is no separate password store for Reserver to protect.
- Can anyone sign themselves up?
No. An administrator creates every account. There is no self-signup.
- What roles can a team member hold?
Three: owner, admin, and member. Owner and admin can connect AWS accounts and invite members. Member is read-only.
- What happens when we remove a team member?
Their access to your organization ends immediately. Reserver deletes the membership row, so every request for your data returns not found. Reserver also deletes their Cognito login, which invalidates the refresh token. Their existing access token stays valid until it expires, but it reaches nothing in your organization. Reserver blocks their address from starting a new organization.
Logging and audit
What a request log line contains, how long it is kept, and how a change reaches production.
- What does a request log line contain?
One line per request: method, path, status, duration, and bytes. It reads no header, body, or query string.
- Can we trace one request through the logs?
Yes. Every API response carries an X-Request-Id header, so you can trace that request through a log line.
- How long do you keep request logs?
90 days, capped at 512 MB on the box. Whichever limit is hit first prunes the oldest entries.
- How do you manage changes to the API?
Every change is reviewed and merged through CI. The test suite and the lint gate both must pass before a change ships.
Availability, backup, and continuity
The plain position on backup, replication, and uptime monitoring today.
- Is data encrypted at rest?
Reserver holds no workload data and no AWS credential. The database stores fleet and reservation metadata, plus your team members' email addresses for sign-in and alerts. Reserver makes no disk-level encryption claim today.
- Do you back up the database?Planned
Nightly off-box backup is planned, not live today. If the database were lost, Reserver would rescan your connected accounts and rebuild the metadata.
- Do you replicate the database continuously?Planned
Continuous, seconds-old replication is planned, not live today. It would complement the planned nightly backup, on top of it rather than in place of it.
- Do you monitor uptime, and is there an SLA?Planned
External uptime monitoring is planned, not live today. There is no uptime figure, and no SLA outside an Enterprise agreement.
Compliance and procurement
Certifications, agreements, and how to reach us about a security question.
- Are you SOC 2 or ISO 27001 certified?Planned
Not yet. Reserver is pre-launch, and formal certifications are planned. We would rather say that plainly than claim a badge we do not have.
- Can you sign a Data Processing Agreement?Planned
A formal DPA is planned. It comes with an Enterprise agreement today.
- What comes with an Enterprise agreement?
An Enterprise agreement adds an MSA, a full security review, and a named contact for your SLA questions.
- How do we report a security vulnerability?
Send it through the waitlist form and mark it security. The Reserver team will follow up directly.
This pack is the reference version. Read the fuller story on security, or see exactly what the site and the free tools collect on privacy.
Stop overpaying for a steady fleet.
Reserver is in early access. Join the list and we'll onboard you as capacity opens up. Your first recommendation lands within minutes of connecting.