1 Who we are
Infrox is operated by BluNorth Technologies LLC, a limited liability company organised in Wyoming, United States. In this policy "we", "us" and "Infrox" mean BluNorth Technologies LLC.
This policy covers the marketing site at infrox.io and the Infrox application at app.infrox.io. It does not cover your own AWS accounts, which remain entirely under your control, or third-party sites we link to.
2 Information we collect
Account information
To create an account you provide an email address and a password. That is the whole sign-up form — we do not ask for your name, company, phone number or job title. Authentication is handled by Amazon Cognito; your password is stored by Cognito as a hash and is never visible to us. If you enable two-factor authentication we store the associated TOTP registration, not any code.
If you sign in with Google instead, Google tells us your email address and basic profile information for the account you chose. We do not receive your Google password, and we do not gain access to any other Google service.
If you invite colleagues to a workspace, we store the email addresses you enter in order to send the invitation and to show who has access.
Billing information
Payments are processed by Stripe. Card numbers are entered on Stripe's own pages and never reach our servers — we neither receive nor store them. What we keep is the Stripe customer and subscription identifiers, your plan, its status and renewal date, and your invoice history as Stripe reports it.
Assessment data from your AWS accounts
When you connect an AWS account, you create an IAM role in that account that grants Infrox read-only access. We then read configuration metadata in order to run the checks and produce your report:
- your AWS account ID, the regions you scan, and resource identifiers such as ARNs, resource names and tags;
- configuration attributes of the resources we check — for example whether a bucket blocks public access, whether a database has backups enabled, whether an instance is in more than one availability zone;
- the findings we derive from that metadata: a check identifier, a risk level, a short description and a recommended fix.
The findings and the generated report PDFs are stored so that you can re-open a past report and see how your posture has changed over time.
Usage and technical data
Our infrastructure records ordinary server logs — IP address, browser user agent, request path and timestamp — which we use to operate the service, investigate faults and detect abuse. Within the application we record activity needed to run your account: scan history, quota counters, schedules and notification state.
Correspondence
If you email us or submit an enquiry through the app, we keep that message and our reply so we can answer it and follow up.
3 What we never collect
The boundaries below are enforced by the permissions your role grants us, not by policy alone. The role attaches AWS-managed read-only permissions — a describe-and-list grant. In practice that means:
- We cannot read the contents of your data. No object bodies from S3, no rows from your databases, no application data of any kind.
- We cannot read secret values. No Secrets Manager secret values, no SSM parameter values, no environment variables carrying credentials.
- We cannot change anything. The role grants no write, create, modify or delete permission. Every fix we recommend is applied by you, in your own account, at a time you choose.
- We never hold your AWS access keys. Access works by cross-account role assumption gated by an external ID unique to your tenant, so there is no long-lived credential of yours for us to store or lose.
You can revoke our access at any time by deleting the role stack in your AWS account, or by removing the connected account in Infrox. Revocation is immediate and does not depend on us.
4 How we use information
We use the information above only to run the service:
- to authenticate you and keep your workspace separate from every other tenant;
- to run the checks you request and produce reports, scores, trends and remediation plans;
- to bill the plan you chose, enforce its quotas, and tell you when you are near a limit;
- to send you the account and service email described below;
- to keep the service secure, debug failures, and prevent abuse;
- to comply with law and to enforce our Terms of Service.
We do not sell your personal information, and we do not share it with advertisers or data brokers. We do not use your assessment data to build products for anyone else, and we do not disclose one customer's findings to another.
We send transactional email only — verification and password-reset codes, scan results and digests you asked for, quota and billing notices. We do not send marketing email to customers who have not asked for it, and every optional message can be turned off in the app.
5 AI analysis, and exactly what it receives
Infrox can add a narrative layer to a report — an executive summary, correlation across findings and a suggested order of work. That step calls the Anthropic API, and because it sends data outside our own infrastructure we describe it precisely rather than generically.
What is sent for a single report: your AWS account ID, the region, the scan timestamp, the pillars in scope, and, for each non-passing finding, its check identifier, risk level, title, resource type, resource identifier, detail text and the recommended fix. For a fleet report, the group label you chose, the fleet score and account count, and per account its label, score, critical and high counts and weakest pillar, plus the risks shared across accounts. A fleet report sends no account IDs and no resource identifiers.
What is not sent: your email address, your billing details, your password or two-factor secrets, your report PDFs, or any resource content — only the metadata-derived findings listed above.
- The step is optional. A scan can be run without it, and if your AI quota is exhausted the scan still completes and the report is produced without the narrative.
- Your scores never depend on the model. Risk levels and the WAR score come from the checks themselves and are identical whether or not the AI step ran.
- Content sent to the Anthropic API is processed under a commercial agreement that does not permit it to be used to train models.
6 Service providers
We use a small number of providers to run Infrox. Each receives only what its function requires.
| Provider | Purpose | What it receives |
|---|---|---|
| Amazon Web Services | Hosting, database, file storage, authentication (Cognito) | All service data, held in the US East (N. Virginia) region |
| Anthropic | Optional AI narrative on a report | The findings payload described in section 5 |
| Stripe | Payments and subscription management | Your email, plan and payment details you enter on Stripe's pages |
| Resend / Amazon SES | Transactional email delivery | Your email address and the contents of that message |
| Optional "Sign in with Google" | Only used if you choose it; Google tells us your email and basic profile |
We may also disclose information if the law requires it, or to establish, exercise or defend a legal claim. If we are ever involved in a merger or acquisition, your information may transfer as part of that transaction, subject to this policy.
8 Retention and deletion
We keep your data for as long as your account is open, because the product's value comes from comparing today's posture with the last scan. You control the rest:
- Delete an individual scan or report and its stored findings and PDF go with it.
- Remove a connected AWS account and we stop reading it. Our access also ends the moment you delete the role stack on your side.
- Delete a workspace and we purge its data partition — the connected accounts, scans, findings, schedules, branding and report PDFs belonging to it.
- Close your account by writing to support@infrox.io and we will delete your account and its data.
Two exceptions, both ordinary: billing and tax records are retained for the period the law requires, and routine backups and server logs age out on their own schedule rather than being erased on request.
9 How we protect it
- Traffic is encrypted in transit with TLS, and data at rest in our database and file storage is encrypted.
- Each tenant's data is stored in its own partition and every request is scoped to the signed-in tenant.
- Access to your AWS accounts is read-only, assumed per scan, and gated by an external ID unique to your tenant — with the trust scoped to named principals rather than the whole account.
- Two-factor authentication is available on your account, and we recommend turning it on.
- Administrative access to production is limited to the people who need it, and privileged actions are logged.
No system is perfectly secure, and we will not pretend otherwise. If we become aware of a breach affecting your data, we will notify you without undue delay.
10 Your choices
You can, at any time:
- see and correct your account details in the app;
- export a report as a PDF, and download your scan history;
- delete scans, reports, connected accounts and workspaces, as described above;
- turn off optional email, including scheduled-scan digests;
- revoke our access to any AWS account by deleting the role stack in your account.
To request a copy of the personal information we hold about you, to have it corrected, or to have your account deleted, email support@infrox.io. We will respond within 30 days, and we may need to verify that the request comes from the account holder.
11 Children
Infrox is a tool for businesses and is not directed at children. We do not knowingly collect information from anyone under 18. If you believe a child has given us personal information, write to support@infrox.io and we will delete it.
12 Changes to this policy
We will update this page when the service changes. The "last updated" date at the top always reflects the current version. If a change materially reduces your privacy — a new category of data, or a new purpose for existing data — we will tell account holders by email before it takes effect, rather than relying on you to re-read this page.
13 Contact us
Privacy questions, data requests and anything else: support@infrox.io. It is one mailbox and it is monitored — mark a data request as such in the subject line and it will be routed.
BluNorth Technologies LLC, Wyoming, United States.
Also worth reading: Terms of service