Track Cloud Cost

Security

Effective Date: May 10, 2026  |  Version: 1.0

Security is foundational to Azure Spend Watch. This page describes the technical and organizational measures we apply to protect your data and the Services.


1. Our Core Security Commitments

🔑

No Azure Credentials

We never request, store, or process your Azure credentials, service principals, or access tokens.

🔒

Webhook-Only Architecture

Azure pushes budget alerts to us. We never pull data from your Azure environment.

🛡️

Encryption at Rest & In Transit

All data is encrypted in transit (TLS 1.2+) and at rest (Azure SQL Transparent Data Encryption).

🏢

Azure-Hosted Infrastructure

The Services run entirely on Microsoft Azure within the West Europe region.


2. Authentication and Access Control

2.1 User Authentication

Authentication is delegated entirely to Microsoft Entra External ID (CIAM). We support:

We never store or handle passwords. Credential management is handled exclusively by Microsoft's identity platform.

2.2 Session Security

2.3 Role-Based Access

All authenticated pages are protected by ASP.NET Core authorization policies. Unauthenticated requests are redirected to the login page.


3. Data Security

3.1 Encryption

3.2 Secrets Management

Application secrets (database connection strings, API keys, signing keys) are stored in Azure Key Vault and accessed via Managed Identity — never hardcoded or stored in configuration files.

3.3 Database Security


4. Webhook Security

Azure Budget Alert webhooks are received and processed with the following controls:


5. Infrastructure Security


6. Third-Party Integrations

Service Purpose Data Shared
Microsoft Entra External IDAuthenticationEmail, name, subject ID
WhatsApp Business APINotification deliveryPhone number, alert message text
PaddlePayment processingEmail, plan selection
Microsoft AzureHosting & storageAll application data (within Azure)

All third-party providers are contractually bound to handle data in compliance with applicable privacy regulations.


7. Incident Response

In the event of a confirmed security breach affecting personal data, we will:


🔍 Responsible Disclosure

If you discover a security vulnerability in Azure Spend Watch, please report it responsibly. Do not publicly disclose the issue until it has been resolved.

Contact us at: [email protected]

We aim to acknowledge reports within 48 hours and resolve confirmed issues within 30 days. We appreciate the security community's efforts to keep our users safe.


8. Contact

Wertheimer Engineering Ltd
21 Sirkin st, Haifa, Israel
[email protected]