Security & data

Where your data lives, who can see it, and how it's used.

CostCtrl handles financial and operational data from operationally complex businesses. This page exists so your IT and compliance reviewer can answer their questions without a follow-up call.

Where your data lives

Your data is hosted in the EU (on AWS, in Ireland) and separated by company, so your team only ever sees your own organisation's data. It's encrypted at rest with AES-256 and encrypted in transit with TLS 1.2.

AI and your data

CostCtrl never uses customer data to train AI models. The allocation engine is deterministic and fully auditable: it computes the numbers, and that calculation is always the source of truth. The AI layer that interprets those results runs inside our own AWS environment (Amazon Bedrock), so your data stays within the same boundary as the rest of CostCtrl. CostCtrl's own AI features never send your data to an outside provider. Connecting your own AI through the MCP server is a separate, opt-in choice, described under data handling below.

Access controls

Your models, scenarios, and reports are scoped to your company, so people only ever access their own organisation's data.

Explainability

Because the engine is deterministic, every number it produces traces back to the rule and the inputs that produced it. No black-box figures: a result we can't explain is not a result we'd put in front of you.

Data handling

Data handling principles.

We don't sell your data and we don't share it. It's held in the EU and separated by company, so it isn't commingled with anyone else's. If you have specific data-residency, processing, or single sign-on requirements, talk to us and we'll tell you honestly what we can support today and what's on the way.

The MCP server and your own AI. CostCtrl can expose your model through an MCP server: a standard port that lets an AI you already use (Claude, ChatGPT, Copilot or your own) read results, create scenarios, change inputs and run the calculation. Nothing leaves CostCtrl through that port until you connect something to it. You decide whether the port is opened and which provider is connected. What that provider does with the results it receives is governed by your agreement with them, not by ours, so read their terms before you connect one, and ask us and we will walk through what the port exposes. The engine's rule holds on every call: the agent changes inputs, the engine computes the figures, and the calculation inside CostCtrl remains the source of truth.

Talk to us about security

Got a question your reviewer needs answered?

We're happy to complete a vendor security questionnaire or walk your team through our architecture. Send a note and we'll respond within one business day.

Contact our team

Want to see how this works in practice?

Book a 30-minute call and we'll walk through both the product and the security architecture in one go.

Book a 30-minute call