Evaluate Infralign
Security and data flow
A short pre-sales summary of what enters Infralign, where it goes, and how access is stopped — with links to the full reference pages.
Data moves in one direction: out of your Azure tenant, through a read-only service principal, into an EU-hosted warehouse. Nothing writes back. The authoritative detail is in security and data handling and the annotated data-flow diagram.
The flow in six steps
Section titled “The flow in six steps”- In your Azure tenant, you create an Entra service principal and choose which subscriptions are in scope.
- Collection is read-only, and no role can change a workload: Cost Management Reader covers cost details, and Reader covers resource inventory, configuration metadata, Advisor signals, Monitor metrics, and Activity Log context.
- The nightly pull copies the agreed billing and control-plane metadata into Infralign’s warehouse in Microsoft Azure, Italy North (EU). Each tenant is isolated at the storage and query layer.
- An Infralign practitioner reviews candidate findings, and your team supplies business and architecture context.
- Your team decides whether and how to implement a finding through its own change process. There is no automated production-remediation step.
- Where a change is implemented, Infralign compares landed billing data against the agreed baseline.
What is collected
Section titled “What is collected”Collected:
- Azure billing and amortised cost records.
- Subscription, resource-group, and resource identifiers.
- Resource type, SKU, location, tags, and control-plane configuration metadata.
- Advisor recommendations, selected Monitor utilisation metrics, and Activity Log change context.
Never collected: database rows, VM filesystems, application payloads, Key Vault secret values, and source repositories. The roles cannot reach them.
Stopping access
Section titled “Stopping access”Remove the two role assignments or delete the app registration and new collection stops the same moment, with nothing required from Infralign. On offboarding, the collected data is deleted within 30 days, confirmed in writing.
Where to read the detail
Section titled “Where to read the detail”Security and data handling · How your data flows · Why Reader, and what it cannot see · Data sources · Available today versus roadmap
Next: Exact permissions — the two roles, their caveats, and what is never requested.