Security at CDK Insights
CDK Insights is built by Instance Labs Ltd (UK company no. 17053174). We treat your infrastructure code as some of the most sensitive data we could ever touch — so by default, we never touch it.
Last reviewed: June 2026
Does my source code leave my machine?
No — not for static analysis. The CDK Insights CLI synthesises and scans your CDK application entirely on your own machine (or your CI runner). Your CDK source code, your synthesized CloudFormation, and your findings never leave that environment for the free static scan, and no account is required to run it.
AI-powered analysis is opt-in. When you enable it, we send the synthesized CloudFormation — not your CDK source — to our analysis service for evaluation. That template is processed transiently to generate recommendations and is not retained beyond the duration of the request. The resulting insights, recommendations, and scores are stored in your account so you can review them on your dashboard.
Where is my data stored?
Our platform runs on Amazon Web Services in the EU West (London) region (eu-west-2). Hosting, authentication, the database, and AI processing all run within that region. Some third-party providers (for example Stripe for payments) process data elsewhere under appropriate transfer safeguards — see “Sub-processors” below and our Privacy Policy.
Encryption
- In transit: TLS 1.2+ for all customer-facing endpoints and inter-service calls.
- At rest: AWS-managed KMS encryption for all durable stores, including DynamoDB, S3, and Cognito.
Authentication & access control
User accounts are managed through Amazon Cognito. Staff access to production systems follows the principle of least privilege, and multi-factor authentication is enforced for administrator accounts across our AWS Console, GitHub, and Stripe.
How is my code handled during AI analysis?
AI analysis uses Amazon Bedrock within our AWS environment. Only the redacted, synthesized CloudFormation needed for the analysis is sent to the model, it is processed transiently, and it is not retained by the model provider beyond the duration of the request. You choose which model runs (and therefore the cost/depth trade-off) per scan.
Data retention & deletion
- Account data is kept for the life of your account. On deletion, a 7-day soft-delete grace period applies (you can cancel deletion from your preferences page); after that we hard-delete or anonymise.
- Technical logs (AWS infrastructure logs) are retained for up to 30 days.
- Database backups (DynamoDB point-in-time recovery snapshots) may retain data for up to 35 days before rotation, encrypted at rest.
- Payment records are archived by Stripe for 6 years to meet HMRC accounting-record requirements; personal details are scrubbed.
Full detail is in our Privacy Policy.
Sub-processors & third parties
We use a small set of vetted sub-processors — AWS (hosting, auth, database, Bedrock AI), Stripe (payments), Sentry (error tracking), and Google Analytics. A full, versioned list is published at instancelabs.dev/sub-processors, and we give at least 30 days’ notice of material changes.
Monitoring & error tracking
We monitor our services for availability and errors. Our error tracker (Sentry) scrubs request bodies, authentication headers, cookies, and email/IP fields before any event leaves our infrastructure, so diagnostic data does not carry your credentials or personal data.
Vulnerability & dependency management
We keep dependencies current, scan them for known vulnerabilities, and apply security patches promptly. We run an annual security review covering account hygiene, dependency scanning, and sub-processor due diligence.
Payment security
Payments are processed by Stripe. We never receive or store your full card details. Stripe operates in the US under Standard Contractual Clauses; see the Stripe Privacy Policy.
Data protection & compliance
We operate under UK GDPR. Business customers can enter into our Data Processing Agreement, which covers sub-processors, international-transfer safeguards (UK IDTA / SCCs), retention, and our technical and organisational measures. We support data subject access and erasure requests as described in the Privacy Policy. Our security programme follows the practices described on this page.
Incident response
We monitor for security incidents and respond promptly. Where an incident affects your personal data, we follow the notification obligations set out in our DPA and applicable law.
Responsible disclosure
If you discover a vulnerability, please report it to security@cdkinsights.dev. We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure, and we will not pursue action against good-faith research that respects user privacy and avoids service disruption. For any other security questions, reach the same address.