Security & Trust
We Only Read.
We Encrypt Everything.
Lizrd connects to your cloud and code read-only, seals every credential with strong encryption, and never changes your infrastructure without your explicit approval.
How We Keep You Safe
Read-Only by Design
You approve a least-privilege role. Lizrd reads, never writes โ no modify, no delete.
Encrypted End to End
Every credential is sealed with AES-256-GCM envelope encryption and rotation-ready keys.
Isolated per Organization
Strict per-tenant isolation at the database layer โ your data never crosses tenants.
Nothing Without Approval
Every change is proposed, and applied by you โ never auto-run.
We Read Less Than You Think
Config, usage, and cost metadata โ never your application or customer data.
Revoke in One Move
Remove the role or token and Lizrd loses all access immediately โ no lingering credentials.
The exact scope
What Lizrd Accesses โ and What It Doesn't
โ Reads (read-only)
- โ Cloud resource inventory & configuration
- โ Utilization metrics & real, billed cost
- โ Repository & infrastructure-as-code metadata
โ Never touches
- โ Your application data or customer data
- โ Source secrets or environment variables
- โ Any write, delete, or modify action
Revoke anytime โ remove the role or token and Lizrd loses all access immediately.
More security questions? See the FAQ โ Found a vulnerability? Email hello@lizrd.ai.
See It Safely
Connect read-only in minutes and watch the optimizations surface โ nothing changes until you say so.