Skip to main content
MilkStraw AI is designed with security as a core principle, ensuring your workloads and data remain isolated and untouched. Our approach is built on isolation and least privilege.

Integration security

Our integration with your AWS environment relies on a secure cross-account IAM role that you deploy.
  • Cross-Account IAM Role: Resides within your AWS management account. If your organization has member accounts, a CloudFormation StackSet creates the same role in each member account, including accounts you add later. If an account leaves your organization, the role stays in that account until you delete its stack.
  • Unique External ID: The role’s trust policy includes a unique external ID known only to Milkstraw.ai, preventing confused-deputy attacks and verifying the call origin.
  • Temporary Credentials: We utilize temporary AWS STS credentials for each API call, avoiding the use of long-lived access keys.

Transfer security

Onboarding and offboarding (accounts with savings) are managed through secure, controlled steps.
  • Invite Through Your Role: After you activate savings, MilkStraw AI sends an AWS Organizations invite to each MilkBox account from your management account, using your cross-account role.
  • Single-Action Acceptance: Milkstraw AI accepts the invite from within the milkbox account; no other permissions are exchanged.
  • Revocable: You can detach a MilkBox at any time by removing the account from your organization in AWS Organizations. MilkStraw AI detects the change within an hour.

Least-privilege policy

MilkStraw AI operates with minimal necessary permissions to perform its function.
  • Least-privilege Role: We use a single least-privilege IAM role.
  • No Workload Changes: The role can’t start, stop, or modify your workloads, such as instances, databases, or networks. It reads cost, usage, and resource metadata. A few write permissions let MilkStraw AI create an AWS Organization for a standalone account, invite MilkBox accounts, and set up S3 Storage Lens. See Permissions for the full list.
  • Limited Scope: The scope is limited strictly to the AWS APIs required for cost analysis and MilkBox management.

MilkBoxes isolated by design

MilkBoxes are engineered to be entirely separate from your existing environment.
  • Zero-Access Architecture: They operate outside your VPCs, IAM roles, and networks.
  • No Data Paths: There are no data paths between MilkBoxes and your workloads—only billing linkage.
  • One-Way Isolation: You also have no access to MilkBoxes, which prevents potential lateral movement risks.

MilkBox removal

When your on-demand capacity or savings needs change, we remove the MilkBox from your organization. After that, the MilkBox has no billing link to your organization.

Underlying safeguards

Our technical operations incorporate standard security best practices.
  • Encryption: All control-plane communication with AWS over the cross-account role uses TLS 1.2 or higher encryption.
  • Auditability: Every AWS API call that MilkStraw AI makes through your cross-account role is logged in your AWS CloudTrail.
  • Best Practices: Our controls are designed in alignment with AWS Well-Architected principles and CIS benchmarks.

Billing security

We use Stripe as our payment gateway. Stripe stores your full payment details, and we keep only display details, such as the card brand and the last four digits.