Security Model

Customer-controlled, read-only AWS discovery.

AgentOpsMind is designed for evidence collection and reporting. Customers own the AWS role and can revoke access at any time.

No admin access

The recommended role grants read-only discovery permissions and does not allow resource modification.

No source code handoff

Customers receive portals and PDFs. AutoMyx operates and controls the product engine.

No secret collection

The scanner does not intentionally collect S3 object contents, database data, secret values, or private keys.

External ID support

Cross-account access uses a unique external ID for each customer.

Evidence archive

Each scheduled scan can preserve a monthly snapshot and PDF pack.

Revocable access

The customer can remove the role trust relationship or delete the role at any time.