Security & Trust
How GoNinja accesses your cloud โ and why it can never change anything.
Read-only by architecture, not by promise
- You create the access role, in your own account โ using a CloudFormation template we give
you. It grants AWS's managed
SecurityAuditpolicy: read-only visibility, no write permissions of any kind. - A unique External ID per user โ the role can only be assumed together with your personal External ID, which prevents anyone else (including other GoNinja customers) from ever reaching your account through us.
- Temporary credentials only โ each scan uses short-lived STS credentials. We never hold long-lived keys to your account, and we never see your passwords or secrets.
- Revoke in one click โ delete the role in your account and GoNinja's access ends instantly. You are always in control.
Your data
- Sydney, always โ everything is stored in the AWS Sydney region (ap-southeast-2). Data never leaves Australia.
- Encrypted โ TLS in transit, encryption at rest for scan results and generated Terraform.
- Secret values are never read โ checks are metadata-based. Where a check involves a secret (for example, detecting a key stored in the wrong place), only its name and age are examined, never its value.
- Payments โ handled entirely by Stripe; card details never touch GoNinja.
Your account
- Sign-in is managed by AWS Cognito (passwords hashed, never visible to us).
- Two-factor authentication (TOTP) is available for all accounts and required on paid accounts.
Reporting a vulnerability
If you believe you've found a security issue in GoNinja, please email support@goninja.com.au with the details. We investigate all reports promptly and appreciate responsible disclosure.
Contact us
Support & general enquiries: support@goninja.com.au
We reply within 2 business days (Sydney time), usually much faster.