Is the cloud connection safe? What exactly can Cybermatic access?
Every connection is read-only by construction — that principle holds across all twenty integrations. Cloud accounts use read-only roles (an AWS IAM read-only role, Azure's built-in Reader, GCP's Viewer). Identity providers use read-only API scopes. Security and asset platforms use their least-privileged read credentials — runZero's export-only token, a Qualys Reader account, two read permissions for Defender. Cybermatic can list and describe, but cannot create, modify, or delete anything, anywhere. You can review the exact permissions before approving (every setup guide shows them), and revoke access at any time from your own console — you stay in control.