SECTION 06 / TRANSPARENCY
Documented Limitations
We prefer transparent, upfront statements of scope over generic claims. Here is the honest, auditable list of Costframe’s current capabilities, active integrations, and cloud system boundaries.
GCP Ingestion & Parity
Live GCP resource-level scanning is not yet at parity with Azure. Cost ingestion on GCP is currently billing-export based only, which requires an active BigQuery billing dataset configuration.
AWS & GCP Multi-Cloud Support
AWS and GCP connections are readiness-gated provider paths. They support read-only, approved detector sets and background processing only where the connection validates and the workspace plan allows scheduling.
Grounded, Low-Variance AI Summaries
Our AI summaries are grounded in structured, locally compiled findings and generated at a low sampling temperature to minimize wording variance. They cannot invent resources, fabricate list prices, browse the web, or propose modifications beyond pre-compiled rules.
Optional Security Scans
Governance and security-posture detectors are completely optional and must be explicitly enabled inside workspace settings. They are not active by default.
Integrations & Custom Scripts
Slack and Microsoft Teams use customer-provided HTTPS webhook URLs. Jira Cloud, Azure DevOps, and Linear ticketing use customer-provided API credentials. Live sends require the outbound integration feature flags to be enabled; otherwise drafts remain inside Costframe.
Data Freshness & Sync
Provider billing cost data syncs daily via BullMQ queue jobs. The Azure Retail Prices catalog index is fetched and rebuilt on a weekly cadence.
Enterprise Identity Features
SSO/SAML, custom support targets, and private deployment arrangements are Enterprise commercial terms. They may require paid identity-provider features, customer-provided domains, or a separate order form before activation.