Skip to content
misia.ai
Menu

Cost Analytics

Security and data

Before your firm issues an admin key, someone will ask what it can reach, what a directory consent allows, and where your usage records sit. This page answers.

Reviewed 21 September 2026.

What is read

Usage and spend records, not conversations

Cost Analytics reads Claude Enterprise records from Anthropic’s organisation admin API. The keys are read-only, and yours to issue and revoke. What arrives is usage and spend: which account, which model, how many tokens, what it cost, when.

It does not read the content of anyone’s conversations, and it can’t change anything on the provider’s side.

A read-only directory consent lets the platform match an account to a person and their department, and applies your own structure to access inside Misia. Nothing is written back.

Prompts and completions do not cross. Illustrative data.
Where it lives

Amazon Web Services, encrypted at rest and in transit

Credentials
In a managed secret store, not in code.
Our engineers’ access
Single sign-on with credentials that expire, never a long-lived key.
Databases
Backed up automatically.
Region, account structure, how long we keep your records
In writing for your team, before you issue a key, not after.
Who can see it

You decide who sees what, by role and by scope

Administrators manage users, invitations and seats from the admin platform, which nobody else sees.

  • Scope. Set on the item: the whole firm, or part of it.
  • Roles. Permissions come with the role a person holds.
  • Joining. By invitation, or by a request an administrator approves; nobody is in by default.
  • Sign-in. Through your own identity provider, OIDC or SAML, so joiners and leavers are handled where you already handle them. Multi-factor authentication is whatever you enforce there.
  • The audit log. Changes to the tenant are written to it, and you can query and export it.
Every change says who made it, when, and to what. Illustrative data.
Sub-processors

Who else processes your data

  • Amazon Web Services

    Hosts the platform.

  • Anthropic

    Cost Analytics reads from Anthropic’s admin API, and Claude models answer in the platform’s assistant. We hold commercial terms, not consumer ones, and customer data is not used to train models.

  • Microsoft

    Teams and directory consent, where your firm chooses to use them.

Policy

What the policy commits us to

Misia’s information security policy is owned by the chief executive and reviewed every year. It is written to align with ISO 27001 and available on request under NDA. The parts that matter to you:

Within 24 hours
Access is removed when someone leaves or changes role.
Every six months
Privileged access is reviewed.
On joining and every year after
Everyone completes security training.
On discovery
A security incident is reported to the security lead, the chief technology officer or the chief executive. We tell anyone affected, and the Information Commissioner’s Office where the law requires it.
Before we depend on them
Suppliers are reviewed for their security practices.
How a change reaches you

Two people, a passing test run, and no exceptions

These are written down and owned by the chief technology officer.

  1. Before it is merged. Security testing runs against every change, and nobody merges their own work.
  2. Before it is released. A full end-to-end run has to pass.
  3. At the release itself. Both the chief executive and the chief technology officer approve it before it reaches production.

A change to live infrastructure is applied by a person at a gate, never by automation.

An urgent fix gets the same review and the same approval. There is no exception path to ask for.

Questions

What gets asked before a key is issued

Do you read our conversations? No

Cost Analytics reads records of usage and spend through the provider’s admin API. The platform’s assistant answers from material a person in your firm has approved. Neither reads what people type into their AI tools.

Which standard is your security policy aligned with?

ISO 27001. What it commits us to is set out above, under Policy.

Who else processes our data?

The sub-processors named above, and no others without telling you. We run supplier due diligence before we depend on one. Cost Analytics answers whether any of it is used to train a model.

Can we have the detail in writing? Yes

The region, the account structure, the retention periods, the sub-processor list and the terms the product is licensed under go in writing on request. Ask for the written detail and a person will send it.

What it answers: Cost Analytics. What a rollout asks: How it works.

The detail, in writing

To your team, before you issue a key.

  • Region
  • Account structure
  • Retention periods
  • Sub-processor list
  • Security questionnaire, under NDA
Book a 20-minute call opens in a new tab

The security lead joins the call for any of these.