Authentication Method
AWS authenticates using an AWS Access Key ID and Secret Access Key. These credentials are generated from AWS IAM and scoped with the minimum read-only permissions required for Montro to import users, resources, services, and policy information.
How to Connect:
- Navigate to Integrations in your Montro dashboard.
- Select AWS from the integrations catalogue and click Connect.
- Enter your AWS Access Key ID.
- Enter your AWS Secret Access Key.
- Click Connect to authorise the integration.
- Montro validates the credentials and establishes a secure connection.
- AWS users, resources, services, policies, and cloud usage information are synchronised automatically.
- Review imported cloud data within Montro.
Data Synced
Users | AWS IAM user identities, including account information and access details. |
Resources | Cloud resources deployed across your AWS environment, including compute, storage, and database instances. |
Services | AWS services active across your account, including AI/ML services such as SageMaker, Rekognition, and Bedrock. |
Policies | IAM policy information supporting access control visibility and governance assessments. |
Data Residency
AWS data imported into Montro is stored on AWS Frankfurt (eu-central-1), within the European Union. This is separate from your own AWS environment - Montro's infrastructure is EU-only regardless of which AWS regions your own resources operate in. Data residency terms are specified in Montro's Data Processing Agreement.
Sync Frequency
Data can be synchronised manually at any time after the initial connection, with no limit on the number of manual syncs. Montro also provides an automatic sync option - when enabled, the platform synchronises data once every night to keep information current.
Permission Scope
Montro uses read-only AWS credentials scoped to the minimum permissions required to retrieve user, resource, service, and policy information. Montro does not create, modify, or delete any AWS resources, users, policies, or configurations. We recommend generating credentials for a dedicated IAM user with read-only permissions rather than using root credentials or existing administrative accounts.
EU Data Storage
Montro's infrastructure runs exclusively on AWS eu-central-1 (Frankfurt), governed by Irish and EU law. There is no FISA 702 exposure and no Schrems II ambiguity. Your data is never replicated outside the EU without your explicit, documented consent. EU data residency is not a configuration option, it is the architecture.









