For what it's worth, we're trying to be extremely thoughtful about security. If it helps (or hurts?), we're a venture backed company, have a published privacy policy, etc. We don't include any anonymous identity tracking, nor do we do any resource crawling, or anything like that. For the CloudTrail feature, we do hit a read-only API endpoint using your browser session, but we don't send any of that data to our servers. We'd never hit any read/write endpoints without you properly granting us an IAM role.