Private by design
Security & Privacy
Your Databricks data stays between your browser and your workspace.
FinOpsWay was designed without a backend. The extension communicates directly with the Databricks workspace you configure. We do not operate a server that receives your credentials, billing information, job metadata, query results or workspace data.
What leaves your browser?
FinOpsWay sends requests only to the Databricks workspace needed to show the extension. It does not send Databricks data to FinOpsWay servers, because there are no FinOpsWay servers processing that data.
We do not collect billing data, job or run information, cluster or SQL warehouse information, pipeline information, query results, workspace metadata or extension telemetry. We cannot inspect your company's Databricks environment remotely.
What about my Databricks credential?
Your credential is used locally by the extension to communicate with your workspace. It is not sent to FinOpsWay. In token mode, it is stored locally by the extension and is never synced to a browser account. In session mode, the extension uses your existing Databricks session.
For enterprise environments, use a dedicated credential with only the permissions needed for the cost data you choose to expose. FinOpsWay does not require Account Admin or Metastore Admin access for normal cost visibility.
You control the security boundary
Organizations can expose approved cost data through restricted views or a dedicated catalog, rather than grant unrestricted access to the System Catalog. FinOpsWay can be configured to use that cost-data catalog.
Give FinOpsWay access only to the cost information you want the user to see.
Least privilege by design
- Use a dedicated identity or restricted user where appropriate.
- Grant only the permissions needed to read approved cost data.
- Use restricted views or a dedicated catalog where direct system table access is not allowed.
- Use a dedicated SQL warehouse where required by your governance model.
- Review permissions before organization-wide deployment.
Does FinOpsWay modify Databricks?
FinOpsWay is designed for cost visibility, not workload administration. It does not need to change jobs, clusters, SQL warehouses, pipelines, notebooks or data to calculate and display cost information. The extension runs read-only SQL queries against the cost and compute information it is permitted to read.
No telemetry from the extension
FinOpsWay does not operate telemetry that tracks the Databricks jobs, clusters, warehouses, pipelines or pages you use. Your cost data is there to help you understand your infrastructure, not to become our product analytics dataset.
Enterprise security reviews
FinOpsWay is distributed through official browser extension stores and can be evaluated by your security team before deployment. Managed-browser administrators can decide whether it is permitted under their existing extension policies.
For a detailed account of local storage and workspace endpoints, read the privacy policy. For a security review, contact us.