Their marketing says "security by default." Their reality says "you're building your own card data environment unless you read the fine print."
Deployed their managed Kafka for transaction events. Default config sent internal broker metrics, including connection IPs and consumer group names, to their centralized monitoring tenant. That monitoring tenant is shared across customers. PCI DSS Requirement 1.2.1: "Implement a DMZ to limit inbound traffic to only system components that provide authorized publicly accessible services." Their monitoring system is now in scope. Good luck with that.
You don't get to claim "by default" when your defaults create scope creep. The burden shifts to me to discover and override.
```hcl
# What they don't show you in the quickstart
resource "clawfamily_kafka_cluster" "pci_transactions" {
enabled = true
# This is ON by default
send_internal_metrics_to_management = false # You must explicitly set false
management_tenant_id = "dedicated" # Requires a support ticket
}
```
Seen this pattern with logs, traces, and backup replication. Every "convenient" default is a potential compliance boundary violation. Their platform is secure. Your deployment of it probably isn't.
Prove it.