Security Overview
Architecture, connector design, secure SDLC, audit logging, vulnerability management, and our overall security posture.
Status: AvailableTrust & Security
Cloudryption is designed to help security teams make better cloud-risk decisions. We apply the same standard to our own platform: protect customer data, limit access, maintain clear controls, and communicate our compliance posture transparently.
Architecture, connector design, secure SDLC, audit logging, vulnerability management, and our overall security posture.
Status: AvailableHow data moves through Cloudryption, TLS enforcement, at-rest encryption, secrets handling, tenant isolation, and evidence minimisation.
Status: AvailableRBAC role model, MFA/SSO requirements, provisioning controls, and quarterly privileged access reviews.
Status: AvailableEncrypted backups, RPO/RTO targets, restore testing cadence, and recoverability commitments for the platform.
Status: AvailableEnterprise customers can use SAML/OIDC SSO with Okta, Microsoft Entra ID, and Google. SCIM provisioning is available on supported enterprise plans.
Status: Available / EnterpriseCloudryption supports regional deployment options for customers with data residency requirements.
Status: Available by deployment modelCloudryption acts as a data processor for customer data. A full DPA covering processing purposes, security measures, and sub-processors is available for enterprise customers.
Status: AvailableOur sub-processor list is minimal by design. Review the full list of approved subprocessors and how we manage third-party data flows.
Status: AvailableRetention schedules for scan data, findings, audit logs, and account metadata — plus tenant offboarding data removal timelines.
Status: AvailableOur honest status: not yet certified. See the GA controls baseline and phased path toward SOC 2 Type II covering Security, Availability, and Confidentiality criteria.
Status: Readiness in progressCloudryption is building an Information Security Management System aligned to ISO/IEC 27001 principles.
Status: Readiness in progressPublic-sector compliance support is part of the future roadmap.
Status: RoadmapHow to report suspected vulnerabilities, what to expect from our security team, and our safe harbour commitment to security researchers.
Status: AvailableHow Cloudryption detects, contains, and communicates security incidents — and what customers can expect during and after an event.
Status: AvailableStandardised answers covering governance, compliance, architecture, encryption, access control, SDLC, and subprocessors for enterprise vendor reviews.
Status: Available