Security at KloudSec
We take security seriously. Here's how we protect your data and infrastructure.
Data Encryption
All data is encrypted both in transit and at rest using industry-standard encryption protocols.
In Transit
- •TLS 1.3 for all communications between your browser and our servers
- •HTTPS enforced across all services
- •Strong cipher suites only (no weak or deprecated algorithms)
At Rest
- •AES-256 encryption for all stored data
- •Database encryption enabled on all production databases
- •Encrypted backups with secure key management
Data Storage & Location
Your data sovereignty matters. We're transparent about where your data is stored and processed.
- Primary Storage: All user data, scan results, and metadata are stored in EU data centers (AWS EU regions)
- Processing: Some processing operations may occur in US-based infrastructure for performance optimization, but all data remains encrypted
- GDPR Compliance: We comply with EU data protection regulations and ensure appropriate safeguards for any cross-border data transfers
What Data We Collect
We only collect data necessary to provide our security scanning service.
Account Information
- • Email address
- • Name
- • Organization details
Cloud Metadata
- • Resource configurations (read-only)
- • Security findings
- • Compliance scan results
Usage Data
- • User actions (for audit trails)
- • Scan history
- • Platform interactions
Authentication
- • Session cookies (authentication only)
- • Login timestamps
- • Access logs
What We DON'T Collect or Store
- •No cloud credentials or secrets - We use read-only roles (e.g., IAM roles for AWS)
- •No analytics or tracking - We don't use Google Analytics, Facebook Pixel, or similar tools
- •No third-party error tracking - No Sentry, Rollbar, or similar services (yet)
- •No sensitive application data - We only scan configurations, not your actual data
Access Controls & Cloud Permissions
KloudSec requires read-only access to your cloud infrastructure. We never need or request write permissions.
How We Access Your Cloud Account
- CloudFormation Template: For AWS, we provide an official CloudFormation template that creates a read-only IAM role
- Least Privilege Principle: The role only has permissions to describe and list resources (e.g.,
ec2:Describe*,s3:GetBucketPolicy) - No Write Access: Zero permissions to modify, delete, or create resources in your cloud account
- External ID Protection: Unique external ID per customer prevents unauthorized cross-account access
- Revocable Access: You can revoke KloudSec's access anytime by deleting the CloudFormation stack
Internal Security Practices
How we protect your data internally and ensure our team follows security best practices.
Audit Logging
All user actions and system events are logged for security monitoring and compliance auditing
Secure Development
Code reviews, dependency scanning, and security testing are part of our development workflow
Employee Access
Limited team access to production systems with multi-factor authentication enforced for all team members
Infrastructure Security
Regular security updates, patch management, and infrastructure monitoring on AWS
Incident Response
In the unlikely event of a security incident, we have procedures to respond quickly and transparently.
Our Commitment
- •Immediate investigation and containment of any security incident
- •Transparent communication with affected customers within 72 hours
- •Compliance with GDPR breach notification requirements
- •Post-incident analysis and preventive measures implementation
Report a Security Issue:
If you discover a security vulnerability, please email us immediately at hello@kloudsec.io
Security Certifications Roadmap
We're committed to achieving formal security certifications as we grow. Here's our roadmap:
Planned for 2026/2027
- Q2SOC 2 Type I: Begin SOC 2 audit process
- Q4SOC 2 Type II: Complete annual SOC 2 Type II audit
- Q4ISO 27001: Begin ISO 27001 certification process
Note: While we work toward formal certifications, we already implement the security controls and best practices required by these frameworks.
Questions About Security?
We're transparent about our security practices. If you have questions or concerns, we're here to help.
Last updated: August 1, 2026
For questions about this security page, contact hello@kloudsec.io