Security at KloudSec

We take security seriously. Here's how we protect your data and infrastructure.

Data Encryption

All data is encrypted both in transit and at rest using industry-standard encryption protocols.

In Transit

  • TLS 1.3 for all communications between your browser and our servers
  • HTTPS enforced across all services
  • Strong cipher suites only (no weak or deprecated algorithms)

At Rest

  • AES-256 encryption for all stored data
  • Database encryption enabled on all production databases
  • Encrypted backups with secure key management

Data Storage & Location

Your data sovereignty matters. We're transparent about where your data is stored and processed.

  • Primary Storage: All user data, scan results, and metadata are stored in EU data centers (AWS EU regions)
  • Processing: Some processing operations may occur in US-based infrastructure for performance optimization, but all data remains encrypted
  • GDPR Compliance: We comply with EU data protection regulations and ensure appropriate safeguards for any cross-border data transfers

What Data We Collect

We only collect data necessary to provide our security scanning service.

Account Information

  • • Email address
  • • Name
  • • Organization details

Cloud Metadata

  • • Resource configurations (read-only)
  • • Security findings
  • • Compliance scan results

Usage Data

  • • User actions (for audit trails)
  • • Scan history
  • • Platform interactions

Authentication

  • • Session cookies (authentication only)
  • • Login timestamps
  • • Access logs

What We DON'T Collect or Store

  • No cloud credentials or secrets - We use read-only roles (e.g., IAM roles for AWS)
  • No analytics or tracking - We don't use Google Analytics, Facebook Pixel, or similar tools
  • No third-party error tracking - No Sentry, Rollbar, or similar services (yet)
  • No sensitive application data - We only scan configurations, not your actual data

Access Controls & Cloud Permissions

KloudSec requires read-only access to your cloud infrastructure. We never need or request write permissions.

How We Access Your Cloud Account

  • CloudFormation Template: For AWS, we provide an official CloudFormation template that creates a read-only IAM role
  • Least Privilege Principle: The role only has permissions to describe and list resources (e.g., ec2:Describe*, s3:GetBucketPolicy)
  • No Write Access: Zero permissions to modify, delete, or create resources in your cloud account
  • External ID Protection: Unique external ID per customer prevents unauthorized cross-account access
  • Revocable Access: You can revoke KloudSec's access anytime by deleting the CloudFormation stack

Internal Security Practices

How we protect your data internally and ensure our team follows security best practices.

Audit Logging

All user actions and system events are logged for security monitoring and compliance auditing

Secure Development

Code reviews, dependency scanning, and security testing are part of our development workflow

Employee Access

Limited team access to production systems with multi-factor authentication enforced for all team members

Infrastructure Security

Regular security updates, patch management, and infrastructure monitoring on AWS

Incident Response

In the unlikely event of a security incident, we have procedures to respond quickly and transparently.

Our Commitment

  • Immediate investigation and containment of any security incident
  • Transparent communication with affected customers within 72 hours
  • Compliance with GDPR breach notification requirements
  • Post-incident analysis and preventive measures implementation

Report a Security Issue:

If you discover a security vulnerability, please email us immediately at hello@kloudsec.io

Security Certifications Roadmap

We're committed to achieving formal security certifications as we grow. Here's our roadmap:

Planned for 2026/2027

  • Q2
    SOC 2 Type I: Begin SOC 2 audit process
  • Q4
    SOC 2 Type II: Complete annual SOC 2 Type II audit
  • Q4
    ISO 27001: Begin ISO 27001 certification process

Note: While we work toward formal certifications, we already implement the security controls and best practices required by these frameworks.

Questions About Security?

We're transparent about our security practices. If you have questions or concerns, we're here to help.

Last updated: August 1, 2026

For questions about this security page, contact hello@kloudsec.io