Legal

Privacy Policy

How CloudSure respects customer privacy, processes data responsibly, and protects your organization when using our multi-cloud compliance platform.

Last updated: July 2026

Customer Privacy

CloudSure is committed to protecting the privacy of organizations and individuals who use our platform. We collect and process only the information needed to operate the CloudSure SaaS portal, deliver compliance assessments, and support your account.

This typically includes:

  • Account and profile information such as name, email address, organization name, and role
  • Authentication and security settings, including optional two-factor authentication (2FA) configuration
  • Scan job metadata, compliance findings, scores, and generated reports associated with your tenant workspace
  • Messages submitted through our contact forms when you reach out for support or sales inquiries

We do not sell customer personal data. Access to tenant data is restricted by role-based access controls and multi-tenant isolation so that each organization’s workspace remains separate from others on the platform.

Fire-and-Forget Credential Handling

CloudSure uses a fire-and-forget credential model for cloud compliance scanning. When you provide AWS, Azure, or GCP credentials to run an assessment, those credentials are used strictly in-memory for the duration of the scan and are not stored in the CloudSure database.

  • Cloud access keys and tokens are processed only to execute the requested scan
  • Credentials are purged from memory after the scan completes or terminates
  • CloudSure does not persist cloud secrets in a long-term credential vault
  • You retain control over which credentials you supply and when scans are run

This approach is designed to reduce secret exposure risk and align with security-conscious compliance workflows. Scan outputs such as findings and reports may be retained in your tenant workspace so your team can review results and download audit-ready documentation.

Data Processing Practices

CloudSure processes data to provide compliance scanning, reporting, account management, and customer support. Processing activities include:

  • Running cloud configuration assessments against selected frameworks and regions
  • Storing scan results, compliance scores, and downloadable PDF reports within your tenant
  • Generating optional AI-assisted executive summaries and remediation guidance when enabled
  • Operating authentication, session management, and audit logging for platform access
  • Responding to contact and support requests submitted through our website or portal

We retain account and scan data for as long as your organization uses the service and as needed to fulfill legitimate business, security, and legal obligations. You may request information about your data or contact us regarding privacy questions using the details below.

Security Measures

CloudSure applies technical and organizational measures designed to protect customer information and platform integrity, including:

  • Multi-tenant workspace isolation with role-based access control (RBAC)
  • Encrypted sessions and secure authentication, with optional TOTP-based 2FA
  • Fire-and-forget handling of cloud credentials during scans
  • Least-privilege design for scan operations and administrative access
  • Monitoring and logging of platform activity to support security review

For Enterprise Deployment customers, CloudSure can be operated within your own infrastructure, allowing your organization to apply additional network, data residency, and governance controls. Security practices should be reviewed alongside your internal policies and compliance requirements.

Contact Information

If you have questions about this Privacy Policy, your account data, or CloudSure’s privacy practices, please contact us:

CloudSure

Office 15453, 182-184 High Street North
East Ham, London E6 2JA
United Kingdom

Contact us via the website to reach our team for privacy, support, or enterprise inquiries.

Questions about privacy or security?

Our team can help you understand how CloudSure handles data, credentials, and compliance outputs for your organization.