Security
Version 1.1, August 2026
Compliance data deserves bank-grade care. This page summarises how Cloudpliant protects it.
Infrastructure
- All application data and documents are hosted in the EU (Germany), on ISO 27001-certified infrastructure (Hetzner). Cloudpliant's own ISO 27001 certification is on the roadmap.
- Transport encryption (TLS) everywhere; encryption at rest on all storage.
- OAuth tokens for connected systems are encrypted with AES-256-GCM before storage.
- Least-privilege access control; production access is limited and logged.
Application
- Screening evidence and reports are immutable snapshots: what you saw is what is stored.
- Report links are protected with unguessable tokens and timing-safe verification.
- Webhooks from connected systems are signature-verified.
- Per-user quotas and rate limits protect against abuse.
- New passwords are checked against known data breaches (Have I Been Pwned) using k-anonymity: only the first five characters of a hash leave our servers, never the password itself.
Disclosure
Found a vulnerability? Report it to security@cloudpliant.com. We respond quickly and appreciate responsible disclosure. An ISO 27001 certification trajectory is on our roadmap.