Trust Center
Security, compliance, and privacy at CloudRepo. We believe in complete transparency about how we protect your data and artifacts.
Security
How We Protect Your Data
- Encryption at Rest & In Transit
- AES-256 encryption for all stored artifacts. TLS 1.2+ enforced on all connections. Passwords hashed with PBKDF2+BLAKE2b-512.
- Access Controls
- MFA required on all production systems. Principle of least privilege enforced. No shared credentials. Individual accounts for all access.
- US-Based Infrastructure
- Artifacts and account data stored in the United States on AWS, except as disclosed in our subprocessor list. Amazon S3 with 99.999999999% durability. DynamoDB with automated backups. Certain operational subprocessors process limited categories of data outside the United States. See our subprocessor list.
- Zero-Breach Track Record
- No security breaches in over 10 years of operation. No known data breaches in company history. We respond to security reports as quickly as possible, typically within 24 hours.
Compliance
Our Compliance Posture
While CloudRepo does not hold formal certifications like SOC 2 or ISO 27001, we maintain strong security practices and partner exclusively with certified vendors.
AES-256 Encryption
All data encrypted at rest and in transit
US Data Residency
Artifacts and account data in AWS US-West (N. California)
SOC 2 Certified Vendors
All infrastructure partners are SOC 2 certified
Zero Security Breaches
No data breaches in company history
GDPR Ready
Data processing agreement and deletion processes in place
Documentation
Security Documentation
Download our security documents for your vendor review process.
Security Practices
Comprehensive overview of our security controls, infrastructure, and processes.
Security Self-Assessment
Complete 43-question vendor security questionnaire for enterprise procurement.
Compliance Status Letter
Founder letter on our security commitment and compliance posture.
FAQ
Frequently Asked Questions
Common questions about our security and compliance practices.
-
CloudRepo does not hold SOC 2 certification. As a bootstrapped company, the cost of formal certification is disproportionate to our size. However, we exclusively partner with SOC 2 certified vendors (AWS, Braintree, Postmark, etc.) and maintain comprehensive security practices that align with SOC 2 principles. We provide full transparency through our Security Practices Document, Data Processing Agreement, and Subprocessor List.
-
SAML/OIDC SSO is on our roadmap and will be included on all plans. We actively encourage customers to tell us which identity providers (Okta, Azure AD, etc.) they need so we can prioritize accordingly. Contact us at security@cloudrepo.io.
-
All customer artifacts and account data are stored in the United States (AWS US-West). Artifacts are stored in Amazon S3 with 99.999999999% durability. Metadata is stored in Amazon DynamoDB. Certain operational subprocessors process limited categories of data (including billing contacts, operational records, support conversations, email addresses, and error and session metadata) and may do so outside the United States; see our subprocessor list for details.
-
Email security@cloudrepo.io with your data deletion request. We process verified requests within 30 calendar days. Deletion is an operator-run procedure that covers your artifacts and repository data in Amazon S3. It does not remove account and identity records (your organization record, user records, credentials, API tokens, and SSO configuration are retained), and repository metadata rows are kept with storage counters reset to zero. Because object storage uses versioning and our databases use point-in-time recovery, prior copies remain recoverable to us for their retention window. Note that cancelling a subscription does not by itself delete anything: deletion begins only when you request it. You can also delete any repository and its contents yourself, at any time, from the portal or the API.
-
No. CloudRepo has had no security incidents in the past 3 years and no known security breaches or data loss events in company history.
-
Yes. Our GDPR Article 28 compliant Data Processing Agreement is available for download from our Trust Center. Contact us at security@cloudrepo.io if you need a countersigned copy.
Need a Custom Security Review?
We're happy to complete vendor questionnaires, discuss our security practices, or address specific compliance requirements.