1. Current security posture
CloudAlls uses secure transport, access controls, CSRF protections, prepared database statements, session protections, logging, and operational review practices in the delivered application. Controls are subject to deployment configuration and ongoing maintenance.
2. Incident response
Security events are triaged, contained, investigated, documented, and communicated according to impact, contractual commitments, and applicable law. Response times are targets or agreement-specific commitments unless expressly stated in a signed service agreement.
3. Assurance and testing
Security testing, dependency reviews, backups, restore drills, and independent assessments should be tracked as evidence. No specific certification or penetration-testing cadence is claimed on this page unless a current report is available for review.
4. Reporting
Report suspected security issues through the approved CloudAlls contact channel. Do not include passwords, secrets, or unnecessary personal data in an initial report.