Security
In short
We design systems with security in mind and welcome responsible reports of vulnerabilities. Email security@cloudalls.com with details and we will respond.
Our approach
We treat security as part of design, not an add-on. In practice that means:
- encrypted connections (HTTPS) on our website;
- least-privilege access to systems and data;
- keeping software and dependencies up to date;
- validating and limiting what our website forms accept;
- separating personal data from the public website.
We do not claim certifications we do not hold. If a project needs a specific standard, we will agree that with you in writing.
Reporting a vulnerability
If you believe you have found a security issue in cloudalls.com or a CloudAlls service, email security@cloudalls.com with enough detail for us to reproduce it. Please do not access data that is not yours, disrupt services or share the issue publicly before we have had a reasonable chance to fix it.
We will acknowledge your report, investigate and keep you updated. We will not take legal action against good-faith research that follows these guidelines.
Incident response
If we confirm a security incident, we follow three steps: detect and triage, contain and assess, then recover and improve. Where personal data is affected, we notify the people and authorities required by law.
Customer responsibilities
Security is shared. You are responsible for keeping your own passwords and accounts safe, for the accuracy of access lists you give us and for telling us promptly about suspected problems.
Version history
- Version 2.0, 1 October 2026: rewritten in plain language for the new website.
Questions about this page: contact@cloudalls.com. You can print this page or save it as a PDF from your browser.