Online — typically replies instantly
Powered by Claude AI · Responses in seconds
Security is not an afterthought at Cloudrix. It is woven into every layer of our platform, from infrastructure choices to employee access policies. This page explains exactly how we protect your data, what compliance frameworks we follow, and how to report vulnerabilities.
Encryption, privacy, and GDPR compliance at every level
Every piece of data that flows through Cloudrix is protected by industry-standard encryption. We use AES-256 encryption at rest for all stored data, including databases, backups, and file storage. Data in transit is secured with TLS 1.3 across all connections, including internal service-to-service communication.
Our approach to data protection is built on the principle of data minimization. We collect only the data necessary to provide our services, and we are transparent about what we collect and why. Every data field in our systems is classified by sensitivity level, and access controls are applied accordingly.
As a company headquartered in the Netherlands, Cloudrix is subject to the General Data Protection Regulation (GDPR). We fully embrace this framework:
Enterprise-grade hosting with EU data residency
Cloudrix runs on a multi-provider infrastructure stack that prioritizes reliability, performance, and security. Our primary hosting providers are:
eu-west-1 (Ireland) and eu-central-1 (Frankfurt). We use VPC isolation, security groups, and network ACLs to segment workloads.All infrastructure is managed as code using Terraform, ensuring consistent security configurations across environments. Infrastructure changes go through pull request review, automated security scanning (tfsec, checkov), and staged rollouts. We maintain separate development, staging, and production environments with strict network isolation between them.
We perform regular vulnerability scans on our infrastructure using automated tools and address critical vulnerabilities within 24 hours of discovery. Non-critical vulnerabilities are prioritized and resolved within our standard sprint cycle.
Zero-trust architecture with role-based permissions
Cloudrix implements a zero-trust security model. No user, service, or device is trusted by default, regardless of whether it is inside or outside the network perimeter. Every request is authenticated and authorized independently.
For customer-facing authentication, we support:
Internally, we follow the principle of least privilege. Team members are granted access only to the systems and data they need for their role. Production database access requires VPN connection, SSH key authentication, and manager approval. All access is logged and reviewed quarterly.
Session management includes automatic expiration after 24 hours of inactivity, concurrent session limits, and the ability for users to revoke all active sessions from their security settings.
GDPR-compliant today, SOC 2 on the roadmap
Cloudrix maintains compliance with the following frameworks and regulations:
Fully compliant. Data processing agreements, privacy impact assessments, and data subject request procedures are in place.
Our AI-powered products are designed with EU AI Act compliance in mind. Risk classifications, transparency requirements, and human oversight controls are built in.
In progress. Expected completion Q4 2026. Our security controls already align with Trust Services Criteria.
Planned for 2027. We are implementing an Information Security Management System (ISMS) based on ISO 27001 controls.
We maintain a detailed record of processing activities (ROPA) as required by GDPR Article 30. This register documents every category of personal data we process, the legal basis, retention periods, and any third-party processors involved. We review and update the ROPA quarterly.
Structured process for detecting, responding to, and learning from incidents
Cloudrix maintains a documented incident response plan that covers detection, containment, eradication, recovery, and post-incident review. Our incident response process includes:
We conduct quarterly tabletop exercises to test our incident response procedures and ensure the team is prepared. Annual penetration testing is performed by independent security researchers.
Clear policies on how long we keep data and how to request deletion
We retain customer data only for as long as necessary to provide our services and meet legal obligations. Our retention policy is:
Customers can request complete deletion of their data at any time by contacting privacy@cloudrix.io. We process deletion requests within 30 days and provide confirmation once the deletion is complete. Deletion is performed across all systems, including backups, within 90 days.
We welcome security researchers and handle reports with care
If you discover a security vulnerability in any Cloudrix product or service, we want to hear about it. We are committed to working with security researchers to verify, reproduce, and address vulnerabilities responsibly.
How to report: Send an email to security@cloudrix.io with a detailed description of the vulnerability, including steps to reproduce, potential impact, and any supporting evidence (screenshots, logs, proof of concept).
Our disclosure timeline:
We do not pursue legal action against security researchers who follow this responsible disclosure process. We ask that you do not access or modify other users' data, do not disrupt our services, and give us reasonable time to address the issue before public disclosure.
Request our full security questionnaire, discuss compliance requirements, or schedule a call with our security team.
Yes. Cloudrix is fully GDPR-compliant. We process personal data only with valid legal bases, provide data subject access and deletion capabilities, maintain a processing register, and use EU-based data centers. Our Data Protection Officer can be reached at privacy@cloudrix.io.
All customer data is stored in EU data centers (AWS eu-west-1 and eu-central-1, Vercel Edge EU). We do not transfer personal data outside the European Economic Area unless you explicitly request it and appropriate safeguards (such as Standard Contractual Clauses) are in place.
We are currently working toward SOC 2 Type II certification, with an expected completion in Q4 2026. Our infrastructure already meets the security controls required by the Trust Services Criteria. Contact us for our current security questionnaire.
We have a responsible disclosure policy. Please email security@cloudrix.io with details of the vulnerability. We acknowledge reports within 24 hours, provide an initial assessment within 72 hours, and work with researchers through remediation. We do not pursue legal action against good-faith reporters.
Yes. We maintain a comprehensive security questionnaire covering infrastructure, access controls, encryption, incident response, and compliance. Contact security@cloudrix.io or use our contact form to request a copy.
Yes, we provide GDPR-compliant Data Processing Agreements to all customers who process personal data through our platform. DPAs are available upon request and can be customized for enterprise requirements.