Security
How we protect data and build secure, resilient systems — for our own operations and for the products we ship.
Last updated: 7 August 2026
Our approach to security
Security and compliance are core to what we do for clients, so we hold our own practices to the same standard. We design, build, and operate systems with a “secure by default” mindset — applying defence in depth, least-privilege access, and continuous review across the software lifecycle.
This page describes the safeguards we apply to our own operations and the practices we bring to client engagements. Specific controls for a given project are agreed in the engagement contract and, where applicable, a Data Processing Agreement (DPA).
Infrastructure & hosting
We build on reputable cloud providers — including Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure, and Vercel. These providers maintain independently audited certifications such as ISO/IEC 27001 and SOC 2, and we inherit and build upon the physical and network security controls of their data centres.
Hosting region is selected per engagement to meet each client’s performance and data residency requirements — including keeping data within a specific jurisdiction (for example, the EU or UK) where required.
Data protection & encryption
- Encryption in transit: traffic to our systems and the services we build is protected with TLS (HTTPS).
- Encryption at rest: data stored in managed cloud services is encrypted at rest using provider-managed encryption where supported.
- Secrets management: credentials, API keys, and certificates are stored in dedicated secret managers — never in source code.
- Data minimisation: we collect and retain only the data needed for a purpose, and delete it when it is no longer required.
Access control
- Access is granted on a least-privilege, need-to-know basis and reviewed periodically.
- Multi-factor authentication (MFA) is enforced on critical accounts and systems.
- Production, staging, and development environments are separated.
- Access to client systems is governed by the engagement agreement and revoked promptly on project completion or role change.
Secure development practices
- Peer code review before changes are merged and released.
- Version control with auditable history for all code.
- Dependency monitoring and timely patching of known vulnerabilities.
- Automated checks in CI/CD pipelines, with controlled, repeatable deployments.
- Security considered during design, following practices aligned to the OWASP guidelines.
Monitoring, backups & resilience
We use logging and monitoring to detect and investigate anomalies, and we design systems for resilience with backups and recovery appropriate to each engagement. Our incident-response process is intended to contain, assess, and remediate issues quickly, and to notify affected clients in line with contractual and legal obligations.
Compliance & data protection alignment
We align our practices with recognised data-protection frameworks, including the EU GDPR and UK GDPR. When we process personal data on behalf of a client, we do so as a data processor under a Data Processing Agreement that sets out security measures, sub-processors, and breach notification. A DPA is available on request. For how we handle personal data on our own website, see our Privacy Policy.
Responsible disclosure
We welcome reports from security researchers and users. If you believe you have found a security vulnerability in our website or a system we operate, please report it responsibly to security@cloudflect.com.
Please include enough detail to reproduce the issue, and give us a reasonable opportunity to investigate and remediate before any public disclosure. We ask that you do not access, modify, or delete data that is not yours, and that you avoid actions that could degrade our services. We appreciate and acknowledge good-faith reports.
Contact us
Questions about our security practices? Get in touch:
- Security & vulnerabilities: security@cloudflect.com
- Data protection: privacy@cloudflect.com
- CLOUDFLECT (PRIVATE) LIMITED, Colombo, Sri Lanka