This policy explains what information CloudGuard ("we", "us") collects when you use cloudguard.solutions and the CloudGuard platform, how we use it, and the choices and rights you have.
Account information. When you create an account, we collect your name, email address, organization name, and a password. Passwords are never stored in readable form.
Scan data. To provide the service, CloudGuard connects to the cloud accounts, virtualization environments, and servers you choose to connect, using read-only access. We collect configuration metadata needed to run security checks, such as resource names, configuration settings, and service states. We do not collect the contents of your workloads, databases, or files.
Connection credentials. Credentials you provide for scanning are encrypted at rest and used only to perform the scans you configure. They are never shared with third parties or used for any purpose beyond running the service on your behalf.
Support data. When you open a support ticket, we collect the information you submit, together with limited context such as your plan and browser, so we can help you faster.
Usage and technical data. Standard server logs, such as IP address, browser type, and timestamps, used for security and operating the service reliably.
Your data is used solely to provide the service to you. It is never used for advertising, and never used to train models or features outside your own account.
We share information only where necessary to operate the service, and only with parties bound by confidentiality and data protection obligations:
All data in CloudGuard is scoped to your organization, and access is isolated between organizations at every layer of the platform. Access to the environments you connect is read-only by design. Passwords and stored credentials are protected using industry-standard encryption and hashing, and access to the platform is protected by short-lived authentication tokens.
We retain your data while your account is active. If you close your account or ask us to, we will delete your organization's data, including stored credentials, findings, and support history, within 30 days, except where we are legally required to retain certain records, such as billing history.
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these rights, email support@cloudguard.solutions, and we will respond within 30 days.
CloudGuard uses browser storage to keep you signed in and to remember your preferences. We do not use advertising or third-party tracking cookies.
Your information may be processed in countries other than your own. Where this occurs, we take steps to ensure your information receives an equivalent level of protection, consistent with applicable data protection law.
If we make material changes to this policy, we will update the date above and, for significant changes, notify account owners by email.
Questions about this policy: support@cloudguard.solutions